New virus/script problem

  • Thread starter Thread starter Jeff
  • Start date Start date
J

Jeff

I am wondering if anyone has recently encountered a
situation where something seems to be running on a server
that is constantly sending out packets to the internet to
destination ports 25, 80, obviously scanning for holes,
but I can't seem to find anything. It sends out so much
info that when that server is connected to the network I
can't even ping an IP address of a computer on the
internet. I am running SAV Corp 8.1 with up to date
virus defs and it finds nothing. I figure it must be a
script of some sort, but I was on a call with Microsoft
for 7 hours yesterday and they couldn't figure it out.
Any ideas. Thanks

Jeff
 
Sounds like blaster infection or something to that affect. I know blaster
uses port 135 scans but Have you did a netstat -an or netstat -ao to
determine if there are connections or did a sniffer trace to see where they
are going? Is there any services that aren't familiar with that might be
installed? Just wild guesses but that's about where i'd start.

--
* ----------------------------------------- *
* Steve Schofield - MCP, CCA
* (e-mail address removed)
*
* Microsoft MVP - ASP.NET
* http://www.adminblogs.com
* ----------------------------------------- *
 
Back
Top