Jump to content

W97M/Marker.T Virus found by Forefront on file server


Recommended Posts

Guest Sandy Wood
Posted

I'm posting this here because I'm not getting any response in the Forefront

forums. (What happened over there? They used to be so responsive? Maybe the

new look) The Forefront client has discovered W97M/Marker.T on one of my file

servers. I've chosen to have it removed by FCS and it's now in a state of

"Taking Actions....". This has been going on for a hour now and the System

Event log is filling up with FCSAM Information events every 15 or so seconds

saying FCS is taking action. How long should I wait for this to finish?

--

Sandy Wood

Orange County District Attorney

  • Replies 12
  • Created
  • Last Reply
Guest PA Bear [MS MVP]
Posted

Contact Forefront Support: You (or rather, your employer) is paying for it.

--

~Robear Dyer (PA Bear)

MS MVP-IE, Mail, Security, Windows Desktop Experience - since 2002

AumHa VSOP & Admin http://aumha.net

DTS-L http://dts-l.net/

 

Sandy Wood wrote:<span style="color:blue">

> I'm posting this here because I'm not getting any response in the

> Forefront

> forums. (What happened over there? They used to be so responsive? Maybe

> the

> new look) The Forefront client has discovered W97M/Marker.T on one of my

> file servers. I've chosen to have it removed by FCS and it's now in a

> state

> of "Taking Actions....". This has been going on for a hour now and the

> System Event log is filling up with FCSAM Information events every 15 or

> so

> seconds saying FCS is taking action. How long should I wait for this to

> finish? </span>

Guest PA Bear [MS MVP]
Posted

PS: Have you tried posting to microsoft.public.security.forefront newsgroup?

 

PA Bear [MS MVP] wrote:<span style="color:blue">

> Contact Forefront Support: You (or rather, your employer) is paying for

> it.

>

> Sandy Wood wrote:<span style="color:green">

>> I'm posting this here because I'm not getting any response in the

>> Forefront

>> forums. (What happened over there? They used to be so responsive? Maybe

>> the

>> new look) The Forefront client has discovered W97M/Marker.T on one of my

>> file servers. I've chosen to have it removed by FCS and it's now in a

>> state

>> of "Taking Actions....". This has been going on for a hour now and the

>> System Event log is filling up with FCSAM Information events every 15 or

>> so

>> seconds saying FCS is taking action. How long should I wait for this to

>> finish? </span></span>

Guest Sandy Wood
Posted

Yes, but only the server-side. They won't support our client

questions......have to love it.....

--

Sandy Wood

Orange County District Attorney

 

 

"PA Bear [MS MVP]" wrote:

<span style="color:blue">

> Contact Forefront Support: You (or rather, your employer) is paying for it.

> --

> ~Robear Dyer (PA Bear)

> MS MVP-IE, Mail, Security, Windows Desktop Experience - since 2002

> AumHa VSOP & Admin http://aumha.net

> DTS-L http://dts-l.net/

>

> Sandy Wood wrote:<span style="color:green">

> > I'm posting this here because I'm not getting any response in the

> > Forefront

> > forums. (What happened over there? They used to be so responsive? Maybe

> > the

> > new look) The Forefront client has discovered W97M/Marker.T on one of my

> > file servers. I've chosen to have it removed by FCS and it's now in a

> > state

> > of "Taking Actions....". This has been going on for a hour now and the

> > System Event log is filling up with FCSAM Information events every 15 or

> > so

> > seconds saying FCS is taking action. How long should I wait for this to

> > finish? </span>

>

> </span>

Guest Sandy Wood
Posted

Yes....lately my posts have just sat there...maybe the new forum style?

--

Sandy Wood

Orange County District Attorney

 

 

"PA Bear [MS MVP]" wrote:

<span style="color:blue">

> PS: Have you tried posting to microsoft.public.security.forefront newsgroup?

>

> PA Bear [MS MVP] wrote:<span style="color:green">

> > Contact Forefront Support: You (or rather, your employer) is paying for

> > it.

