From Testing to Production in a day.
This client had a small company with about 60 computers over 4 branch offices across India.
They were using Kaspersky and AVG in their network. About 40 clients had kaspersky 15 had AVG and 5 were having no antivirus at all,
So they had asked for a 5 user license to test it as they said they have used many antivirus but were not satisfied with any yet.So they wanted to test it first on 5 computers for a month or so If they would like it they will deploy on all the computers
Then I found they were having a major Outbreak of Downadup.b and w32.Harakit and their production was down.
I was shocked to see that the Domain controller was using AVG free version, Later they explained as Kaspersky was not catching anything on the server so they removed it and installed AVG but still no luck.
The domain controller itself was the File server and database server. The users had to access the server's folders and drives to store, retrieve and access their data.
But now due to the infection they were not able to do so as they were not able to open the Shared drives on the servers.
The client had resolved the issue with account lock out by disabling number of attempts in group policy.
So when I had the first look on the server the situation was horrible. The server was extremely slow with pop-ups coming now and then.
So the very first thing I did was disconnected the server from the network, removed AVG and installed SEP with all the features and downloaded and installed latest rapid release from another computer, restarted the server in safe mode a ran a full scan.
It found about 20 different kinds of threats mostly w32.downadup.b,w32,trojans and downloaders.
Restarted the server in normal mode Ran ESUG Loadpoint diagnostic tool and Rootkit revealer found at least 50 suspected files.
So I submitted everything I could think of to Symantec Security Response.
Then I went ahead and disabled Autoplay from group policy
Downloaded KB 958644 and gave it them to install it on all the computers by the end of the day, they agreed.
After installing KB 958644 on the server I ran Downadup removal tool from Symantec website.
Server was a bit stable by now but still pop-ups never stopped.
After reviewing the NTP logs I found out which computers were attacking after checking those computers I found they had no patch and no antivirus.
I just dint had to deal with Downadup but also Harakit others were just Trojans so they can be taken care locally but these 2 worms were the major concern.
I installed SEPM on the server created a install package and deployed it to clients without antivirus and ran full scan in safe mode with Least Rapid Release definitions.
As I was doing the deployment I got call from the higher management of the company requesting me to take care of the outbreak and requested me to install SEP on all the 60 computes.
Immediately the called Symantec Sales and got License for more 55 computers.
So we went ahead and removed Kaspersky and AVG from all other computers and deployed SEP on them.
The next day we got response from Symantec Security Response out of about 50 files I had submitted 40 were infected and detected.
We downloaded Rapid Release updated SEPM with JDB all clients got updated immediately with new Definitions.
Ran a full scan from SEPM almost all the clients had hundreds of detections.
There were 2 computers which had to be re-imaged because the system files were corruped due to some File Infector virus.
I taught the Admin over there how to use SEPM console and how he can use application and device control feature to maintain security and guided him to Symantec forum.
Till the 2nd days evening everything was under control all the computers were running on SEP and their business was up and running.
Their Management was too happy with the Product and the Fast response they got with Symantec Security Response..
What a feat it must be.... so
What a feat it must be....
so after the installation, how are they performing today?
What SEP version are they using now?
thanks.
Nel Ramos
Latest and Greatest MR4Mp2
After having such a outbreak and downtime they realised the importance of security.
So now they are using the latest mr4mp2 and are doing great.
They have blocked USB drives for all employees except for their Managers.
GUPs are in place and the Admin over there gets notified with all the Notification emails.
They were using VNC that was getting detected by PTP but even that has been taken care of.
The Server and the clients run full scan daily at evening.
Now they are really in good shape.
SEP 11.0 Top Articles
FAQ about Symantec Critical System Protection
can you please let me know
can you please let me know what is PTP
@Vikram Kumar-SAV to SEP:
@Vikram Kumar-SAV to SEP: that is good to hear... being a user of the new MR4MP2... what would you say is the most significant added feature it had over its predecessors?
We are still checking if the upgrade would be that big a PRO...
thanks...
Nel Ramos
Quite a few but still depends
There are quite a few changes made in mr4mp2 but what really depends is the issues that you are facing is that fixed.
Some common issues like
Proactive Threat Protection displays the status "Waiting for Update" after a client migration
Windows Security displays the warning "MALWARE PROTECTION out of date" after a user manually runs an Active Scan or a Complete Scan
Clients cannot download content from Group Update Provider (GUP)--This was a major issue
During installation of LiveUpdate, lucheck.exe returns an invalid error code
Ping response times increase in releases since Symantec Endpoint Protection 11 MR3
Inconsistent behavior with NTP "Microsoft Windows Networking" settings---Used to block network shares
Deleting old packages generates errors in the Symantec Endpoint Protection Manager during manual LiveUpdate
Slow process of DAT files in the Inbox\Agentinfo folder on the Manager
- But i am still not sure if it is completely fixed
And many more which you can check in the release notes for sep
http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007121216360648
SEP 11.0 Top Articles
FAQ about Symantec Critical System Protection
yeah actually i as well got
yeah actually i as well got good response from Symantec Security Response
as soon as i send them files ; within 18 hours they provided rapidrelease to me
Happy to hear such a story
Happy to hear such a story
Mr4Mp2
Mr4Mp2 has been the most stable version till date.
may i know which company it
may i know which company it is which migrated to sep from kav & avg.
Would you like to reply?
Login or Register to post your comment.