Jump to content

Recommended Posts

Posted

I'm not sure if its a false positive or whether something has infected the sims directory this morning but we've had the setups directory completely annilihated by Sophos on access scanning.

 

Was detecting

 

W32/Parite-B Win32 executable file virus (W32.Pinfi, W32/Pate-B, PE_PARITE.A, W32/Pate.b, W95/Parite.B, Win32.Parite.b) - Sophos security analysis

 

All over the place.

 

It couldn't clean the files and I've got it set to delete uncleanable files (as they're generally purely virus exes - obviously not in this case)

 

Am restoring from tape now but wanted to make anyone else aware.

 

I'm sure its a false positive which makes it even scarier. Stupid Sophos.

 

I've changed my policies now to "do nothing" if unable to clean the files ;)

 

Matt

Posted

ARGH!

 

Good job I updated the policy to not delete, I have over 800 alerts on my apps server showing this virus as having infected every exe going. wtf is going on?!

 

A phonecall to sophos is required methinks.

Posted
ARGH!

 

Good job I updated the policy to not delete, I have over 800 alerts on my apps server showing this virus as having infected every exe going. wtf is going on?!

 

A phonecall to sophos is required methinks.

 

Is it possible you have an actual virus? Sounds like typical virus behaviour to me...

Posted

Its possible, but its detectable by sophos, on-access scanning was turned on which is how its caught it, if the virus infects exes by sitting in memory all of the infected exes would have had to have been run to be infected - theres too many apps that just haven't been used for eons for that to have happened.

 

Still looking into it... :confused:

Posted
Its possible, but its detectable by sophos, on-access scanning was turned on which is how its caught it, if the virus infects exes by sitting in memory all of the infected exes would have had to have been run to be infected - theres too many apps that just haven't been used for eons for that to have happened.

 

Still looking into it... :confused:

 

Not necessarily. Some don't need to run the application in memory to infect it.

Posted

Right, chosen a random exe on the apps server and done an on-demand scan on there.

 

Its infected "apparently".

 

Modified date of 20/07/2007

 

Surely if it was infected by this virus it would have changed the modified date?

Posted
Thats good advice, I'd also suggest (along a very similar line) install an additional AV software(s) on a machine that can see the folder concerned and scan it with those.
Posted
I am sure an e-mail was sent to us regarding this. I am not at school at the moment and our internet connection is down. I will post back when I get in :)
Posted
Thats good advice, I'd also suggest (along a very similar line) install an additional AV software(s) on a machine that can see the folder concerned and scan it with those.

 

Don't do this multiple anti-virus software can interfere with each other, system hooks, etc. And leave you with a dead system.

Posted

Bugger.

 

I really had hoped it was a false positive.

 

Recieved this back from Sophos.

 

Matt,

Thanks for contacting Sophos Support.

In regards to this infection in particular.

I have discussed this with a colleague who can remember more details about this threat. Our thoughts are that it would be odd to suddenly get a false positive on Parite-B. It is pretty persistent nowdays, so may well reappear - perhaps via email, or even associated with another infection.

Since any of the newly infected files become a valid sample, it would be best if you submitted a copy of one of the files to SophosLabs - that way we can confirm the infection.

 

This threat is a file infector, which spreads by shares - so there must be one or more unprotected machines on the network. That is something you will have to verify.

Lastly, as to the deletion of your files - it is unfortunate. Sophos is set by default to do nothing when disinfection fails - for this very reason. You may wish to examine this listing of the remainder of defaults for AV and HIPS settings, in comparison with the remainder of your network settings.

Meanwhile, to submit a sample of the file, you can reply to this email, provided you zip and protect the file first. Here is a link for doing that online, if you prefer:

Submitting samples of suspicious files to Sophos

If you do choose to submit the sample, please use the case reference from this email in the submission: [#902153]. That way, I will be able to track your submission of the file.

 

If you have any further questions, please reply to this email.

 

First time I've had a virus infection on the network in five years. Gutted.

 

Guess I'd better not put the overtime sheets in just yet.

Posted

:eek:

 

I was hoping my link would lead to you being able to say "Phew, it's all OK..."

 

Sounds like FSecure can clean it up - I assume there'll be other similar standalone cleaners - ftp://ftp.f-secure.com/anti-virus/tools/f-parite.txt

 

First port of call should be tracking down where the infections come from - who has write access to the shares and how this could have happened, otherwise after cleaning up the server either with a tool or by restore from backup it'll likely pop right back up.

 

Good luck! :(

  • Thanks 1
Posted

Thanks again mate.

 

Problem we've got is the Sims share and apps share are mapped for all staff.

 

We're trying to nail it down but from looking at the Sophos log (something I don't do enough), its showing infections on the sims server from 14/5/08 - the infected files are in the setups folder and it was the night I was trying to do the sims may update (before it was pulled) after it had already failed for our sims administrator due to a signature mis-match. The signature didn't match because it was infected with a virus evidently.

 

The may update didn't get pulled because it was infected with a virus did it?

 

I presume now that the infected machine is a registration workstation and that the may update has now infected all registration machines if not all classroom machines.

 

We're going to be pulling a late one. Basically disconnecting everything at 3pm, clean the servers, make sure sophos is activated fully on them, start working through the 900 workstations we have and go from there.

 

I really can't believe this has happened.

Posted

Server cleanup is going well, that f-secure thing did the trick.

 

Need to work out what we're going to do site wide now. Making sure sophos is set up properly on the servers with full on-access scanning set up. Going to work out a way to run that app on login and we'll just log everything in (quicker than re-imaging - just).

 

Maybe re-image the registration machines that will need a sims update on them anyway.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...