Re: Searching for virus by Jim
Jim
Sat Apr 17 21:44:38 CDT 2004
Work late at night and scan every workstation for viruses. Watch
packets on the external nic. After the scan turn off every
workstation. At the server have the packets slowed down? Stop Exchange
and see if things slow down. You can go into Exchange manager and
drill into the queues and watch stuff going out through Exchange. On
your Exchange server I do a few things. First is enable complex
passwords at least 8 characters long. That is a group policy edit. I
make sure the guest account is disabled but I make a complex password
for that before I disable it just in case someone enables it. In the
Exchange I find the relay section I make sure that the checkbox for
all authenticated users is not checked. I make sure that only the
internal ip and the external ip are listed.
Open ISA manager and configure reports.
"Netnathan" <n.a.smith@att<nospam>.net> wrote:
>I believe I have a rouge machine that has the netsky virtus. It may have
>slipped by the Sysmantec NAV install.
>
>Is there a log I can watch that will tell me what IP or pc is sending email
>and when?
>Likewise for the exchange mail send and deliver.
>
>-nn
>
Jim B. SBS MVP
remove the mvp to send email