Get your own customer support community
 

Why does Vipre AP NOT detect Win32.Virut.x?

Our network was hit with the Win32.Virut virus the only reason we picked up on the infection was blocked IRC traffic on our firewall going to the URL jL.chura.pl/rc/: a malware URL, and that users outbound email was being blocked by our Mail Marshal SMTP gateway which uses another virus scanning engine which (works) picked up the virus. Vipre was reporting all the workstations to be 'clean' even after multiple deep scans.

Once on the LAN and undetected by Vipre this virus spread like wildfire infecting .exe's both locally on the workstations and then to our dismay on our file server. It also dropped Iframes into .HTML code pointing to jL.chura.pl/rc/ if it had got onto our internal company web servers it would have been very embarrassing.

We had to clean what workstations we could with Dr Web boot CD. Other machines that were too infected had to be reimaged / rebuilt. The fileserver had to be restored from backup, an alternate AV product installed that detected Virut and then cleaned.

Just wanting to see if other users running Vipre Enterprise running the latest AV definition files and configure to Vipre's best practices recommendations have experienced anything similar? In particular Win32/Virut.

Has really left our confidence in Vipre Enterprise shot to bits. If one gets through undetected then how many more have snuck through under the radar?

If anyone from Sunbelt reads this how can I get you an 'infected' file for analysis so Vipre can start detecting and removing this nasty.
 
sad I’m seriously worried
Inappropriate?
1 person has this question

User_default_medium