Dear All,
I have trawled for the last few days but have not been able to come up with a solution, any help would be much appreciated.
Exchange 2007 Std on Windows 2003 64Bit and users report search not working in OWA.
So I first check indexing is enabled on the mailstores
Get-MailboxDatabase...
Just for anyone reading this thread.. after about 12 hours i have managed to clean it, after discovering this virus has more than one name.
1) use msconfig to do a diagnostic startup
2) run http://support.kaspersky.com/downloads/utils/sality_off.rar
3) then reboot
4) run sality_off again...
cheers for the tips, i think i have found it....
C:\WINDOWS\system32\drivers\glnmkn.sys
this is being hidden by a rootkit and iv still not managed to stop the bugger loading!
tried, UnhackME, Sophos and McAfee up to now.
unfortunately im having to do this remotely...
Hi James,
This virus seems to prevent booting in safemode, casuses a blue screen of death on evey machine iv tried.
Dan Cunliffe, General MCSE Jack of all trades!
Cheers Tony,
I know, iv been on all the RIM courses and i raised the same issues, i must have installed BES 50 times though and never had a problem
no luck with the online scans im afraid :-( if i install the actuall AVG client on the server it just goes mental!
Dan Cunliffe, General MCSE...
Thanks for you help ben,
iv Already run those two tools,(after renaming the exe) they just find the registry changes. fix them. then obviously their back on the next scan
tried spybot S+D too
Heres the log from the last program you suggested
GMER 1.0.14.14536 - http://www.gmer.net
Rootkit...
heres it with those out, virus is still in memory though somwhere!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:01:00, on 16/02/2009
Platform: Windows 2003 SP2 (WinNT 5.02.3790)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes...
Thanks for the response!
If end the random EXEs and delete, then they are recreated afre a few minutes.
Same with the Regedit registry key. :-(
the dam bugger changes a few other things in the registry too, including hidden files, and access to task manager!
Dan Cunliffe, General MCSE...
Hi There,
I hope somebody could put a second set of eyes over this, taken on a new client, site visit resulted in me finding a ver out of date symantec installation and lots of problems, about 10 / 20 machines had win32/tanatos.m and win32/heur.
Using a combination of combofix, and the AVG...
Hi, Iv configured a Stack of 8 Procurve 2610 switches all managable from one ip address
the only problem iv got is that a vlan is only configurable on the current switch not accross the stack.
Is it possible to do this?!?!
its in a serviced office configured accross mutliple comms rooms...
That is a very big kettle off fish and you have taken quite a few steps back in the way of fucntionality,
The GAL will have to be set up by your ISP or whover is handling your mail,
what i would do is reinstate exchange and either use Pop3 Collector for Exchange or get back on a SMTP feed.
as Matt Said,
the way we do it is to go Find the user in AD, Exchange General Tab
Deliver options
Forwarding...
Dead easy and make sure you put the tick in!!
Isnt that a seperate ACL
after you have enabled managment on the correct port i think you do it like this....
http 82.42.*.* 255.255.255.224 management
http 192.168.8.0 255.255.255.224 management
Hi guys im wondering if somone could help me,
Im trying to configure a ASA 5510 for use in a serviced office building, The building has a.llq Vlan Capable Procurve Stack Uplinked into Eth0/1
An SDSL router into Eth0/0 With 32 External IPs
What im trying to do is set up a different VLAN for...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.