Couldn't log into Windows Server because of a virus

Couldn't log into Windows Server because of a virus

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Couldn't log into Windows Server because of a virus Hammett 01-21-2007
Posted by David H. Lipman on January 22, 2007, 4:18 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| I booted the server from something called Winternal ERD Commander 2005. I can
| get access to windows file system now.
|
| I scanned the server with Nod32 on-demand scanner. Every executable file in
| the windows directory and sub directories were infected with Win32/Parite.B
|
| when i try to log on to Windows, the computer automatically logs. I tried to
| log on from Safe Mode as well, but that didn't work.
|
| Any advice will be highly appreciated.
|
| Thank you
|
| Ahmed Athif
| (MCSA:Security, MCSE:Security, CCNA,CCNP,CCSP, Security+)
| --------------------------------------
|

The Parite is a True file infecting virus and spreads quite well. In fact, I
have actually
seen Trojans infected with it.

Someone wasn't using the server as a server, They were using it as a
workstation and didn't
practice Safe Hex. You have an issue here that needs to be resolved ASAP.

Follow Malke's advice !

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by =?Utf-8?B?SGFtbWV0dA==?= on January 23, 2007, 2:56 am
If you were  Registered and logged in, you could reply and use other advanced thread options

--
Ahmed Athif
(MCSA:Security, MCSE:Security, CCNA,CCNP,CCSP, Security+)


"David H. Lipman" wrote:

>
> | I booted the server from something called Winternal ERD Commander 2005. I can
> | get access to windows file system now.
> |
> | I scanned the server with Nod32 on-demand scanner. Every executable file in
> | the windows directory and sub directories were infected with Win32/Parite.B
> |
> | when i try to log on to Windows, the computer automatically logs. I tried to
> | log on from Safe Mode as well, but that didn't work.
> |
> | Any advice will be highly appreciated.
> |
> | Thank you
> |
> | Ahmed Athif
> | (MCSA:Security, MCSE:Security, CCNA,CCNP,CCSP, Security+)
> | --------------------------------------
> |
>
> The Parite is a True file infecting virus and spreads quite well. In fact, I
have actually
> seen Trojans infected with it.
>
> Someone wasn't using the server as a server, They were using it as a
workstation and didn't
> practice Safe Hex. You have an issue here that needs to be resolved ASAP.
>
> Follow Malke's advice !
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>
>

Hi Dave and Malke,

Thank you very much for your advice. I have restored the server from backups
1 month old. And there was a serious flaw on the network, which I've been
able to track and fix. Once again, thank you

Regards,


Posted by Malke on January 23, 2007, 8:35 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hammett wrote:

(OP's response written below signature delimiter and stripped; here it
is for completeness):

***
Thank you very much for your advice. I have restored the server from
backups
1 month old. And there was a serious flaw on the network, which I've been
able to track and fix. Once again, thank you
***

I'm glad you were able to fix this. Don't forget to check all
workstations too.


Malke
--
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"
MS-MVP Windows - Shell/User

Posted by David H. Lipman on January 23, 2007, 4:19 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

***
Thank you very much for your advice. I have restored the server from
backups
1 month old. And there was a serious flaw on the network, which I've been
able to track and fix. Once again, thank you
***


I suggest scanning the "restored" server and any systems that communicated with
it.


Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go
through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal
Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the
PC.

You can choose to go to each menu item and just download the needed files or you
can
download the files and perform a scan in Normal Mode. Once you have downloaded
the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode
[F8 key
during boot] and re-run the menu again and choose which scanner you want to run
in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive
PDF help
file. http://www.ik-cs.com/multi-av.htm

Additional Instructions:
http://pcdid.com/Multi_AV.htm


* * * Please report back your results * * *




--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Similar ThreadsPosted
Windows 2003 server - firewall / virus protection March 7, 2006, 7:06 pm
Security issue with MS Exchange and Windows 2003 Server November 28, 2005, 5:05 pm
Win 2K Server anti virus July 25, 2005, 4:49 pm
Anti-Virus on Server - Advice September 8, 2005, 7:33 am
setiathome virus on a 2003 server October 24, 2005, 3:20 am
Re: Server Infected by virus and unable to clean May 31, 2007, 2:04 am
anti-virus for 2008 Server Core ? October 6, 2008, 3:06 pm
Virus Scan SCSI HDD for Server HP ML370 Series G4 Series October 13, 2008, 10:06 am
my network server has a virus and i can not conect to the network. November 1, 2008, 6:19 pm
Virus on Windows Xp Embedded October 19, 2005, 2:28 pm

The site map in XML format XML site map

Contact Us | Privacy Policy