»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 08-13-2003, 03:55 PM   #1 (permalink)
Registered User
 
Join Date: Aug 2003
Posts: 4
ssbbg is on a distinguished road
Backdoor.WinShell.50/Stealther.B Virus

Just wanted to give a heads up about this virus. It exploits the same hole in security as blaster does, but it is causing our LAN a lot more trouble. The worm appears to not have activated until yesterday, at least on our machines. Some of our machines were already patched with the windows security patch, but still had the worm. When we went to do additional updates today, when the worm was active, we ran into this problem. So I would recommend scanning for the virus before updating any windows 2000 machines, even if they have been patched for a while.

Basically, as far as I can tell, if you try to install any sort of service pack (for win2K) while you have the virus, the install will say it cannot find csrsrv.dll. There doesn't seem to be any fix at this point. If you ignore, continue, or cancel, when windows restarts, it will endlessly reboot or not boot at all. In some cases, you can boot from disk, copy the .dll from a clean computer to the win\sys folder, reboot into windows, clean the virus off, then update again. However, some of our machines will not boot from disk after this error, and we haven't figured out the fix yet.

Removal tool at:
http://securityresponse.symantec.com...nshell.50.html

Hope this helps some of you avoid trouble!

ssbbg is offline   Reply With Quote
Old 08-13-2003, 04:56 PM   #2 (permalink)
Registered User
 
Join Date: Oct 2001
Posts: 691
zskillz is on a distinguished road
Send a message via AIM to zskillz
Thanks for the heads up!

-Z
zskillz is offline   Reply With Quote
Old 08-26-2003, 06:57 AM   #3 (permalink)
tks
Registered User
 
Join Date: Aug 2003
Posts: 1
tks is on a distinguished road
Thanks for posting this--I was just about to rebuild.

I saw the problem with not finding csrsrv.dll with Service Pack 4; when I tried Service Pack 3, install couldn't find csrss.exe.

McAfee's Stinger (as of version 1.8.4, 19 August 2003) doesn't find this worm.
__________________
Sandy Shew
tks is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 11:52 PM.