w3k server

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Hi,
I am convinced my server has been compromised. After research I am certain
it has. However, I am still a little unsure as to how and what is going. It
appears that a program called Hacker Defender has been installed, thus hiding
its registry entries and files. I have found two registry entries and certain
tools shows that two exe files have been run, the kicker is those files are
no where to be found, they just do not exist on the system. There was also
log files that were deleted. And I found an odd reg entry with the name of
Andreas Haak, with no subfolders for the key, I assume that the children have
been hidden. It is apparent that the process used utilized something that MS
has designed called Alternate Data Streams(ADS). I have the tools and
instuctions on how to remove this rootkit, but I need a little more insight
on this before I clean it, I have isolated the server so it is useless to
them at the moment. One thing I have not been able to confirn is if w3k
server supports the ADS structure. Does anyone have any sorts of info on
this? Thanks.
.



Relevant Pages

  • Re: Convert InProcServer to OutProc
    ... searching the web, however, I didn't save a reference to them. ... Use regasm to register your .dll and create a type library ... Manually add appropriate AppId registry entries ... > I created a COM Server .NET dll that works fine as an InProcServer. ...
    (microsoft.public.dotnet.framework.interop)
  • Re: OWA 2003 times out.
    ... The mailbox store on the FE server shouldn't be an issue AFAIK - you just ... >> I'm not sure why you configured registry entries. ... >> minutes for Public and 24 hours for Private. ... >> Ben Winzenz ...
    (microsoft.public.exchange.admin)
  • Re: ADOConnection fail after a while in TThread
    ... It certainly can on Windows 2000. ... (this was the only way I could test my server under rapid ... There are registry entries that you have to ... but I found them relatively easily on Google. ...
    (borland.public.delphi.database.ado)
  • RE: ExcelUseConstantColumnWidth and Crystal Reports from server not wo
    ... On the server, Key registry entries were ... but when I copy it to the server it does not. ... On my PC when exporting a report, it works - columns are varible width to ... Dim objExcelOptions As ExcelFormatOptions = New ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Setup failed to configure sefrver
    ... >> When I look in the installation log, at the return value 3 section is ... >> Setup failed to configure the server. ... >> and setup error logs for more information. ... > not clear MSDE Windows Installer related registry entries (I still have 1 ...
    (microsoft.public.sqlserver.msde)