Re: Virus is getting domain account listing

From: Ronda Allen (ronda.allen_at_state.co.us)
Date: 05/10/04

  • Next message: Harlan Carvey: "RE: Virus is getting domain account listing"
    Date: Mon, 10 May 2004 12:21:53 -0600
    To: <focus-ms@securityfocus.com>
    
    

    About a year ago we experienced the same issue when 2 machines on our
    network were infected with a Trojan called Backdoor.gen. We could see
    failed logon attempts in the Security Event Viewer on the DC's on the
    Windows 2000 domain ....and this will also tell you what machine on your
    network is infected. When you find the machine that is attacking your
    network you should run a full virus scan and see if the trojan is
    detected. Strange thing is that the Trojan was not detected until a
    full scan was run on the infected machine...even though the dats were up
    to date.

    RLA

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Harlan Carvey: "RE: Virus is getting domain account listing"

    Relevant Pages

    • Re: Expert Needed For Paid Interview...
      ... Is my XP network going to go kaput when I turn off UPnP and how do I fix it? ... I'm such a tyro when it comes to networking and security - I was thrilled when I finally got all the XP computers in the house sharing files so I could back stuff up. ... and probably the 'best' trojan seeker on the market. ... So I went back to XP1, dumped using system restore,Recycle Bin is not longer used, and Windows System Backup Files deleted since root-kits can make them useless just the same. ...
      (rec.aquaria.freshwater.misc)
    • Solution to mIRC and Secedit Virus Networking Problems
      ... threads in all 4 related to the recent outbreak of mIRC/Secedit trojan... ... for has a small network consisting of several w2kpro computers networked as ... use the backup security database template to restore the system to its ... right click on "security and configuration analysis" and click on "open ...
      (microsoft.public.security)
    • Solution to mIRC and Secedit Virus Networking Problems
      ... threads in all 4 related to the recent outbreak of mIRC/Secedit trojan... ... for has a small network consisting of several w2kpro computers networked as ... use the backup security database template to restore the system to its ... right click on "security and configuration analysis" and click on "open ...
      (microsoft.public.win2000.security)
    • Re: Windows 2000 users accounts get locked out
      ... it looks like a trojan that came into my ... >Typically that sounds like an outside the network attack ... >consider is the possibility a machine on your network has ... >firewall configured with a default block all outbound ...
      (microsoft.public.win2000.security)
    • Re: Solution to mIRC and Secedit Virus Networking Problems
      ... > threads in all 4 related to the recent outbreak of mIRC/Secedit trojan... ... > work for has a small network consisting of several w2kpro computers ... then double click on "Security and Configuration Analysis" ...
      (microsoft.public.win2000.security)