Re: windows event ID when finding a virus??

From: Galen (galennews_at_gmail.com)
Date: 04/29/05


Date: Thu, 28 Apr 2005 23:29:12 -0400

In news:1f716d42.0504280657.43fe5937@posting.google.com,
paul b <bisibis@pt.lu> had this to say:

 My reply is at the bottom of your sent message:

> Hello,
> I am using Symantec Antivirus and Norton Antivirus as antivirus
> software in my network. Because I want to monitor my network with
> whats'sup, I need the eventID that I get in the event manager when a
> virus is found.
> (For example, if a file could not be opened, the event ID I get is 6
> (with as source Symantec Antivirus). Which is the corresponding event
> ID when a virus is found???
>
> Thanx in advance

I don't know if NAV does but I know KAV doesn't (from my logs though it
could be my configuration) write an event to the event log when viruses (or
is that virii??? no one seems to know) found. All I can say is you've been
told where to download eicar which might trigger the event if, indeed, one
is found. I just tested that and nothing came up in mine.

Galen

-- 
"My mind rebels at stagnation. Give me problems, give me work, give me
the most abstruse cryptogram or the most intricate analysis, and I am
in my own proper atmosphere. I can dispense then with artificial
stimulants. But I abhor the dull routine of existence. I crave for
mental exaltation." -- Sherlock Holmes 


Relevant Pages

  • windows event ID when finding a virus??
    ... I am using Symantec Antivirus and Norton Antivirus as antivirus ... software in my network. ... I need the eventID that I get in the event manager when a ... ID when a virus is found??? ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Virus Warnning
    ... > It is not the antivirus filter for Exchange that discovers the virus. ... >> Our company is using Exchange Server 2003 and Symantec AntiVirus Filter ... Have any people know what's wrong in the mail server? ...
    (microsoft.public.exchange2000.general)
  • Re: Possible virus?
    ... | Symantec AntiVirus found a virus in an attachment from ... It surprised me, and while I do have Symantec AntiVirus, I'm not sure ... I didn't download anything and ... This is the returned-to-sender email I got: ...
    (microsoft.public.windowsxp.general)
  • Re: Antispyware beta- virus after downloading
    ... potentially unknown virus is found using Symantec Bloodhound technology. ... but this is just in old version of symantec antivirus 2004 or corporate 7 ... > These newsgroups can be accessed via NNTP or HTTP. ...
    (microsoft.public.security)
  • Possible virus?
    ... I'm worried that I've somehow gotten the W32.Mytob virus. ... It surprised me, and while I do have Symantec AntiVirus, I'm not sure ... I didn't download anything and ... | This is the mail system at host alipes.hs.columbia.edu. ...
    (microsoft.public.windowsxp.general)