Koozali.org: home of the SME Server
Legacy Forums => General Discussion (Legacy) => Topic started by: Ron Moxham on June 11, 2003, 12:02:45 PM
-
Anyone have any experience with this type of virus.
My RAV scan picked up this.
Scan engine 8.11 for i386.
Last update: Tue, 10 Jun 2003 08:59:38 -0700
Scanning for 79323 malwares (viruses, trojans and worms).
Scan started on Tue Jun 10 23:38:53 2003
var/spool/squid/00/2A/00002AB7->(part0000:)->ie_plugin.exe Infected:
TrojanDropper:Win32/Delf.AV
Scan ended on Tue Jun 10 23:44:16 2003
I tried to remove it like so:
# rm /var/spool/squid/00/2A/00002AB7
The virus still shows up when i scan the server.
Any ideas?
-
Sounds like one of your clients downloaded this and it's still in the squid cache. Have you tried flushing the cache? There is an add-on by Abe Loveless (sp?) around somewhere that will allow you to do this from the server manager.
-
Thanks. Any idea where I could find that RPM?
-
All of his contribs and other stuff is here
http://www.tech-geeks.org/contrib/loveless/
-
Anyone know how Abe's panel (re/inter)acts if you have dansguardian installed?
Doug M.
-
Thanks to Terry and byte and of course Abe. After I got time to install Abe's panel and flush the squid cache my problem dissappeared.
Cheers