G
Guest
I was implementing security auditing on my w2k SBS server and i noticed that
my d:> disk space started to diminish by about 100mb per minute. Thinking it
was the audit policy, I turned it off. It carried on, so I disconnected the
internet and it stopped! So, I did a netstat and found that my server was
connected to 150.188.1.10:3835, 195.70.236.164: on various ports. I blocked
these ports and ip address's. Went into task manager and found the following
strange services: server.exe, syshosts.exe, WinSRV.exe, syshost.exe and
SL14F2.tmp. I tried to stop all of them, but I was not allowed except for
SL14F2.tmp. I ran Trend Anti-virus on all my workstations and server, with
the latest pattern file. It came up with a few virus's which were deleted or
quarantined. I then ran adaware, which found a few bits and pieces and
removed them as well.
As it stands now, my d:> is 55GB in size. 26.92GB is accounted for in files
and i have 2.98GB free space. Where did 14GB go? I have searched with
utilitities to no avail and have even done a attrib search in DOS. Has anyone
got any ideas? Thanks for your time!
my d:> disk space started to diminish by about 100mb per minute. Thinking it
was the audit policy, I turned it off. It carried on, so I disconnected the
internet and it stopped! So, I did a netstat and found that my server was
connected to 150.188.1.10:3835, 195.70.236.164: on various ports. I blocked
these ports and ip address's. Went into task manager and found the following
strange services: server.exe, syshosts.exe, WinSRV.exe, syshost.exe and
SL14F2.tmp. I tried to stop all of them, but I was not allowed except for
SL14F2.tmp. I ran Trend Anti-virus on all my workstations and server, with
the latest pattern file. It came up with a few virus's which were deleted or
quarantined. I then ran adaware, which found a few bits and pieces and
removed them as well.
As it stands now, my d:> is 55GB in size. 26.92GB is accounted for in files
and i have 2.98GB free space. Where did 14GB go? I have searched with
utilitities to no avail and have even done a attrib search in DOS. Has anyone
got any ideas? Thanks for your time!