> >

> > Sandy Wood wrote:<span style="color:darkred">

> >> I'm posting this here because I'm not getting any response in the

> >> Forefront

> >> forums. (What happened over there? They used to be so responsive? Maybe

> >> the

> >> new look) The Forefront client has discovered W97M/Marker.T on one of my

> >> file servers. I've chosen to have it removed by FCS and it's now in a

> >> state

> >> of "Taking Actions....". This has been going on for a hour now and the

> >> System Event log is filling up with FCSAM Information events every 15 or

> >> so

> >> seconds saying FCS is taking action. How long should I wait for this to

> >> finish? </span></span>

>

> </span>

Guest PA Bear [MS MVP]
Posted

Sounds like you may be confusing the Forefront newsgroup

(microsoft.public.security.forefront) with the Forefront forums, Sandy =>

http://forums.microsoft.com/forefront/default.aspx?siteid=41

 

EDIT: Maybe not. Looks like those forums were moved in late May but...

 

 

Sandy Wood wrote:<span style="color:blue">

> Yes....lately my posts have just sat there...maybe the new forum style?

><span style="color:green">

>> PS: Have you tried posting to microsoft.public.security.forefront

>> newsgroup?

>>

>> PA Bear [MS MVP] wrote:<span style="color:darkred">

>>> Contact Forefront Support: You (or rather, your employer) is paying for

>>> it.

>>>

>>> Sandy Wood wrote:

>>>> I'm posting this here because I'm not getting any response in the

>>>> Forefront

>>>> forums. (What happened over there? They used to be so responsive? Maybe

>>>> the

>>>> new look) The Forefront client has discovered W97M/Marker.T on one of

>>>> my

>>>> file servers. I've chosen to have it removed by FCS and it's now in a

>>>> state

>>>> of "Taking Actions....". This has been going on for a hour now and the

>>>> System Event log is filling up with FCSAM Information events every 15

>>>> or

>>>> so

>>>> seconds saying FCS is taking action. How long should I wait for this to

>>>> finish?</span></span></span>

Guest PA Bear [MS MVP]
Posted

Nevermind. I see that you had been using (TechNet) Forefront Forums:

http://forums.microsoft.com/ForeFront/Sear...wMzYx&SiteID=41

 

Try the newsgroup?

 

 

PA Bear [MS MVP] wrote:<span style="color:blue">

> Sounds like you may be confusing the Forefront newsgroup

> (microsoft.public.security.forefront) with the Forefront forums, Sandy =>

> http://forums.microsoft.com/forefront/default.aspx?siteid=41

>

> EDIT: Maybe not. Looks like those forums were moved in late May but...

>

>

> Sandy Wood wrote:<span style="color:green">

>> Yes....lately my posts have just sat there...maybe the new forum style?

>><span style="color:darkred">

>>> PS: Have you tried posting to microsoft.public.security.forefront

>>> newsgroup?

>>>

>>> PA Bear [MS MVP] wrote:

>>>> Contact Forefront Support: You (or rather, your employer) is paying for

>>>> it.

>>>>

>>>> Sandy Wood wrote:

>>>>> I'm posting this here because I'm not getting any response in the

>>>>> Forefront

>>>>> forums. (What happened over there? They used to be so responsive?

>>>>> Maybe

>>>>> the

>>>>> new look) The Forefront client has discovered W97M/Marker.T on one of

>>>>> my

>>>>> file servers. I've chosen to have it removed by FCS and it's now in a

>>>>> state

>>>>> of "Taking Actions....". This has been going on for a hour now and the

>>>>> System Event log is filling up with FCSAM Information events every 15

>>>>> or

>>>>> so

>>>>> seconds saying FCS is taking action. How long should I wait for this

>>>>> to

>>>>> finish? </span></span></span>

Guest Sandy Wood
Posted

Yes, I'm sure I am. The Forefront forum I posted my question to is at

 

http://forums.technet.microsoft.com/en-US/...entMTR/threads/

 

 

--

Sandy Wood

Orange County District Attorney

 

 

"PA Bear [MS MVP]" wrote:

<span style="color:blue">

> Sounds like you may be confusing the Forefront newsgroup

> (microsoft.public.security.forefront) with the Forefront forums, Sandy =>

> http://forums.microsoft.com/forefront/default.aspx?siteid=41

>

> EDIT: Maybe not. Looks like those forums were moved in late May but...

>

>

> Sandy Wood wrote:<span style="color:green">

> > Yes....lately my posts have just sat there...maybe the new forum style?

> ><span style="color:darkred">

> >> PS: Have you tried posting to microsoft.public.security.forefront

> >> newsgroup?

