Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > Troj/ServU - How to Prevent?

Reply
Thread Tools Display Modes

Troj/ServU - How to Prevent?

 
 
Brock Hensley
Guest
Posts: n/a

 
      04-02-2009
Hello,

I have been trying to research this "Serv-U" Virus, with the following
aliases, to figure out how it infects servers and how to prevent it. We have
a solution on how to remove the virus, we just need to know how it infects
servers and how to prevent it.

not-a-virus:Server-FTP.Win32.Serv-U.5000 (Kaspersky Lab) is also known as:

not-a-virus:RiskWare.FTP.Serv-U.5000 (Kaspersky Lab)
Hacktool (Symantec)
BackDoor.Servu.5000 (Doctor Web)
Troj/ServU-Gen (Sophos)
BDS/ServU.ba.1 (H+BEDV)
Win32:Trojano-356 (ALWIL)
Trojan.ServU.G (SOFTWIN)
Trojan.Servu.1 (ClamAV)
Bck/ServU.BB (Panda)

Does anyone have any helpful information on this virus?

Thanks,
-B


 
Reply With Quote
 
 
 
 
Peter Foldes
Guest
Posts: n/a

 
      04-02-2009
Try this in the public.security newsgroup.

--
Peter

Please Reply to Newsgroup for the benefit of others
Requests for assistance by email can not and will not be acknowledged.

"Brock Hensley" <> wrote in message
news:95182E57-E171-41CE-9FBA-...
> Hello,
>
> I have been trying to research this "Serv-U" Virus, with the following aliases, to
> figure out how it infects servers and how to prevent it. We have a solution on how
> to remove the virus, we just need to know how it infects servers and how to
> prevent it.
>
> not-a-virus:Server-FTP.Win32.Serv-U.5000 (Kaspersky Lab) is also known as:
>
> not-a-virus:RiskWare.FTP.Serv-U.5000 (Kaspersky Lab)
> Hacktool (Symantec)
> BackDoor.Servu.5000 (Doctor Web)
> Troj/ServU-Gen (Sophos)
> BDS/ServU.ba.1 (H+BEDV)
> Win32:Trojano-356 (ALWIL)
> Trojan.ServU.G (SOFTWIN)
> Trojan.Servu.1 (ClamAV)
> Bck/ServU.BB (Panda)
>
> Does anyone have any helpful information on this virus?
>
> Thanks,
> -B
>
>


 
Reply With Quote
 
Brock Hensley
Guest
Posts: n/a

 
      04-02-2009
Peter,

Thank you, sorry for the mis-post, every instance I've seen of this
infection has been on Virtual Servers with Windows Server 2003 Web Edition
on them so figured this would suffice.

I've moved the post to "microsoft.public.security.virus".

Thanks,
-Brock

"Peter Foldes" <> wrote in message
news:...
> Try this in the public.security newsgroup.
>
> --
> Peter
>
> Please Reply to Newsgroup for the benefit of others
> Requests for assistance by email can not and will not be acknowledged.
>
> "Brock Hensley" <> wrote in message
> news:95182E57-E171-41CE-9FBA-...
>> Hello,
>>
>> I have been trying to research this "Serv-U" Virus, with the following
>> aliases, to figure out how it infects servers and how to prevent it. We
>> have a solution on how to remove the virus, we just need to know how it
>> infects servers and how to prevent it.
>>
>> not-a-virus:Server-FTP.Win32.Serv-U.5000 (Kaspersky Lab) is also known
>> as:
>>
>> not-a-virus:RiskWare.FTP.Serv-U.5000 (Kaspersky Lab)
>> Hacktool (Symantec)
>> BackDoor.Servu.5000 (Doctor Web)
>> Troj/ServU-Gen (Sophos)
>> BDS/ServU.ba.1 (H+BEDV)
>> Win32:Trojano-356 (ALWIL)
>> Trojan.ServU.G (SOFTWIN)
>> Trojan.Servu.1 (ClamAV)
>> Bck/ServU.BB (Panda)
>>
>> Does anyone have any helpful information on this virus?
>>
>> Thanks,
>> -B
>>
>>

>


 
Reply With Quote
 
Dave Warren
Guest
Posts: n/a

 
      04-02-2009
In message <95182E57-E171-41CE-9FBA-> "Brock
Hensley" <> was claimed to have wrote:

>I have been trying to research this "Serv-U" Virus, with the following
>aliases, to figure out how it infects servers and how to prevent it. We have
>a solution on how to remove the virus, we just need to know how it infects
>servers and how to prevent it.
>
>not-a-virus:Server-FTP.Win32.Serv-U.5000 (Kaspersky Lab) is also known as:
>
>not-a-virus:RiskWare.FTP.Serv-U.5000 (Kaspersky Lab)
>Hacktool (Symantec)
>BackDoor.Servu.5000 (Doctor Web)
>Troj/ServU-Gen (Sophos)
>BDS/ServU.ba.1 (H+BEDV)
>Win32:Trojano-356 (ALWIL)
>Trojan.ServU.G (SOFTWIN)
>Trojan.Servu.1 (ClamAV)
>Bck/ServU.BB (Panda)
>


In short, it's not a virus at all, it's just an FTP server that is
trivially easy to embed into other malware. In other words, it's a
common choice FTP server used by script-kiddies.
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Re: How to remove lingering remnants of 'Troj/Rustok-N' JackStrap Windows Vista General Discussion 2 07-17-2009 08:42 AM
How do I prevent ..... Mike Windows Vista Mail 1 11-20-2007 12:09 AM
How do i prevent someone from accesing my LAN MSExchangeStudent Server Networking 5 08-16-2007 05:58 AM
Prevent authentication to a particular DC JT Server Networking 1 10-11-2006 07:26 AM
Troj/Bdoor-CPK ucmehere Windows Update 2 02-13-2006 03:48 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59