Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. The Lounge
  3. virus problem??

virus problem??

Scheduled Pinned Locked Moved The Lounge
helpcomsysadminquestion
10 Posts 7 Posters 0 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • P Offline
    P Offline
    PSK_
    wrote on last edited by
    #1

    I am having strange problem hope any body can help me, in my remote server different folders with strange name like "xxxx com1 xxx " with nested folders like "xxxxxxxx/incantesimù/27012005/1pt3 /kill bill 1 et 2/aux  /scan by scrutchy/tagg by scrutchy/up by scrutchy" and some folders without any name are automatically created and each folder contains some .rar file its taking server space in GBS, some of the folders i can delete manually but others i can't i am getting message that the .rar file is used by some other process. Please help me to solve this problem.

    [

    ](HTTP://PRAKASH-K.BLOGSPOT.COM)

    A R 2 Replies Last reply
    0
    • P PSK_

      I am having strange problem hope any body can help me, in my remote server different folders with strange name like "xxxx com1 xxx " with nested folders like "xxxxxxxx/incantesimù/27012005/1pt3 /kill bill 1 et 2/aux  /scan by scrutchy/tagg by scrutchy/up by scrutchy" and some folders without any name are automatically created and each folder contains some .rar file its taking server space in GBS, some of the folders i can delete manually but others i can't i am getting message that the .rar file is used by some other process. Please help me to solve this problem.

      [

      ](HTTP://PRAKASH-K.BLOGSPOT.COM)

      A Offline
      A Offline
      Anna Jayne Metcalfe
      wrote on last edited by
      #2

      It sounds like your server has been hacked. If I were you I'd be giving it a thorough security check and cleanup by now. Anna :rose: Riverblade Ltd - Software Consultancy Services Anna's Place | Tears and Laughter "Be yourself - not what others think you should be" - Marcia Graesch "Anna's just a sexy-looking lesbian tart" - A friend, trying to wind me up. It didn't work.

      D 1 Reply Last reply
      0
      • A Anna Jayne Metcalfe

        It sounds like your server has been hacked. If I were you I'd be giving it a thorough security check and cleanup by now. Anna :rose: Riverblade Ltd - Software Consultancy Services Anna's Place | Tears and Laughter "Be yourself - not what others think you should be" - Marcia Graesch "Anna's just a sexy-looking lesbian tart" - A friend, trying to wind me up. It didn't work.

        D Offline
        D Offline
        Darren_vms
        wrote on last edited by
        #3

        Sounds more like a virus, can't remember the one looking now. Darren

        D 1 Reply Last reply
        0
        • D Darren_vms

          Sounds more like a virus, can't remember the one looking now. Darren

          D Offline
          D Offline
          Darren_vms
          wrote on last edited by
          #4

          Could be off the mark here but it could be Netsky The worm will also copy itself to various peer-to-peer shared folders as the following files: Look here for the list http://www.sophos.com/virusinfo/analyses/w32netskyp.html Hope this helps. Darren

          1 Reply Last reply
          0
          • P PSK_

            I am having strange problem hope any body can help me, in my remote server different folders with strange name like "xxxx com1 xxx " with nested folders like "xxxxxxxx/incantesimù/27012005/1pt3 /kill bill 1 et 2/aux  /scan by scrutchy/tagg by scrutchy/up by scrutchy" and some folders without any name are automatically created and each folder contains some .rar file its taking server space in GBS, some of the folders i can delete manually but others i can't i am getting message that the .rar file is used by some other process. Please help me to solve this problem.

            [

            ](HTTP://PRAKASH-K.BLOGSPOT.COM)

            R Offline
            R Offline
            Ryan Roberts
            wrote on last edited by
            #5

            Looks like your being used as a wares drop site. Do you have FTP enabled? and if so it is anonymous? Lots of warez kiddies run scanners looking for open anonymous FTP sites to drop stuff in. Of course, you could always deny delete permission to the ftp root directory and build up a nice collection of 0-Day scr33ners / hampster pornography etc :P Ryan

            P 1 Reply Last reply
            0
            • R Ryan Roberts

              Looks like your being used as a wares drop site. Do you have FTP enabled? and if so it is anonymous? Lots of warez kiddies run scanners looking for open anonymous FTP sites to drop stuff in. Of course, you could always deny delete permission to the ftp root directory and build up a nice collection of 0-Day scr33ners / hampster pornography etc :P Ryan

              P Offline
              P Offline
              PSK_
              wrote on last edited by
              #6

              i think you r correct because all folders are present in ftp root folder only .. i have changed the security settings, but 1 more problem how to delete those existing folders.

              [

              ](HTTP://PRAKASH-K.BLOGSPOT.COM)

              R J 2 Replies Last reply
              0
              • P PSK_

                i think you r correct because all folders are present in ftp root folder only .. i have changed the security settings, but 1 more problem how to delete those existing folders.

                [

                ](HTTP://PRAKASH-K.BLOGSPOT.COM)

                R Offline
                R Offline
                Ryan Roberts
                wrote on last edited by
                #7

                Use the IIS config tool to shutdown IIS, then delete the warez collection. Ryan

                R 1 Reply Last reply
                0
                • R Ryan Roberts

                  Use the IIS config tool to shutdown IIS, then delete the warez collection. Ryan

                  R Offline
                  R Offline
                  Roger Alsing 0
                  wrote on last edited by
                  #8

                  but do remember to burn them to a cd first..

                  J 1 Reply Last reply
                  0
                  • R Roger Alsing 0

                    but do remember to burn them to a cd first..

                    J Offline
                    J Offline
                    Jerry Hammond
                    wrote on last edited by
                    #9

                    :laugh::laugh::laugh: He said this was like painstakingly assembling the first layer of a house of cards, then boasting that the next 15,000 layers were a mere formality.--The Code Book, pp. 331 Toasty0.com DotNetGroup.org

                    1 Reply Last reply
                    0
                    • P PSK_

                      i think you r correct because all folders are present in ftp root folder only .. i have changed the security settings, but 1 more problem how to delete those existing folders.

                      [

                      ](HTTP://PRAKASH-K.BLOGSPOT.COM)

                      J Offline
                      J Offline
                      James R Twine
                      wrote on last edited by
                      #10

                      Take a look at http://www.deletefxpfiles.com[^] and if interested drop a private email to custserv(AT)jrtwine.com and I will hook you up with a free key for Professional Edition of the product.    Peace! -=- James


                      If you think it costs a lot to do it right, just wait until you find out how much it costs to do it wrong!
                      Tip for new SUV drivers: Professional Driver on Closed Course does not mean your Dumb Ass on a Public Road!
                      DeleteFXPFiles & CheckFavorites

                      1 Reply Last reply
                      0
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Don't have an account? Register

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • World
                      • Users
                      • Groups