Re: Spyware on an SBS client and what to do?
- From: stephen <stephen@xxxxxxxxxxxxxxx>
- Date: Wed, 23 Jul 2008 16:10:38 +0100
Leythos wrote:
In article <#cHYt4L7IHA.4864@xxxxxxxxxxxxxxxxxxxx>, stephen@xxxxxxxxxxxxxxx says...I'm just back from removing this from a client's computer. The malware came in an email pretenting to be from UPS in the form of a zipped exe. Neither clamav nor Trend WFBSA prevented the infection although the Trend logs showed some stuff had been found and cleaned.
A properly setup firewall would never have permitted an exe to pass through to the users email box. A properly setup Exchange Aware anti-
malware product would never have let an exe pass to the user through email either.
What forms of protection are you using on this server?
This server is running Trend Micro Worry Free Business Security Advanced (the successor to CSMSS). This was a zipped exe, not a raw exe. The mail is also pre-scanned with MailScanner (incorporates ClamAV anti-virus and SpamAssassin anti-spyware)before it hits Exchange. ClamAV didn't pick it up, nor did the Exchange scanner in Trend, so the infected message ended up in the user's Junk Mail Folder. They then opened the zip attachment and double clicked on the exe inside (file extensions were hidden so it was not obvious to the user that this was an executable).
I would have thought that the Trend real-time scanner should have blocked this, but it didn't, although later inspection of the Trend logs shows that it did detect malware associated with this exe. I'm not sure if a later update to Trend was able to detect the malware but the pattern was not available when the user ran the program. In any case, I am dissappointed in the performance of Trend in this instance, because despite the protection, a deep infection occurred, which required a site visit to fix.
--
stephen
.
- Follow-Ups:
- Re: Spyware on an SBS client and what to do?
- From: Leythos
- Re: Spyware on an SBS client and what to do?
- From: Les Connor [SBS MVP]
- Re: Spyware on an SBS client and what to do?
- References:
- Spyware on an SBS client and what to do?
- From: Hollis Paul
- Re: Spyware on an SBS client and what to do?
- From: stephen
- Re: Spyware on an SBS client and what to do?
- From: Leythos
- Spyware on an SBS client and what to do?
- Prev by Date: SBS 2000 Comparison too 2003
- Next by Date: outlook 2003 in different language possible?
- Previous by thread: Re: Spyware on an SBS client and what to do?
- Next by thread: Re: Spyware on an SBS client and what to do?
- Index(es):
Relevant Pages
|