Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

hi all

 

i have recently taken over working as NM at a large primary in my local area and im having problems

 

my sql server/sims server has w32/sality-am and cxmal/pifpad-A and so does my primary domain controller

 

there both s2008 r2 64 bit and both have sophos end point security on and im struggling to get rid of them

 

sophos is useless at this point i want to remove the threat but with out taking the servers off line as my main dc does just about everything

 

has anyone else got any suggestions of how to remove it i have tried obviously sophos, msert, slty.exe and all make no difference or even see the virus

 

Regards

 

Me

Posted
Characteristics

Turns off anti virus applications

Deletes files off the computer

Records keystrokes

 

As a matter of urgency I would be taking down both servers, booting to safemode or a PE and running a full virus scan/hijackthis/spybot etc etc.

 

Whats the point of keeping the servers up if you have no idea what sensitive information they are capturing, sending or deleting?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...