Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

W32.Zoher@mm

Status
Not open for further replies.

Pharquah

MIS
May 14, 2001
27
0
0
GB
I've got this email server (notes domino) running on NT4 (SP6) with NAV corporate edition latest version running on it. Defs are up to date.
When I do a full scan of the system, it appears to be clean, but every night, three copies of W32.zoher@mm appear in the quarantine that have been picked up by the real time file protection. No other machine in the network has/had the virus. The domino server also has norton av for lotus notes v2, which detects nothing. We also have mailsweeper, with norton av plug in. That doesn't detect anything either.

Where is coming from???

Any ideas would be most appreciated??
 
Thanks for the pointer, I already checked it though...
 
The fact that the files are already in quarantine means that NAV already detected them. Shouldn't pose too much problems. You can just delete them.

The problem here would seem to indicate that instead of NAV cleaning the virus (and probably deleting it), it chose to quarantine the files. Unless you've had it to quarantine in the first place, I'm not comfortable with having virus-infected files ANYWHERE on my network.

AVChap
 
That's the point - every machine in the network gets a full scan every day, and they ALL come out clean. And then at some ridiculous time of night these 3 zoher files (random file name.exe) appear in quarantine, and they were picked up from the %systemroot%\temp folder. Crazy.
 
Send the files to Symantec. Have them check whether these files are causing a "false positive", which is not a good thing.

AVChap
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top