Continuos infestation

Continuos infestation

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Continuos infestation Fabio 06-01-2006
Posted by Fabio on June 1, 2006, 9:15 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I have a w2003 r2 server with iis6 and ftp ,smtp and terminal server
active.
The iis6 is active for asp page and php page.
The two site in this web server allow upload image for the community.
Recently the server are infected by backdoor trojan etc.
I scan with many antivirus,antispyware etc and i think the server is
now clean.
But often, i see two service (spyware) installed and started :

D.N.S. DNS Server service (dns.exe) (not real dns)
Remote Administrator Service (r_server.exe)

I remove with
sc delete

But often this two service is reinstalled, antivirus often clean
another files backdoor etc.

I don't understand how a user web account with your privileges succeeds
to install a service
if the install service is only admin privileges?

The http upload can bypass script controll estension but the http
privileges cannot install a service.
yesterday this backdoor restart the server and tried to register to web
site a wrong url
that deactivated the service ( es.of wrong url :
http://www.mysite.it:80:localIP/).
How is possible by scripting with web privileges?
How Is possible by scripting increase the privileges?

HELP ME


Posted by =?Utf-8?B?UGFuZGFfbWFu?= on June 1, 2006, 4:45 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
"Fabio" wrote:

> I have a w2003 r2 server with iis6 and ftp ,smtp and terminal server
> active.
> The iis6 is active for asp page and php page.
> The two site in this web server allow upload image for the community.
> Recently the server are infected by backdoor trojan etc.
> I scan with many antivirus,antispyware etc and i think the server is
> now clean.
> But often, i see two service (spyware) installed and started :
>
> D.N.S. DNS Server service (dns.exe) (not real dns)
> Remote Administrator Service (r_server.exe)
>
> I remove with
> sc delete
>
> But often this two service is reinstalled, antivirus often clean
> another files backdoor etc.
>
> I don't understand how a user web account with your privileges succeeds
> to install a service
> if the install service is only admin privileges?
>
> The http upload can bypass script controll estension but the http
> privileges cannot install a service.
> yesterday this backdoor restart the server and tried to register to web
> site a wrong url
> that deactivated the service ( es.of wrong url :
> http://www.mysite.it:80:localIP/).
> How is possible by scripting with web privileges?
> How Is possible by scripting increase the privileges?
>
> HELP ME
>
>



Scan and clean your computer using the instructions in my site:
http://pandaman.my.contact.bg
because I think it is possible for the server to be infected and not cleaned


I'm not an expert for servers so for qualitive answer to your other
questions , I hope someone else reply to you.

Panda_man
--
Bronze level Contributor
http://pandaman.my.contact.bg
Please , rate posts

Similar ThreadsPosted
TROJAN Infestation February 14, 2008, 5:25 pm

The site map in XML format XML site map

Contact Us | Privacy Policy