spexta trojan installs to protected folder



Running XP SP2,

I have just seen a curious virus identified by Symantec Corporate 10.1. The virus is called trojan.spexta and is a mass mailing worm. The computer is locked down. Users are only given limited accounts. I am the only user who logs in as Admin and I assure you I am careful in this account. The issue I am having and according to the logs, is that this particular virus somehow manages to write directly to c: and c:\windows\system32 with a file called eventmgr.exe. I have seen this process eat 100% of the system resources. I think that it might be getting in through a users web mail of choice. This system is fully patched so how is this possible? As far as I can fathom, this virus must be using some exploit that overrides folder security.
.



Relevant Pages

  • Re: [fw-wiz] Blocking email through the web services
    ... >> scanning engine to scan incoming http traffic. ... > Virus scanning on HTTP helps, if viruses are all you worry about. ... unfortunately going through the output from the proxy logs consumes ... We use a proxy appliance, ...
    (Firewall-Wizards)
  • Re: Secured IIS Project - msg 2
    ... DSHIELD. ... logs to his addresses until further notice. ... Delivery co-sponsored by Trend Micro ... TREND MICRO REAL-TIME VIRUS ALERTS ...
    (NT-Bugtraq)
  • Re: if edb.log was deleted
    ... And a virus would likely ruin the log so Exchange would crash trying to read ... This posting is provided "AS IS" with no warranties, and confers no rights. ... And the exchange transaction logs will not have ...
    (microsoft.public.exchange.admin)
  • Re: computer sending emails
    ... You can take the time to download and install it, ... Usenet Groups are not the place to get help with HJ Logs, ... Lipman as he is the resident anti virus guy... ... Sorry about the rude reply from legos... ...
    (microsoft.public.windowsxp.security_admin)
  • SUMMARY: System logging in batches
    ... > This does work, however, the STDOUT part logs to the file in batches. ... > are not the intended recipient you are strictly prohibited from using, ... We use reasonable endeavours to virus scan all ...
    (SunManagers)