Unsolved

This post is more than 5 years old

2 Intern

 • 

2K Posts

7062

April 25th, 2007 11:00

Vundo - infection on Server

This moring a user reported being unable to access documents on a specific server. Suspecting a server problem, I went to our space and re-booted. I noticed on the black and white a fleeting message "Symantec is cleaning infection and will re-boot" after which (re-boot) I logged Administrator in and then also saw two Symantec (corporate) dialogs showing "Vundo" cleaned (five or six times, on the scanning pane). This seems to me like a problem for our operation (higher education organization).

4 Posts

May 2nd, 2007 13:00

Symantec (in our experience) mistakes unknown variants of Rinbot/Delbot as trojan.vundo and or "infostealer"
 
Never seen this on a server, but Rinbot/Delbot gets on the machine most frequently from poor passwords for a SQL install, vulnerable Symantec installs (early 10.0 releases), VNC, or unpatched RPC/network share type vulnerabilities.
 
good luck
No Events found!

Top