General discussion

Locked

worms on exchange 2000

By itadmin ·
We have a exchange server infected with the following viruses;
W32.Netsky.P@mm!enc, W32.Netsky.Q@mm.enc, W32.Mydoom.A@mm, W32.Lovgate.R@mm, W32.Mydoom.A@mm.enc.
my antivirus detected them some files got quarentine and just some of them were left alone by my AV, what is the right presedure to clean up my server? and how do I get protected from getting infected again? a reference to a steb by step instruction manual would really help,
Thanks

This conversation is currently closed to new comments.

1 total post (Page 1 of 1)  
| Thread display: Collapse - | Expand +

All Comments

Collapse -

by R. A. Caluste In reply to worms on exchange 2000

Your antivirus will quarantine the worms, but it does not do anything about the entries in your server's registry.

Download the appropriate virus removal tools from Symantec Security Response. These tools not only find and deletes the viruses but cleans-up your registry as well.(http://securityresponse.symantec.com/avcenter/)

Download the necessary patch for your Windows and Exchange Server. Scan for updates at Windows Update website.(http://v4.windowsupdate.microsoft.com/en/default.asp)

Determine your vulnerabilities with Microsoft Baseline Security Analyzer 1.2 (http://www.microsoft.com/technet/security/tools/mbsahome.mspx)

From time to time, you should execute the MS Baseline Secuirty Analyzer (MSBSA) to determine if there is a need to patch your system (MSBSA will always download from microsoft an updated list of system vulnerabilities and compares it with your existing system).

Hope this helps.

Back to Windows Forum
1 total post (Page 1 of 1)  

Related Discussions

Related Forums