Endpoint Protection

 View Only

Popular documents of Symantec Endpoint Protection 11.0 

May 25, 2010 06:57 PM


Symantec Endpoint Protection 11.0 Top Articles
http://service1.symantec.com/SUPPORT/ent-security....

Top 10 Symantec Best Practices - Deploying Symantec Endpoint Protection Architecture
 http://service1.symantec.com/support/ent-security.nsf/docid/2009012721190648?Open&seg=ent

Best Practices with Symantec Endpoint Protection (SEP) Group Update Providers (GUP)
http://service1.symantec.com/support/ent-security....

Symantec Endpoint Protection: LiveUpdate Troubleshooting Flowchart
http://service1.symantec.com/SUPPORT/ent-security....

Best Practices guide for Installing the Symantec Endpoint Protection Manager with a SQL Server 2005 Database
http://service1.symantec.com/support/ent-security....

Best Practices for Symantec Endpoint Protection Location Awareness
http://service1.symantec.com/support/ent-security....

How to add "Replication Partners" and Schedule Replication
http://service1.symantec.com/SUPPORT/ent-security....

Best Practices for Disaster Recovery with the Symantec Endpoint Protection Manager
http://service1.symantec.com/SUPPORT/ent-security....

Manual uninstallation documents for Symantec Endpoint Protection
http://service1.symantec.com/SUPPORT/ent-security....

Statistics
0 Favorited
0 Views
0 Files
0 Shares
0 Downloads

Tags and Keywords

Comments

May 26, 2010 10:20 PM

1. Even a single computer in whole network is not fully patched up with Microsoft Patches, or doesn't have latest definitions protection. It is potential risk to your environment for infection of W32.Downadup. So Make sure all computers are compliance with both of these.

2. Make sure users have complex passwords. As when any computer gets infected with downadup. It tries to hack user accounts from Activer directory. You might have seen user accounts getting locked up when there is infection of downadup. This is due to default policy of locking up account after 3 failed attempts in AD.

3. All admin (C$) share should be disabled. all shares should be password protected.

4. Autorun MUST be disabled. As it has been seen that this is generally main reason. Note that Autorun.inf is not infected file (its only a text file). However, the entries inside it would get executed if autorun is enabled. In other words, when autorun is enabled, threats can easily execute themselves with autorun from different media, computer shares, etc.

5. Intrusion prevention technology with Symantec Endpoint protection could be crucial against downadup. As only Antivirus & antispyware can't fully protect against downadup due to network attacks. Enable risk tracer after intalling intrusion prevention feature for SEP to trace the attacker machine.

and Last but not the least. Never assume that because you have definitions, so you can't get infected with viruses. Attackers are constantly trying to create new variants of threats so nobody is 100% protected and I guarantee that no security providers can give 100% guarantee that you computer will never be infected. If they do, they are liers.

Just be sure that you are fully up-to-date with all patches, definitions. Taking necessary measures for environment protection. and Most important, as soon as any possible infection. Immediately contact Support for further help if the threat is not getting detected.

Related Entries and Links

No Related Resource entered.