|
|||||||||||
|
Re: Hacked web server
From: sunzi <sunzi(at)mod-x.co.uk>
Date: Tue Jan 14 2003 - 08:28:48 EST Rogelio,
on Nimda.E from Symantec:
The attachment received has been changed to: Sample.exe The dropped .dll file is now: Httpodbc.dll The worm now copies itself to the \%Windows% folder as Csrss.exe instead of Mmc.exe Try looking for c:\winnt\csrss.exe for the virus. Also, this isn't where the ncx99.exe came from. I'd do a thorough search for any usage of cmd.exe/root.exe in your web logs and start there, after taking it offline.
hth,
> At 1/10/2003 12:39 PM, Rogelio Vidaurri Courcelle wrote:
--Received on Tue Jan 14 19:10:04 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:56 EDT |
||||||||||
|
|||||||||||