Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
httperr1.log
   
BullGuard Antivirus Forum > Virus Removal > Removal Help > httperr1.log  
Forum Quick Jump
 
New Topic Post reply to : httperr1.log Printable version of : httperr1.log
[ << Previous Thread | Next Thread >> ]

John
New Member


Date Joined Mar 2004
Total Posts : 3
 
   Posted 3-4-2004 8:28 (GMT +1)    Quote: httperr1.logAlert an admin about: httperr1.log
A recent scan of my log "httperr1.log" came up as infected with "Win32.IISWorm.CodeRed.Gen" but I can't delete or move the file. I can copy the file & then delete that copy, but that doesn't do anything for getting rid of the originally infected file.
Back to Top
 

CoryM
New Member


Date Joined Mar 2004
Total Posts : 6
 
   Posted 3-4-2004 10:29 (GMT +1)    Quote: httperr1.logAlert an admin about: httperr1.log
Hi,

Probably because your IIS is running and blocking AV-products from accessing the file.

Did you try applying the MS patch (http://www.microsoft.com/technet/security/bulletin/MS01-033.asp) ?

BG has a description of that virus here, i think: http://www.bullguard.com/virus/default.aspx?id=61 - what can you make of that?

Looks like they even have a removal tool...

Alternatively, I would try and shut down IIS and then delete the file - or reboot in safe-mode and delete the damn thing!
Back to Top
 

John
New Member


Date Joined Mar 2004
Total Posts : 3
 
   Posted 3-4-2004 10:43 (GMT +1)    Quote: httperr1.logAlert an admin about: httperr1.log
Thanks for the info... I did the safe-mode reboot & deleted the file. I'm running Small Business Server 2003, and have all of the latest patches so I'm not sure why this came up as infected. I think it has something to do with a line in the error log relating to a codered attack:

HTTP/1.0 GET /default.ida?
(a whole bunch of X's then some more junk like this: %u9090%u6858%ucbd3%=a)
(then the resulting error) 400 - Hostname

I shut down all of the outside access to IIS, with the exception of known IP addresses. This is a temporary fix until I make sure that there isn't a threat of infection. I think that it's just logging errors from infected machines, and thereby setting off BullGuard when it sees the above line.

John
Back to Top
 
New Topic Post reply to : httperr1.log Printable version of : httperr1.log
 
Forum Information
Currently it is Wednesday, March 17, 2010 9:19 PM (GMT +1)
There are a total of 76.277 posts in 17.610 threads.
In the last 3 days there were 11 new threads and 60 reply posts. View Active Threads
Who's Online
This forum has 31151 registered members. Please welcome our newest member, kas.
28 Guest(s), 2 Registered Member(s) are currently online.  Details
Dickens, booboo1
5 Latest Threads
Can't perform a full system scan (6)17-03-2010 19:51:51 (booboo1)
Redirect virus - search results cause redirect to ad sites (7)17-03-2010 19:43:46 (kas)
Trojan horse Downloader.Agent2.SNR (0)17-03-2010 19:39:01 (taty03)
Ad.yieldmanager.com problem (6)17-03-2010 19:36:47 (IanR)
Trojan.Generic.KD.4056 (5)17-03-2010 16:20:06 (markusg)