> >>

> >> PA Bear [MS MVP] wrote:

> >>> Contact Forefront Support: You (or rather, your employer) is paying for

> >>> it.

> >>>

> >>> Sandy Wood wrote:

> >>>> I'm posting this here because I'm not getting any response in the

> >>>> Forefront

> >>>> forums. (What happened over there? They used to be so responsive? Maybe

> >>>> the

> >>>> new look) The Forefront client has discovered W97M/Marker.T on one of

> >>>> my

> >>>> file servers. I've chosen to have it removed by FCS and it's now in a

> >>>> state

> >>>> of "Taking Actions....". This has been going on for a hour now and the

> >>>> System Event log is filling up with FCSAM Information events every 15

> >>>> or

> >>>> so

> >>>> seconds saying FCS is taking action. How long should I wait for this to

> >>>> finish?</span></span>

>

> </span>

Guest Sandy Wood
Posted

Not yet. I'll give them a try too. Wow, alot of security forums!

--

Sandy Wood

Orange County District Attorney

 

 

"PA Bear [MS MVP]" wrote:

<span style="color:blue">

> Nevermind. I see that you had been using (TechNet) Forefront Forums:

> http://forums.microsoft.com/ForeFront/Sear...wMzYx&SiteID=41

>

> Try the newsgroup?

>

>

> PA Bear [MS MVP] wrote:<span style="color:green">

> > Sounds like you may be confusing the Forefront newsgroup

> > (microsoft.public.security.forefront) with the Forefront forums, Sandy =>

> > http://forums.microsoft.com/forefront/default.aspx?siteid=41

> >

> > EDIT: Maybe not. Looks like those forums were moved in late May but...

> >

> >

> > Sandy Wood wrote:<span style="color:darkred">

> >> Yes....lately my posts have just sat there...maybe the new forum style?

> >>

> >>> PS: Have you tried posting to microsoft.public.security.forefront

> >>> newsgroup?

> >>>

> >>> PA Bear [MS MVP] wrote:

> >>>> Contact Forefront Support: You (or rather, your employer) is paying for

> >>>> it.

> >>>>

> >>>> Sandy Wood wrote:

> >>>>> I'm posting this here because I'm not getting any response in the

> >>>>> Forefront

> >>>>> forums. (What happened over there? They used to be so responsive?

> >>>>> Maybe

> >>>>> the

> >>>>> new look) The Forefront client has discovered W97M/Marker.T on one of

> >>>>> my

> >>>>> file servers. I've chosen to have it removed by FCS and it's now in a

> >>>>> state

> >>>>> of "Taking Actions....". This has been going on for a hour now and the

> >>>>> System Event log is filling up with FCSAM Information events every 15

> >>>>> or

> >>>>> so

> >>>>> seconds saying FCS is taking action. How long should I wait for this

> >>>>> to

> >>>>> finish? </span></span>

>

> </span>

Guest PA Bear [MS MVP]
Posted

I've pinged an MS contact for information on where the forums might be

located & accessed now.

 

Newsgroups are NOT forums.

 

 

Sandy Wood wrote:<span style="color:blue">

> Not yet. I'll give them a try too. Wow, alot of security forums!

><span style="color:green">

>> Nevermind. I see that you had been using (TechNet) Forefront Forums:

>> http://forums.microsoft.com/ForeFront/Sear...wMzYx&SiteID=41

>>

>> Try the newsgroup?

>>

>>

>> PA Bear [MS MVP] wrote:<span style="color:darkred">

>>> Sounds like you may be confusing the Forefront newsgroup

>>> (microsoft.public.security.forefront) with the Forefront forums, Sandy

>>> =>

>>> http://forums.microsoft.com/forefront/default.aspx?siteid=41

>>>

>>> EDIT: Maybe not. Looks like those forums were moved in late May but...

>>>

>>>

>>> Sandy Wood wrote:

>>>> Yes....lately my posts have just sat there...maybe the new forum style?

>>>>

>>>>> PS: Have you tried posting to microsoft.public.security.forefront

>>>>> newsgroup?

>>>>>

>>>>> PA Bear [MS MVP] wrote:

>>>>>> Contact Forefront Support: You (or rather, your employer) is paying

>>>>>> for

>>>>>> it.

>>>>>>

>>>>>> Sandy Wood wrote:

>>>>>>> I'm posting this here because I'm not getting any response in the

>>>>>>> Forefront

>>>>>>> forums. (What happened over there? They used to be so responsive?

