Windows BBS The Place for Microsoft Windows Support! Windows, Support, Help Site

Go Back   Windows BBS > Security > Malware and Virus Removal

Malware and Virus Removal Problems removing malware/viruses? Get help from our Malware removal experts.

Register your FREE account to unlock additional features at WindowsBBS.com
Register
Welcome to WindowsBBS.com
Microsoft Windows Support

Mission Statement

WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.

Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.


Discussion Forums
Operating Systems
Windows 7 Windows 7
Windows Vista Windows Vista
Windows XP Windows XP
Windows Server System Windows Server System
Windows 2000 Windows 2000
Windows 95/98/Me/NT Windows 95/98/Me/NT
Internet & Networking
Networking
Internet Explorer
Microsoft Mail
Firefox, Thunderbird
      & SeaMonkey

General Internet
Security
General Security
Malware and Virus
     Removal

Other
Other Software
Hardware
Test Posts
Community
Introductions
General Discussions
Comments
      & Suggestions

News @ WindowsBBS

Forum Sponsor
 Image

Closed Thread
 
LinkBack Thread Tools
Old 17th September 2004   #1
Member
 
Profile:
Join Date: Nov 2002
Location: Florida
Posts: 18
Computer Experience:
Experienced
hkelley Reputation Level


Trojans in Exchange Log Files

During a routine deep virus scan we discovered two trojans in Exchange log files and we are not sure how to handle it. The virus report displays the following:

HTML ZEROLIN C C:\Program Files\Exchngsvr\mdbdata\E00000593.log 8/27/2004
JS ZEROLIN A C:\Program Files\Exchngsvr\mdbdata\E00006f1.log 9/27/2004

It is my understanding that neither of these is "cleanable." The general recommendation is to delete the files containing these trojans, however, I am under the impression that to delete these two log files could wreck havoc in my Excahnge Server.

Some advice would be appreciated.

hkelley is offline  
Didn't find the information you thought to find?
Check out these Similar Threads
Old 17th September 2004   #2
Inactive
 
Newt's Avatar
 
Profile:
Join Date: Jan 2002
Location: Concord, NC, USA
Posts: 11,217
Computer Experience:
*****
Newt Reputation Level


Not sure about the criticality of those exchange log files but if your exchange server is any where near up to date on security patches, you should be safe enough. Pretty good discussion of this critter Here but basically it appears that if you have applied MS03-040, MS04-013, MS04-025 you will be OK.
Newt is offline  
Old 17th September 2004   #3
SuperGeek
 
Profile:
Join Date: Apr 2003
Location: New Bremen, Ohio U.S.A.
Posts: 12,523
Computer Experience:
~@<*+
noahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Level

My System

I'm also unsure what deleting the logs would do, but the JS ZEROLIN A C:\Program Files\Exchngsvr\mdbdata\E00006f1.log 9/27/2004 file is very suspicious looking for sure. Notice it's dated for the 27th of this month, yet it's only the 17th? I personally would open them and try to locate the infection. No doubt some scripting, and should be able to spot it and edit it out.
noahdfear is offline  
Old 17th September 2004   #4
Member
 
Profile:
Join Date: Nov 2002
Location: Florida
Posts: 18
Computer Experience:
Experienced
hkelley Reputation Level


Ooops, that date was a typo...should read 9/7/2004.

Thanks for suggestion...any additional thoughts?

hkelley is offline  



Closed Thread

Thread Tools


Similar Threads
Thread Thread Starter Forum Replies Last Post
opening excel files error log generated kincora Other Software 2 15th November 2002 00:58
paging file problem verdi Windows XP 47 14th October 2002 22:08
Flaw Temporary Internet Files rogersch Internet Explorer 2 12th July 2002 09:56


All times are GMT +1. The time now is 20:40.






Advertisements do not imply our endorsement of the product or service advertised.
Powered by vBulletin® Version 3.8.5
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.3.2
Copyright © 2002 - 2009 WindowsBBS.com. All rights reserved.
Terms of Use, Legal Information & Privacy Policy
[]