Windows 2000 viruses and security
Results 1 to 8 of 8

Thread: Windows 2000 viruses and security

  1. #1
    Registered User
    Join Date
    Sep 2001
    Location
    south of sanity
    Posts
    473

    Windows 2000 viruses and security

    A bit of a strange problem this one, we have an old fileserver running Windows 2000 Server at the office, however the software we need has been written to run with IE6 (yeah I know its a bad idea) so we can't upgrade it or install any service packs.

    Now this machine has become infected and I need to find some form of security for it - Symantec AV detects and cleans the viruses but they instantly return. Two files called msudp32.exe and ms18_word.exe are the infected ones, there are probably more.

    I've tried malware scanners and fix tools but these things just keep coming back through the security holes in the software. I wanted to install a firewall on it but Comodo and Zonealarm only offer XP/Vista versions.

    Any suggestions would be appreciated (formatting is not an option and we cant upgrade it either as our antiquated software will not function).
    Last edited by buksida; August 3rd, 2009 at 03:17 AM.

  2. #2
    Registered User Niclo Iste's Avatar
    Join Date
    Oct 2007
    Location
    Pgh, PA
    Posts
    2,051
    From what I'm reading this is a Trojan downloader that is part of malware. My first questions are: Have you installed, updated, and run malwarebytes? My second would be have you tried Combofix? The only other thing I could possibly think of is trying Trend Micros Sysclean. Just remember to do the cleaning in safe mode.
    One Script to rule them all.
    One Script to find them.
    One Script to bring them all,
    and clean up after itself.

  3. #3
    Registered User slgrieb's Avatar
    Join Date
    Feb 2003
    Posts
    4,103
    I'd schedule some down time for the machine so you can connect the drive to a machine running a full set of removal tools and scan it from there.

  4. #4
    Registered User Niclo Iste's Avatar
    Join Date
    Oct 2007
    Location
    Pgh, PA
    Posts
    2,051
    Since slgrieb suggested the slaving of it and scanning I'd agree. My first inclination was that too but I thought I was being too rash.
    One Script to rule them all.
    One Script to find them.
    One Script to bring them all,
    and clean up after itself.

  5. #5
    Registered User geoscomp's Avatar
    Join Date
    Apr 2002
    Location
    Minnesota
    Posts
    2,340
    After you get it clean, you can get an archived version of ZoneAlarm that will work with W2K here:
    http://www.oldapps.com/zonealarm.php
    Computer Rescue Service

    "those who do not remember history are condemned to repeat it."

  6. #6
    Registered User
    Join Date
    Sep 2001
    Location
    south of sanity
    Posts
    473
    Thanks for the replies. I've tried malwarebytes but it crashed on install. I've run Housecall from Trend Micro and it cleans it but the following day they're all back again, specifically this msudp32.exe. Combofix told me the OS was incompatible.

    Not a bad idea to pop the disk out and scan in a clean machine too.

    Thanks for the ZA link, I'll install that once its clean and hope it keeps them out.
    Last edited by buksida; August 4th, 2009 at 12:44 AM.

  7. #7
    Registered User
    Join Date
    Sep 2001
    Location
    south of sanity
    Posts
    473
    Quick update on this as it managed to infect our entire network of XP machines (barring a couple). Symantec AV is a waste of space as it failed to prevent or clean this infection however malwarebytes did the trick. Its just a shame there isn't a W2K version.

    My only choice is to pull the disk out but I can't shut the machine down until the weekend - in the meantime it continues to get hammered by these little bast@#$ds, the latest being msconfigs.exe and sexpants.exe.

  8. #8
    Registered User
    Join Date
    Sep 2001
    Location
    south of sanity
    Posts
    473
    The saga continues, all else failed so I setup a temporary backup file server and IIS for them to use and proceeded to take the hard disk out of the primary server today.

    Problem: its a SCSI disk so I cant simply pop into into another machine for a scan.

    I have updated to the latest service pack for 2K (4) and installed Zonealarm 6.5 but yet they come (ZA does tell me whats going on now though).

    Any further suggestions on cleaning this badboy greatly appreciated.

    Edit: Update - Malwarebytes finally managed to install and clean out most of the crap, ZA blocked the nasties from accessing the net also, a few scans and re-boots and it seems to be clean for now. The problem now is the trojan has filled the C drive up and I don't know where it's put the files or what they are. Is there anyway to find out or is there any handy file utility I can run on it to show me files added by date or files by size instead of the traditional tree view?
    Last edited by buksida; August 7th, 2009 at 04:15 AM.

Similar Threads

  1. windows98 error HELP PLEASE !!!
    By Talonboy in forum Windows 95/98/98SE/ME
    Replies: 11
    Last Post: August 19th, 2008, 06:04 PM
  2. Windows OneCare Live is, well...live. ;)
    By TripleRLtd in forum Spyware & Antivirus - Security
    Replies: 12
    Last Post: January 25th, 2006, 04:35 AM
  3. Replies: 0
    Last Post: August 5th, 2005, 09:30 AM
  4. Replies: 0
    Last Post: August 9th, 2004, 03:36 PM
  5. Download Windows XP SP2 Final + Support Centre
    By TechZ in forum Windows XP
    Replies: 3
    Last Post: August 9th, 2004, 03:29 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •