Re: w95.hybris.worm on SBS 2003

From: Bill Sanderson (Bill_Sanderson_at_msn.com.plugh.org)
Date: 05/19/04

  • Next message: Tom: "Trojan Horse"
    Date: Wed, 19 May 2004 11:30:53 -0400
    
    

    Mike - I lean towards your explanation, but I'm not familiar enough with
    Exchange to say what is happening.

    There are good SBS groups here, though:

    microsoft.public.windows.server.sbs (first choice)
    Microsoft.public.backoffice.smallbiz2000 (second choice)

    "Mike" <mike008us@yahoo.com> wrote in message
    news:%23An$hJUPEHA.2876@TK2MSFTNGP09.phx.gbl...
    > By "sure" I meant, do you know what the \exchsrvr\blocked\ directory is
    > used
    > for. This is the only place the virus is found during a scan at night.
    > I'm
    > fairly confident what this directory is used for(see last post), but was
    > looking for confirmation.
    >
    > Complicated beast? Wipe it clean? I'm sorry this isn't a server group I
    > posted to, but those are neither realistic or necessary options. I've
    > recovered many un-bootable servers that others had not been able to.
    > Server
    > NOS' are not scary and mysterious, but rather operate much like their
    > desktop OS counterparts with added features. My main reason for posting
    > here was input on the particular virus and the tie in with Exchange.
    >
    > Unless someone can contribute something related to this virus and Exchange
    > don't waste your time.
    >
    > Thanks,
    > Mike
    >
    >
    > "Malke" <malke@nospoonnotreally.com> wrote in message
    > news:%23IWCVLNPEHA.1312@TK2MSFTNGP12.phx.gbl...
    >> Mike wrote:
    >>
    >> > Are you sure? After watching this directory it would make sense the
    >> > Exchange may be putting any "executable" files in the \blocked
    >> > directory.
    >> >
    >> > Tell me if I'm wrong.
    >> >
    >> > Thanks,
    >> > Mike
    >> >
    >>
    >> How could I be "sure" about what is going on with a server I've never
    >> seen, without any knowledge of its filters or firewall settings, etc.?
    >> A server is a complicated beast and if you are unsure about your
    >> client's security, wipe the server and restore it with one of his
    >> ghosted backup images. Otherwise, I suppose you could watch it very
    >> closely to see if there is a hole somewhere and security has been
    >> compromised. Who has physical access to the machine? If it is open to
    >> anyone in the office or from outside, then there is no real security.
    >>
    >> Malke
    >> --
    >> MS MVP - Windows Shell/User
    >> Elephant Boy Computers
    >> www.elephantboycomputers.com
    >> "Don't Panic!"
    >
    >


  • Next message: Tom: "Trojan Horse"

    Relevant Pages

    • Re: Sharepoint Administrator and SubWebs
      ... Mike, I suspec5t you are right about STS, being that the website is ... > Subweb is the term used in STS for what in WSS is called sub-sites. ... > Can you also please state the Operating System being used for your Exchange ... > in which case WSS will not run at all on theat server only WSS. ...
      (microsoft.public.sharepoint.windowsservices)
    • Re: RPC over HTTP, NAT firewall, authentication problems
      ... This solution cost me $312.00 Mike, ... exchange man….” is selected. ... Restart the server. ... "To configure the RPC proxy server to use specified ports for RPC over HTTP" ...
      (microsoft.public.exchange.setup)
    • Re: Moving from ISP Mail to Exchange
      ... guide, and deployment guide)? ... Mike ... > Get Exchange loaded and configured on your mailbox server. ... Get SP1 for Exchange and Windows on there as well. ...
      (microsoft.public.exchange.setup)
    • Re: Exchange Disaster Recovery Server
      ... The backup server is setup also in the lab so I ... >>> The Microsoft Exchange Server computer is not available. ... >>> Microsoft Exchange Server Information Store ...
      (microsoft.public.exchange2000.admin)
    • Exchange 2003 SP1 periodicaly losses connection to active directory for about 30 minutes
      ... We have active directory in two servers but the mail server fails to ... the promotion of the server to active directory the exchange was up. ... After a Domain Controller is promoted to a Global Catalog, ...
      (microsoft.public.exchange.connectivity)

  • Quantcast