1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Trojans in Exchange Log Files

Discussion in 'Malware and Virus Removal Archive' started by hkelley, 2004/09/17.

Thread Status:
Not open for further replies.
  1. 2004/09/17
    hkelley

    hkelley Inactive Thread Starter

    Joined:
    2002/11/15
    Messages:
    17
    Likes Received:
    0
    During a routine deep virus scan we discovered two trojans in Exchange log files and we are not sure how to handle it. The virus report displays the following:

    HTML ZEROLIN C C:\Program Files\Exchngsvr\mdbdata\E00000593.log 8/27/2004
    JS ZEROLIN A C:\Program Files\Exchngsvr\mdbdata\E00006f1.log 9/27/2004

    It is my understanding that neither of these is "cleanable." The general recommendation is to delete the files containing these trojans, however, I am under the impression that to delete these two log files could wreck havoc in my Excahnge Server.

    Some advice would be appreciated.
     
  2. 2004/09/17
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    Not sure about the criticality of those exchange log files but if your exchange server is any where near up to date on security patches, you should be safe enough. Pretty good discussion of this critter Here but basically it appears that if you have applied MS03-040, MS04-013, MS04-025 you will be OK.
     
    Newt,
    #2

  3. to hide this advert.

  4. 2004/09/17
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    I'm also unsure what deleting the logs would do, but the JS ZEROLIN A C:\Program Files\Exchngsvr\mdbdata\E00006f1.log 9/27/2004 file is very suspicious looking for sure. Notice it's dated for the 27th of this month, yet it's only the 17th? I personally would open them and try to locate the infection. No doubt some scripting, and should be able to spot it and edit it out.
     
  5. 2004/09/17
    hkelley

    hkelley Inactive Thread Starter

    Joined:
    2002/11/15
    Messages:
    17
    Likes Received:
    0
    Ooops, that date was a typo...should read 9/7/2004.

    Thanks for suggestion...any additional thoughts?
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.