?
Solved

Beagle.AG help

Posted on 2004-09-16
2
Medium Priority
?
214 Views
Last Modified: 2010-04-11
The problem:
a user (the CEO) brought an infected laptop onto our network. It was mostly infected with BeagleAG.  There was no blatant noticable affect to our network, no slowness nothing bogged down, even the PC itself was not running too bad...


1. the virus definitions had not been updated since 21 July. He was running SAV 8.1. Live Update appeared to have been disabled.  updated to SAV 9.0, same def. date. completely removed SAV and reinstalled 9.0 updated to current definitions.  

2. SAV found 250 infected fles and quarantined them all.  Ran removal tools, and a full system scan. Also ran full system scan in safe mode. the removal tools and scans found nothing else.  System restore had been disabled before scanning.

3. The other executives began getting emails 'from' other execs with the BeagleAG virus.  None of these other PC's are infected.  No one outside of the Sr Mgt group is recievng the messages.  All viruses are being detected and quarantined.
 
My question:
Why is the message still being sent to other Execs?? And if the message is being decteted and quarantined why/how is it still getting forwarded?

keep in mind that we are talking about 5 out of 100 users and that the messages are only being sent to this specific group.  No one else in the company is getting these messages from these or any other users.

OS is WinXPSp1 on all clients.  SAV9.0, Exchange 5.5

Thanks for the help
0
Comment
Question by:Clamsy
2 Comments
 
LVL 1

Accepted Solution

by:
Keravi earned 2000 total points
ID: 12075888
I would check for the presence of Internet headers on any of the infected emails to see if they are coming from the outside, unless you know that your AV solution would stop these before getting to Exchange, or, your AV is cleaning the infected attachment but allowing the message to continue on to the clients. My bet is that one of the  Execs' home computers or even corporate laptops that haven't been inside for cleaning yet is perpetuating this problem, and that would explain why only certain members (execs) are still getting this. I would also check the exchange logs to try to correlate to any hosts that are sending this out.
0
 
LVL 2

Author Comment

by:Clamsy
ID: 12076444
Thank you!
I never tought to check the mail headers.  The messages were from an external source.  I have blocked the domain from Exchange.  I am just glad they are from n internal source.

The AV is cleaning the attachment but is also sending along the infected message to other users, only one at a time.  It is not a situation where my 70 users are slammed with junk.  I am talking about two to three messages a day and only to these 5 users.

Thank you again, points  awarded.
0

Featured Post

Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

With the evolution of technology, we have finally reached a point where it is possible to have home automation features like having your thermostat turn up and door lock itself when you leave, as well as a complete home security system. This is a st…
Experts Exchange expands question security options for members.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Is your data getting by on basic protection measures? In today’s climate of debilitating malware and ransomware—like WannaCry—that may not be enough. You need to establish more than basics, like a recovery plan that protects both data and endpoints.…
Suggested Courses

839 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question