Re: aiRstRiKe @ uLtiMate-fXp-CreW Virus?

From: Lanwench [MVP - Exchange] (lanwench_at_heybuddy.donotsendme.unsolicitedmail.atyahoo.com)
Date: 08/31/04


Date: Tue, 31 Aug 2004 14:34:56 -0400

What antivirus software have you used to scan? Did you have some installed
to begin with?

You need to make sure you run good, constantly updated AV software on all
boxes - and run IISLockdown/URLScan on IIS, and segregate any public web
server from your LAN by putting it in your DMZ.

Got good backups?

Jeremy wrote:
> Does anyone have any information about a virus that takes over IIS and
> presents the following error message when pullling up the default web
> site on the server?
>
> 220 aiRstRiKe @ uLtiMate-fXp-CreW 530 Not logged in. 530 Not logged
> in. 530 Not logged in. 530 Not logged in. 331 User name okay, need
> password. 530 Not logged in. 530 Not logged in. 421 Maximum session
> time exceeded - closing.



Relevant Pages

  • RE: Hacked web server
    ... I would also suggest running the IIS lock down tool. ... The above shows that your server is susceptible to a vulnerability detailed ... install the cumulative IIS patch described in Microsoft Security Bulletin ... had antivirus software with relatively current definitions). ...
    (Incidents)
  • IIS 6, DMZ and antivirus
    ... Is it current practice to install an antivirus software on an IIS 6.0 server ... even though it has been hardened and placed in a DMZ? ...
    (microsoft.public.security)
  • Re: IIS services stopped abrubtly
    ... IIS stopping can be ... or more hardening checklists such as the ones at the Microsoft URL above. ... > red worm requests, including .ida file requests, to WWW ... The antivirus software acts as if the ...
    (microsoft.public.inetserver.iis.security)
  • Re: SQL2000 Cluster and virus software
    ... filter driver off in situations like you describe. ... MVP - Windows Server - Clustering ... > You should able to use antivirus software, just exclude the MSCS, MSDTC, ...
    (microsoft.public.sqlserver.clustering)
  • Re: SQL2000 Cluster and virus software
    ... on a dedicated and secured DBMS installation. ... server administrators in conjuction with the AV vendor to properly secure ... MVP - Windows Server - Clustering ... > â??Disable or do not install antivirus software on your clusterâ?? ...
    (microsoft.public.sqlserver.clustering)