>>>>>>> Maybe

>>>>>>> the

>>>>>>> new look) The Forefront client has discovered W97M/Marker.T on one

>>>>>>> of

>>>>>>> my

>>>>>>> file servers. I've chosen to have it removed by FCS and it's now in

>>>>>>> a

>>>>>>> state

>>>>>>> of "Taking Actions....". This has been going on for a hour now and

>>>>>>> the

>>>>>>> System Event log is filling up with FCSAM Information events every

>>>>>>> 15

>>>>>>> or

>>>>>>> so

>>>>>>> seconds saying FCS is taking action. How long should I wait for this

>>>>>>> to

>>>>>>> finish? </span></span></span>

Guest Sandy Wood
Posted

Man, I can't find the newsgroup out there...is it hidden somewhere?

--

Sandy Wood

Orange County District Attorney

 

 

"Sandy Wood" wrote:

<span style="color:blue">

> I'm posting this here because I'm not getting any response in the Forefront

> forums. (What happened over there? They used to be so responsive? Maybe the

> new look) The Forefront client has discovered W97M/Marker.T on one of my file

> servers. I've chosen to have it removed by FCS and it's now in a state of

> "Taking Actions....". This has been going on for a hour now and the System

> Event log is filling up with FCSAM Information events every 15 or so seconds

> saying FCS is taking action. How long should I wait for this to finish?

> --

> Sandy Wood

> Orange County District Attorney</span>

Guest PA Bear [MS MVP]
Posted

Via the clunky web-interface:

http://www.microsoft.com/communities/newsg...urity.forefront

 

Via your NNTP newsreader (e.g., OE; Windows Mail; Windows Live Mail):

news://msnews.microsoft.com/microsoft.publ...urity.forefront

--

~PA Bear

 

 

Sandy Wood wrote:<span style="color:blue">

> Man, I can't find the newsgroup out there...is it hidden somewhere?

><span style="color:green">

>> I'm posting this here because I'm not getting any response in the

>> Forefront

>> forums. (What happened over there? They used to be so responsive? Maybe

>> the

>> new look) The Forefront client has discovered W97M/Marker.T on one of my

>> file servers. I've chosen to have it removed by FCS and it's now in a

>> state of "Taking Actions....". This has been going on for a hour now and

>> the System Event log is filling up with FCSAM Information events every 15

>> or so seconds saying FCS is taking action. How long should I wait for

>> this

>> to finish? --

>> Sandy Wood

>> Orange County District Attorney </span></span>

Guest Johan Blom, TrueSec
Posted

Hi Sandy!

 

I used to post alot on the old Forefront forum (and will continue in the new

forefront forum) however i must say that i don't like the new look and feel

of the forum. I used to be on the top answers list (place 1 - 3). Another

thing with the new forum is that it's alot harder to see if there are new

unanswered questions. In the old forum it was easy to get a quick overview.

I promise i'll be more active on the new forum from now on (just got back

from a month of vacation).

 

Keep the faith Sandy

 

/Johan

--

MCSE, forefront spec | www.msforefront.com

 

 

"PA Bear [MS MVP]" wrote:

<span style="color:blue">

> Via the clunky web-interface:

> http://www.microsoft.com/communities/newsg...urity.forefront

>

> Via your NNTP newsreader (e.g., OE; Windows Mail; Windows Live Mail):

> news://msnews.microsoft.com/microsoft.publ...urity.forefront

> --

> ~PA Bear

>

>

> Sandy Wood wrote:<span style="color:green">

> > Man, I can't find the newsgroup out there...is it hidden somewhere?

> ><span style="color:darkred">

> >> I'm posting this here because I'm not getting any response in the

> >> Forefront

> >> forums. (What happened over there? They used to be so responsive? Maybe

> >> the

> >> new look) The Forefront client has discovered W97M/Marker.T on one of my

> >> file servers. I've chosen to have it removed by FCS and it's now in a

> >> state of "Taking Actions....". This has been going on for a hour now and

> >> the System Event log is filling up with FCSAM Information events every 15

> >> or so seconds saying FCS is taking action. How long should I wait for

> >> this

> >> to finish? --

> >> Sandy Wood

> >> Orange County District Attorney </span></span>

>

> </span>

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...