LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 07-21-2012, 01:40 PM   #1
Jc61990
LQ Newbie
 
Registered: Dec 2008
Location: New York
Distribution: Arch
Posts: 18

Rep: Reputation: 0
Best tool for removing multiple infections at once


Hello everyone,

I recently had a user upload a malicious file to my server, the virus was "Worm.Tenga.A" according to ClamAV.

This virus looks like it spidered its way through my server, infecting just about every file on my Raid0 array, my root drive, and my samba drives.

ClamAV has detected 1249 infections across the whole system, and clam looks like it will only let me remove/quarantine each file 1-by-1.

My question to you guys is what would be a good software i would be able to install into the server to scan and remove all potential infections/threats?

Server is running CentOS 6.3 x64
Services that run on this system:
Webmin, Usermin, Samba, SSH, FTP, VPN, RDP, Apache, MySQL, Sendmail, and some others i cant think of at the moment.

Should i be worried about anything else on the system/network?

thanks in advance
 
Old 07-21-2012, 03:52 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by Jc61990 View Post
This virus looks like it spidered its way through my server, infecting just about every file on my Raid0 array, my root drive, and my samba drives.
Tenga / Gael targets PE, not ELF.


Quote:
Originally Posted by Jc61990 View Post
what would be a good software i would be able to install into the server to scan and remove all potential infections/threats?
Whatever software you think your data is worth?


Quote:
Originally Posted by Jc61990 View Post
Should i be worried about anything else on the system/network?
I think the nfo in http://www.f-secure.com/v-descs/tenga_a.shtml and http://www.securelist.com/en/descriptions/old88153 sums it up pretty much so make that a yes.
 
1 members found this post helpful.
Old 07-21-2012, 04:34 PM   #3
jefro
Moderator
 
Registered: Mar 2008
Posts: 21,982

Rep: Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626
A large security firm was called in to try to fix a government's office. The big firm did their normal load and try to clean and after a few days it kept failing. The solution offered was to turn off every computer (thousands) and reload it from scratch.

As to how to protect it is another matter. You can try one or two of the commercial products. None can fully protect a system from random users downloading what they please.
 
1 members found this post helpful.
Old 07-21-2012, 04:59 PM   #4
Jc61990
LQ Newbie
 
Registered: Dec 2008
Location: New York
Distribution: Arch
Posts: 18

Original Poster
Rep: Reputation: 0
thanks guys , that pretty much answers my question, i was hoping i wouldn't have to re-image the server but i dont mind doing so.

Most of the files that were on there were all personal files, the majority of the infection was in my two networked samaba drives, thats mainly where i keep all my files and installers, basically anything i like to keep but not on my own hard drive. Most of it i can re download it was there for my own convenience, but i can always re download what i had.

Quote:
Originally Posted by unSpawn View Post
Tenga / Gael targets PE, not ELF.
most of the files on my server were portable exe's, game patches, setup files, drivers and what not. i did notice in the scan tho that there were more than just exe's that got infected. im just hope it didnt get into my pictures.

The server is basically a small home hosted webserver/game server(s). One of the users of a server i was renting out uploaded what looked like an addon to a game server but actually did some damage.

I thought AVG was giving me false positives the past few days, i just opened one of my mapped samba drives and AVG said every file and folder had an infection, i found it hard to believe until i ran clam on the server its self.

I guess ill just get the thing offline start looking through what i need the most and start from scratch..
i might also re-install windows on the several pc's i had mapped to that server. Should be a fun weekend.

Once again, thanks for the help!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
TDL4 infections Linux_Kidd General 4 11-26-2011 02:23 PM
help removing multiple rpm packages at once uhlix Linux - General 4 04-14-2011 02:55 PM
Virus writers to charge for infections! vharishankar General 3 11-23-2004 10:06 AM
Removing multiple packages tipaul Slackware 8 08-21-2004 09:45 AM
DISCUSSION: Finding Rootkits, Infections, and Files jeremy LinuxAnswers Discussion 4 07-05-2004 07:00 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 04:22 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration