Re: Spyware on an SBS client and what to do?

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



In article <#cHYt4L7IHA.4864@xxxxxxxxxxxxxxxxxxxx>, Stephen wrote:
I'm just back from removing this from a client's computer. The malware
came in an email pretenting to be from UPS in the form of a zipped exe.
Neither clamav nor Trend WFBSA prevented the infection although the
Trend logs showed some stuff had been found and cleaned.

YES! I saw this at the ISP's mailbox and failed to see that it was about
a parcel post we might have sent; and passed it through to Ann. She
opened it and then asked me about it. We deleted it immediately, but the
damage had obviously been done. And, Trend Micro did miss it.

Now, to clean it up.

--
Hollis Paul
Mukilteo, WA USA


.



Relevant Pages

  • Re: Spyware on an SBS client and what to do?
    ... It seems like a lot of the AV vendors were late in detecting the "UPS" ... malware, considering it was blogged about last week: ... UPS even put a warning on their site about it. ... Trend logs showed some stuff had been found and cleaned. ...
    (microsoft.public.windows.server.sbs)
  • Re: OT: Cap and Trade and The Cooling Earth
    ... but the chart I linked to is actual data. ...  It isn't steady. ... There are ups and downs, but the trend over the last 10 years is down, ...
    (alt.sports.baseball.bos-redsox)
  • Re: Spyware on an SBS client and what to do?
    ... came in an email pretenting to be from UPS in the form of a zipped exe. ... Neither clamav nor Trend WFBSA prevented the infection although the ... Trend logs showed some stuff had been found and cleaned. ...
    (microsoft.public.windows.server.sbs)
  • Re: Spyware on an SBS client and what to do?
    ... Neither clamav nor Trend WFBSA prevented the infection although the Trend logs showed some stuff had been found and cleaned. ... A properly setup firewall would never have permitted an exe to pass through to the users email box. ... The mail is also pre-scanned with MailScanner (incorporates ClamAV anti-virus and SpamAssassin anti-spyware)before it hits Exchange. ... In any case, I am dissappointed in the performance of Trend in this instance, because despite the protection, a deep infection occurred, which required a site visit to fix. ...
    (microsoft.public.windows.server.sbs)