Calling All Geeks

Discussion in 'Software' started by Adrynalyne, Apr 30, 2004.

  1. Adrynalyne

    Adrynalyne Guest

    I'm on a time crunch, but can you guys help me track down a virus/worm?

    When people are getting on the net, lsass.exe is crashing and nt/authority shutdown in 60 seconds message.


    Thanks for the help.
     
  2. Adrynalyne

    Adrynalyne Guest

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  4. Kodo

    Kodo SNATCHSQUATCH

    could we be seeing the first run of worms for the new lsass vuln?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yeah! Way too much time on their hands! Wouldn't you just like to put those hands in a vice and squeeze the crap out of them! :mad:
     
  6. Adrynalyne

    Adrynalyne Guest


    Thats precisely what it is. Sarc is reporting them as gaobot variants.


    Half the building is infected here, heheh.
     
  7. Kodo

    Kodo SNATCHSQUATCH

    joy.. new worm and a broken patch for it.
     
  8. Adrynalyne

    Adrynalyne Guest

    Is it broken? I honestly didn't check. I just assumed the computers here were...less than maintained. The Windows XP support end of the building hasn't been hit...yet.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did they put the MS update - Security Update for Windows XP (KB835732)
    a week or so ago when it came out?

    I think this may be related to this security hole.
     
  10. Adrynalyne

    Adrynalyne Guest

    Probably not.


    LOL.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Tell them to raise their right hands and repeat after me "I will install all MS security patches when they become available". :D
     
  12. Adrynalyne

    Adrynalyne Guest

    You would think people would have learned from msblast....
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I think it's time to shoot a couple dozen kitties! ;)
     
  14. Adrynalyne

    Adrynalyne Guest

    Some more info:


    Remember when Nick posted these patches and recommended that you get them from the direct URL?

    I guess there is a site/sites out there that are recommending people download the patch. The download overwrote the patch, and opened the hole again....heheh.


    At least thats what a fellow tech told me.
     
  15. Kodo

    Kodo SNATCHSQUATCH

    Apparently on win2000 systems it can lock up the boot process. I do believe it's ok for XP though.
     
  16. Kodo

    Kodo SNATCHSQUATCH

    The patch was issued on the 13th. There's nothing "wrong" with that patch that over-writes anything newer. It's a brand new patch..
     
  17. Adrynalyne

    Adrynalyne Guest

    No, you misunderstand what I meant.

    It wasn't an MS site. ANd MS doesnt use popups either, not for that stuff.

    But thats a rumor going around here. Don't know how true it is.
     
  18. Kodo

    Kodo SNATCHSQUATCH

    Oh.. well, that sucks. Why do people have to be that way.. :sigh:.
     
  19. ASUS

    ASUS MajorGeek

    Is a variant of the OPTIX PRO Viruses.
    Optix Pro (bck/Optix.Pro.13) is the trojan that opens TCP port 3410 and allows hacker to control an infected computer.
    Also it installes and executes the Trojan Bck/sub7.22 which disables antiviral programs and systems processes with network displays.
    Optix Pro copies it self thru Floppy disks, CDs, E-mail with infected atachments, files from FTP etc.

    Use RegRun Optimizer to remove it automatically
     
  20. Adrynalyne

    Adrynalyne Guest

    This virus is transmitted by connecting to the net.

    Doesn't sound like Optix Pro, IMO. None of the symptoms seem related.

    I think it is a gaobot variant, as Sarc says. Its exploiting the lsass vulnerability.
     
  21. ASUS

    ASUS MajorGeek

    O.K.

    Hey there only like 25,000 links on google on goabot.
    I only have about 24,980 left to read
     
  22. Adrynalyne

    Adrynalyne Guest

    Lol :D :D
    -------
     
  23. snakefoot

    snakefoot Sergeant Major

    This virus seems to be spreading fast, my homepage is being hit by many people searching for solution to Lsass.exe and error (Very similar to when blaster started and they were searching for Svchost.exe).
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  25. Adrynalyne

    Adrynalyne Guest


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds