RE: Being Attacked...HELPED

  • From: "Clarke, Scott" <Scott.Clarke@xxxxxxxxxxxx>
  • To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx>
  • Date: Thu, 5 May 2005 16:02:07 -0230

I have noticed that the initial attack had come from one of our test networks 
that unfortunately had the fw wide open.  I have since closed it up.

I haven't seen any more attacks now for about an hour now.  Thanks for all the 
help..will keep you updated.

Scott

-----Original Message-----
From: Ball, Dan [mailto:DBall@xxxxxxxxxxx]
Sent: Thursday, May 05, 2005 3:52 PM
To: [ISAserver.org Discussion List]
Subject: [isalist] RE: Being Attacked...HELPED


http://www.ISAserver.org

Not much to that one, if that is what it is...
http://securityresponse.symantec.com/avcenter/venc/data/w32.dos.trinoo.h
tml

-----Original Message-----
From: Danny [mailto:nocmonkey@xxxxxxxxx] 
Sent: Thursday, May 05, 2005 14:13
To: [ISAserver.org Discussion List]
Subject: [isalist] RE: Being Attacked...HELPED

http://www.ISAserver.org

On 5/5/05, Clarke, Scott <Scott.Clarke@xxxxxxxxxxxx> wrote:
> Easier said than done.  We have 26 branch offices with their own
routers/switches.  Is there
> a removal/detection tool for Trinoo because I believe the infection is
here at our main office?

Why do you think it is Trinoo?  If your AV software detected, then it
should be quite capable of removing it.  Patch your systems, ASAP.

Delete C:\WINDOWS\SYSTEM\service.exe  AND
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\"System
Services"="service.exe"

...D

------------------------------------------------------
List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
------------------------------------------------------
Other Internet Software Marketing Sites:
World of Windows Networking: http://www.windowsnetworking.com
Leading Network Software Directory: http://www.serverfiles.com
No.1 Exchange Server Resource Site: http://www.msexchange.org
Windows Security Resource Site: http://www.windowsecurity.com/
Network Security Library: http://www.secinf.net/
Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
------------------------------------------------------
You are currently subscribed to this ISAserver.org Discussion List as: 
scott.clarke@xxxxxxxxxxxx
To unsubscribe visit http://www.webelists.com/cgi/lyris.pl?enter=isalist
Report abuse to listadmin@xxxxxxxxxxxxx


Other related posts: