Windows Server 2000/2003 Thread, Virus on Server in Technical; We are having major problems on our SIMS server with the w32/sality-am virus, we have sophos installed and its is ...
-
20th January 2009, 12:32 PM #1
- Rep Power
- 0
Virus on Server
We are having major problems on our SIMS server with the w32/sality-am virus, we have sophos installed and its is cleaning up detected items but then some of the exe files will not run and become infected again, does anybody know a way of permanantly removing this virus.
-
-
IDG Tech News
-
20th January 2009, 12:36 PM #2 Since you're using Sophos this might help: Sophos: Disinfecting PE executables
-
-
20th January 2009, 12:40 PM #3
- Rep Power
- 0
thanks james i have done that and followed the instructions but it still keeps re-appearing.
-
-
20th January 2009, 12:41 PM #4 roughyed,
I recently attended a site with this exact virus on their SIMS server.
My advice to you would be to isolate the server (first action always upon infection) and in parallel ensure the virus is not elsewhere on the site whilst taking a very light back up of only the most crucial files, the SIMS ldf/mdf and docstorage should be sufficient I'd think but check with your support provider if you have one.
Format + reinstall the server, SIMS, etc, and restore your light back up.
It's the only safe and sure way to know you've eradicated the virus as like you said, it's annoying when it breaks EXE's especially when it does it to everything in the setups dir!
-
-
20th January 2009, 12:51 PM #5
- Rep Power
- 0
I was afraid someone would say that we have 4 other essential software programs on this server so to do a re-install would be a nightmare.
-
-
20th January 2009, 12:57 PM #6 Have you tried a different AV product, there are some online scanners along with some other solutions that can run off Windows PE/UBCD4Win that may be able to disinfect your machine while it is offline.
-
-
20th January 2009, 01:02 PM #7
- Rep Power
- 0
I haven't tried that is there any you would suggest to use.
-
-
20th January 2009, 01:15 PM #8 The server is compromised. You can no longer trust it to work as expected. A format, reinstall and recovery from a known good backup is your only choice.
-
-
20th January 2009, 01:17 PM #9 Dr.Web LiveCD is a software product that features a standard, Dr.Web scanner
Try this one as well:
UBCD for Windows with ClamWin and Trend Micro SysClean from the additional downloads.
That and following the removal instructions from here:
W32.Sality.AE Removal - Removing Help | Symantec
Edit: As Geoff says above, it is a server and the only way to be completely sure it is trusted is a reinstall unless it is an old easily identifyable and removable virus that has been fully explored and understood.
Last edited by SYNACK; 20th January 2009 at 01:19 PM.
-
-
20th January 2009, 01:54 PM #10 If you have a known good backup then as people have said that's the best course.
You should be able to take off the SIMS database, and any others you may have on there, and reattach them once the backup is restored to prevent data loss.
Since the virus (supposedly) infects .scr and .exe files the data itself should be safe, but I'd recommend doing a scan on each of the data files before reattaching them.
-
SHARE: 
Similar Threads
-
Replies: 8
Last Post: 10th October 2008, 01:12 PM
-
By cookie_monster in forum Thin Client and Virtual Machines
Replies: 6
Last Post: 1st June 2008, 03:58 PM
-
By chrbb in forum Windows
Replies: 6
Last Post: 26th January 2008, 12:57 PM
-
By tickmike in forum Windows
Replies: 20
Last Post: 14th August 2006, 08:38 PM
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules