Re: SBS Server seems to have been compromised...HELP!

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Thanks you all for responding.
It turned out to be an infected workstation that was sending
unsolicired emails. The workstation received an email containing many
email addresses for which the sent emails were bounced. I removed the
infection and have not heard from ISP since.

Thanks again to all you gurus for the feedbacks.

C_O wrote:
> Looks like it is may not be your server that is compromised, but one
of the
> workstations on your LAN. If your ISP can get you a log of the
incident with
> precise time and date, you may be able to find the offending machine
by
> mining your server firewall outgoing logs, which should show the IP
of the
> workstation, and then locate the machine by looking at DHCP logs. You
should
> also block outgoing traffic to ports 135 and 445 on your firewall.
> First thing, though, you may want to physically disconnect all
suspect
> machines from the LAN until you can run a thorough virus scan on
them. By
> now all your workstations might be infected. Machines can also
reinfect each
> other as soon as they are reconnected, unless they are running a good
> resident antivirus.

.



Relevant Pages

  • Re: Remove mail
    ... most Outlook rules won't work if the workstation is turned ... But please explain why you need to forward emails for an out-of-office ... > for the server so in case the workstation os switched of no forwarding is ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: Lost emails and folders on network OE6
    ... you can try locating the data on the network and it may be OK for a while but eventually you'll run into the very problem/issue you're having now. ... They can check their emails perfectly, download them and view, answer, ... Our network is running XP SP3 on the workstations, the Server has Windows ... workstation to check if this affected the issue at all, ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
  • Re: Lost emails and folders on network OE6
    ... I'm finding that a couple of yeachers log on in a morning to find that ... Outlook Express has deleted any and all emails received the day before, ... Our network is running XP SP3 on the workstations, the Server has Windows ... workstation to check if this affected the issue at all, ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
  • RE: Lost emails and folders on network OE6
    ... any folders I set up for them as well. ... They can check their emails perfectly, download them and view, answer, ... Our network is running XP SP3 on the workstations, the Server has Windows ... workstation to check if this affected the issue at all, ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
  • Worm.Automat.AHB Worm (also perhaps known as W32.Swen.A@mm
    ... My NAV shows updated through 9/18/03. ... Yet each time these emails come in, ... the criteria of the worm, ... >with the SP3 Security update handled the infection by ...
    (microsoft.public.security.virus)