RE: strange process running on one of my serve rs

Security requires a multi-layered approach.

 

Having AV software is like have a fireman in full dress with a charged fire
hose in your house, ready to stop any fire.

 

Since the problem you are experiencing is considered Spyware/Adware, you
first need to understand how it got there. Most of the time, it is from
visiting web sites, which would indicate 1) some one was using that server
to surf the Internet and 2) IE security settings are not properly set.

 

John Tolmachoff

Engineer/Consultant/Owner

eServices For You

 

-----Original Message-----
From: Naboth Semwayo [mailto:naboths@xxxxxxxxxxxxxxxx] 
Sent: Wednesday, July 21, 2004 11:24 PM
To: [ExchangeList]
Subject: [exchangelist] RE: strange process running on one of my serve rs

 

http://www.MSExchange.org/

Its not enough to have a good antivirus software anymore is it?? What good
cooparate product can I get to stop these malicios codes and trojans from
entering my network at the proxy gateway?? I am running Symantec Coorp
Edition and trend Scanmail on my Exchange!!

-----Original Message-----
From: David Johnson [mailto:djohnson@xxxxxxxxx]
Sent: Thursday, July 22, 2004 1:02 AM
To: [ExchangeList]
Subject: [exchangelist] RE: strange process running on one of my servers

http://www.MSExchange.org/

It's a worm.  You can get more info about the specific worm here:
http://www.2-spyware.com/file-worm-dmsetup-e-exe.html

 


  _____  


From: Naboth Semwayo [mailto:naboths@xxxxxxxxxxxxxxxx] 
Sent: Wednesday, July 21, 2004 2:58 PM
To: [ExchangeList]
Subject: [exchangelist] strange process running on one of my servers

 

http://www.MSExchange.org/

Hi

 

Hope you can assist I have a process called e.exe running on my exchange
server. Now that wasnt there before. Anyone got a clue as to what it might
be??

 

------------------------------------------------------
List Archives: http://www.webelists.com/cgi/lyris.pl?enter=exchangelist
Exchange Newsletters: http://www.msexchange.org/pages/newsletter.asp
Exchange FAQ: http://www.msexchange.org/pages/larticle.asp?type=FAQ
------------------------------------------------------
Other Internet Software Marketing Sites:
World of Windows Networking: http://www.windowsnetworking.com
Leading Network Software Directory: http://www.serverfiles.com
No.1 ISA Server Resource Site: http://www.isaserver.org
Windows Security Resource Site: http://www.windowsecurity.com/
Network Security Library: http://www.secinf.net/
Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
------------------------------------------------------
You are currently subscribed to this MSEXchange.org Discussion List as:
naboths@xxxxxxxxxxxxxxxx
To unsubscribe visit
http://www.webelists.com/cgi/lyris.pl?enter=exchangelist 

---
Incoming mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.721 / Virus Database: 477 - Release Date: 7/16/2004

 

---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.721 / Virus Database: 477 - Release Date: 7/16/2004

------------------------------------------------------
List Archives: http://www.webelists.com/cgi/lyris.pl?enter=exchangelist
Exchange Newsletters: http://www.msexchange.org/pages/newsletter.asp
Exchange FAQ: http://www.msexchange.org/pages/larticle.asp?type=FAQ
------------------------------------------------------
Other Internet Software Marketing Sites:
World of Windows Networking: http://www.windowsnetworking.com
Leading Network Software Directory: http://www.serverfiles.com
No.1 ISA Server Resource Site: http://www.isaserver.org
Windows Security Resource Site: http://www.windowsecurity.com/
Network Security Library: http://www.secinf.net/
Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
------------------------------------------------------
You are currently subscribed to this MSEXchange.org Discussion List as:
johnlist@xxxxxxxxxxxxxxxxxxx
To unsubscribe visit
http://www.webelists.com/cgi/lyris.pl?enter=exchangelist 

Other related posts: