Finding a virus infected file in the Sharepoint Portal Server document store



Hi,
Symantec anti-virus picks up and cleans some file(s) every time it
runs on our SPS 2003 server. They are always in the \Program Files
\SharePoint Portal Server\DATA\Temp\spsgthrsvc\ folder and I have
worked out that it is the search gatherer that is pulling the files
out of the database and putting them there to be searched at which
point the anti-virus sees them. The question is, how do I find out
which files in Sharepoint the infected gatherer files correspond to?
By the time they have been copied locally, they have been re-named to
random names like flt7116_6892.doc, so how do I hunt down the
offending object(s) in the document libraries so I can delete them?
I'm guessing there may be a logfile somewhere that can point the way,
but I don't know where to start looking.
Thanks!
.



Relevant Pages

  • Finding a virus infected file in the Sharepoint Portal Server document store
    ... Symantec anti-virus picks up and cleans some fileevery time it ... runs on our SPS 2003 server. ... worked out that it is the search gatherer that is pulling the files ... which files in Sharepoint the infected gatherer files correspond to? ...
    (microsoft.public.sharepoint.portalserver.development)
  • Re: HELP!!!!!! BSOD on customer ws2003sbs
    ... and let you know how it goes, server changeover will commence this weekend so ... > Symantec Anti-Virus 8x or Symantec Anti-Virus 9.0. ... > please check the Microsoft Hardware Compatibility List to verify that the ... > previously installed a hotfix to update this file, the installer copies the ...
    (microsoft.public.windows.server.sbs)
  • No event logs
    ... I have a 2000 server that have been fully updated and ... checked with the latest Symantec Anti-virus. ... noticed that the event logs are empty. ...
    (microsoft.public.win2000.security)
  • mydoom question
    ... first, my exchange server is 5.5 running on an NT 4 server, all the latest ... my exchange 5.5 server also is anti-virus client, not sure if it should be ...
    (microsoft.public.exchange.misc)