mattcharlton Posted June 2, 2008 Posted June 2, 2008 I'm not sure if its a false positive or whether something has infected the sims directory this morning but we've had the setups directory completely annilihated by Sophos on access scanning. Was detecting W32/Parite-B Win32 executable file virus (W32.Pinfi, W32/Pate-B, PE_PARITE.A, W32/Pate.b, W95/Parite.B, Win32.Parite.b) - Sophos security analysis All over the place. It couldn't clean the files and I've got it set to delete uncleanable files (as they're generally purely virus exes - obviously not in this case) Am restoring from tape now but wanted to make anyone else aware. I'm sure its a false positive which makes it even scarier. Stupid Sophos. I've changed my policies now to "do nothing" if unable to clean the files Matt
Geoff Posted June 2, 2008 Posted June 2, 2008 Full system scans run in 10mins, so I'll let you know how it goes here.
mattcharlton Posted June 2, 2008 Author Posted June 2, 2008 ARGH! Good job I updated the policy to not delete, I have over 800 alerts on my apps server showing this virus as having infected every exe going. wtf is going on?! A phonecall to sophos is required methinks.
localzuk Posted June 2, 2008 Posted June 2, 2008 ARGH! Good job I updated the policy to not delete, I have over 800 alerts on my apps server showing this virus as having infected every exe going. wtf is going on?! A phonecall to sophos is required methinks. Is it possible you have an actual virus? Sounds like typical virus behaviour to me...
mattcharlton Posted June 2, 2008 Author Posted June 2, 2008 Its possible, but its detectable by sophos, on-access scanning was turned on which is how its caught it, if the virus infects exes by sitting in memory all of the infected exes would have had to have been run to be infected - theres too many apps that just haven't been used for eons for that to have happened. Still looking into it...
mattcharlton Posted June 2, 2008 Author Posted June 2, 2008 nm ignore that, it seeks out exes on network shares
localzuk Posted June 2, 2008 Posted June 2, 2008 Its possible, but its detectable by sophos, on-access scanning was turned on which is how its caught it, if the virus infects exes by sitting in memory all of the infected exes would have had to have been run to be infected - theres too many apps that just haven't been used for eons for that to have happened. Still looking into it... Not necessarily. Some don't need to run the application in memory to infect it.
mattcharlton Posted June 2, 2008 Author Posted June 2, 2008 Right, chosen a random exe on the apps server and done an on-demand scan on there. Its infected "apparently". Modified date of 20/07/2007 Surely if it was infected by this virus it would have changed the modified date?
OutToLunch Posted June 2, 2008 Posted June 2, 2008 Pick a random sample of executables from the server and upload to VirusTotal - Free Online Virus and Malware Scan or Online malware scan for a comprehensive scan by multiple engines - should give you a starting point as to whether you do have a mass infection on your hands or a mass Sophos cockup!
mattcharlton Posted June 2, 2008 Author Posted June 2, 2008 Cheers will give that a go and let you know what happens
superfletch Posted June 2, 2008 Posted June 2, 2008 Thats good advice, I'd also suggest (along a very similar line) install an additional AV software(s) on a machine that can see the folder concerned and scan it with those.
mattcharlton Posted June 2, 2008 Author Posted June 2, 2008 Oh dear. Not what we wanted to see.... Virustotal. MD5: f11208ff035b1c1acefde4bd74c28598 W32.Pinfi W32/Pate.b W32/Pinfi.A
AndyD Posted June 2, 2008 Posted June 2, 2008 I am sure an e-mail was sent to us regarding this. I am not at school at the moment and our internet connection is down. I will post back when I get in
Jona Posted June 2, 2008 Posted June 2, 2008 Thats good advice, I'd also suggest (along a very similar line) install an additional AV software(s) on a machine that can see the folder concerned and scan it with those. Don't do this multiple anti-virus software can interfere with each other, system hooks, etc. And leave you with a dead system.
mattcharlton Posted June 2, 2008 Author Posted June 2, 2008 Bugger. I really had hoped it was a false positive. Recieved this back from Sophos. Matt, Thanks for contacting Sophos Support. In regards to this infection in particular. I have discussed this with a colleague who can remember more details about this threat. Our thoughts are that it would be odd to suddenly get a false positive on Parite-B. It is pretty persistent nowdays, so may well reappear - perhaps via email, or even associated with another infection. Since any of the newly infected files become a valid sample, it would be best if you submitted a copy of one of the files to SophosLabs - that way we can confirm the infection. This threat is a file infector, which spreads by shares - so there must be one or more unprotected machines on the network. That is something you will have to verify. Lastly, as to the deletion of your files - it is unfortunate. Sophos is set by default to do nothing when disinfection fails - for this very reason. You may wish to examine this listing of the remainder of defaults for AV and HIPS settings, in comparison with the remainder of your network settings. Meanwhile, to submit a sample of the file, you can reply to this email, provided you zip and protect the file first. Here is a link for doing that online, if you prefer: Submitting samples of suspicious files to Sophos If you do choose to submit the sample, please use the case reference from this email in the submission: [#902153]. That way, I will be able to track your submission of the file. If you have any further questions, please reply to this email. First time I've had a virus infection on the network in five years. Gutted. Guess I'd better not put the overtime sheets in just yet.
OutToLunch Posted June 2, 2008 Posted June 2, 2008 I was hoping my link would lead to you being able to say "Phew, it's all OK..." Sounds like FSecure can clean it up - I assume there'll be other similar standalone cleaners - ftp://ftp.f-secure.com/anti-virus/tools/f-parite.txt First port of call should be tracking down where the infections come from - who has write access to the shares and how this could have happened, otherwise after cleaning up the server either with a tool or by restore from backup it'll likely pop right back up. Good luck! 1
mattcharlton Posted June 2, 2008 Author Posted June 2, 2008 Thanks again mate. Problem we've got is the Sims share and apps share are mapped for all staff. We're trying to nail it down but from looking at the Sophos log (something I don't do enough), its showing infections on the sims server from 14/5/08 - the infected files are in the setups folder and it was the night I was trying to do the sims may update (before it was pulled) after it had already failed for our sims administrator due to a signature mis-match. The signature didn't match because it was infected with a virus evidently. The may update didn't get pulled because it was infected with a virus did it? I presume now that the infected machine is a registration workstation and that the may update has now infected all registration machines if not all classroom machines. We're going to be pulling a late one. Basically disconnecting everything at 3pm, clean the servers, make sure sophos is activated fully on them, start working through the 900 workstations we have and go from there. I really can't believe this has happened.
mattcharlton Posted June 2, 2008 Author Posted June 2, 2008 Server cleanup is going well, that f-secure thing did the trick. Need to work out what we're going to do site wide now. Making sure sophos is set up properly on the servers with full on-access scanning set up. Going to work out a way to run that app on login and we'll just log everything in (quicker than re-imaging - just). Maybe re-image the registration machines that will need a sims update on them anyway.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now