|
Got this from Peter Kruse who pointed me to http://www.norman.no/
- thanks! The worm W32/Nimda.A@mm is spreading very
fast. It may arrive as an email with the following charteristics: It may not remove everything – but it may
stop it long enough to see what damage was done. Steve Clark Clark Systems
Support, LLC www.clarksupport.com -----Original
Message----- Stupid Ev
Question #327: eml files can be executed? Thanks, Evan -----Original
Message----- 1
Unplug servers form network. 2
use ERD to recover. 3
send users home. 4
clean clients. -----Original
Message----- My
network is slammed with some uknown virus of some sort.....Both my NT 4.0
servers running MS-Exchange 6.5 have about 2300 alien files which were
deleted....a "readme.eml" is being executed by all users somehow
automtically and its infecting all my NT domain. I can not
Ctrl+Alt+Delete to log into any of the servers.....the display shows
"initialization of the dynamic link library C:\WINNT\system32\USER32.dll
failed. The process is terminating abnormally" OKaying this results
in no effects....all servers have this displayed onscreen. For the ones
that have admin already logged in, Services (control panel, settings) can not
be accessed! "access to the specified device, path, or file is
denied"....it seems this virus has locked onto this element. PDC is
running Exchange (I know, never put'em together...but we're still cleaning up
after previous SysAdmins here), and this has gone bezerk as well, with the same
message onscreen. Norton/Symantec doesn't recognize
"readme.eml"....who out there can shine a flashlite in this dark
mess? thanks in advance. Terry http://www.sunbelt-software.com/ntsysadmin_list_charter.htm http://www.sunbelt-software.com/ntsysadmin_list_charter.htm http://www.sunbelt-software.com/ntsysadmin_list_charter.htm |
Title: serious network down...readme.eml??
- serious network down...readme.eml?? Terry Manolakos
- RE: serious network down...readme.eml?? Zangara, Jim
- RE: serious network down...readme.eml?? Admin
- Re: serious network down...readme.eml?? James Gosnold
- RE: serious network down...readme.eml?? James Gosnold
- Re: serious network down...readme.eml?? Kelly Borndale
- RE: serious network down...readme.eml?? ebrastow
- RE: serious network down...readme.eml?? Adam Meixler
- RE: serious network down...readme.eml?? Clark, Steve
- RE: serious network down...readme.eml?? Admin
- RE: serious network down...readme.eml?? Miley, Dan
- RE: serious network down...readme.eml?? Clark, Steve
- RE: serious network down...readme.eml?? Terry Manolakos
- Fw: serious network down...readme.eml?? TDI Custom Computers
- RE: serious network down...readme.eml?? Dean Cunningham
- Re: serious network down...readme.eml?? TDI Custom Computers
