{"id":256,"date":"2004-11-27T22:29:24","date_gmt":"2004-11-27T22:29:24","guid":{"rendered":"http:\/\/fiveforks.com\/jeb\/2004\/11\/gandalf_the_whi\/"},"modified":"2004-11-27T22:29:24","modified_gmt":"2004-11-27T22:29:24","slug":"gandalf_the_whi","status":"publish","type":"post","link":"https:\/\/www.fiveforks.com\/jeb\/2004\/11\/gandalf_the_whi\/","title":{"rendered":"Gandalf The White (infected)"},"content":{"rendered":"<p>Gandalf (the white) was set up two weeks ago without anti-virus protection. So a worm (or two) moved in and started routing pirated files. This morning it started being so &#8220;loud&#8221; on the network it ground everything else to a halt.<\/p>\n<p>I had to go make a personal call to perform surgery. Norton Anti-Virus found the following:<\/p>\n<blockquote><p>C:\\WINNT\\MSsrvs32.exe is infected with W32.Randex.gen<\/p>\n<p>C:\\WINNT\\system32\\MSsrvs32.exe is infected with W32.Randex.gen<\/p>\n<p>C:\\WINNT\\system32\\webchecks.dll is infected with W32.IRCBot<\/p>\n<p>C:\\WINNT\\system32\\dhcp\\csrss.exe is infected with W32.IRCBot<\/p>\n<p>C:\\Documents and Settings\\DoNotUse\\payload.dat is infected with W32.Randex.gen<\/p>\n<p>C:\\Documents and Settings\\Default User\\Templates\\winspsv.exe is infected with W32.Spybot.Worm<\/p>\n<p>C:\\Documents and Settings\\Administrator\\payload.dat is infected with W32.Randex.gen <\/p><\/blockquote>\n<p>I had to manually delete MSsrvs32.exe and webchecks.dll using a command line because Norton and Windows were &#8220;denied access.&#8221;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Gandalf (the white) was set up two weeks ago without anti-virus protection. So a worm (or two) moved in and started routing pirated files. This morning it started being so &#8220;loud&#8221; on the network it ground everything else to a &hellip; <a href=\"https:\/\/www.fiveforks.com\/jeb\/2004\/11\/gandalf_the_whi\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"class_list":["post-256","post","type-post","status-publish","format-standard","hentry","category-tech"],"_links":{"self":[{"href":"https:\/\/www.fiveforks.com\/jeb\/wp-json\/wp\/v2\/posts\/256","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.fiveforks.com\/jeb\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.fiveforks.com\/jeb\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.fiveforks.com\/jeb\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.fiveforks.com\/jeb\/wp-json\/wp\/v2\/comments?post=256"}],"version-history":[{"count":0,"href":"https:\/\/www.fiveforks.com\/jeb\/wp-json\/wp\/v2\/posts\/256\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.fiveforks.com\/jeb\/wp-json\/wp\/v2\/media?parent=256"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.fiveforks.com\/jeb\/wp-json\/wp\/v2\/categories?post=256"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.fiveforks.com\/jeb\/wp-json\/wp\/v2\/tags?post=256"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}