Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Detecting who changes/saves a file

Status
Not open for further replies.

KITMark

IS-IT--Management
Apr 26, 2001
3
0
0
CA
I have a loverletter virus going through a network share and I would like to know the computer that is erasing the previous file and saving the new VBS script.

Is there a utility that can do this. The catch is that it is a pathworks server running under OPEN VMS. The clients are Windows PCs.
 


for *nix systems try tripwire and for windows based PCs, go for winfingerprint.

additionally you can run a sniffer on your machines and see which computer is attempting to connect the shares (note that the virus tries to connect to some suspicious shares like NTLDM, NTVDM etc).

you will get the PC which is transferring the virus.
 
The server is VMS ... not UNIX. The client is PC but there are potentially over 1000 clients that could be the culprit.
Sniffing is a possibility but it usually happens off hours and not very frequently .. ie likely a dial-in from a home PC.

What I have done is enabled auditing on the server and waiting for the next strike. Hopefully it will give me everything I need.

Thanks for your suggestions.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top