Endpoint Protection

 View Only
  • 1.  Anserin outbreak

    Posted May 22, 2013 04:44 AM

    I have an question, mostly directed at symantec itself.

    I work in The Netherlands as an IT Specialist with an company that services about 100+ customers.

    We almost exclusivly use Symantec Endpoint Protection and Mail Foundation but my faith is starting to fail in these products.

     

    At several of our customers we have had outbreaks of virusses recently, none of which endpoint of mail foundation stopped.

    Oh yes, of course the management interfaces show that threats have been stopped but we have to many occurences that get through.

    Our most recent issue has been the anserin (http://www.symantec.com/security_response/writeup.jsp?docid=2005-112315-0608-99) virus. The problem with this one it that the phone home traffic gets you on spam blacklists even with port 25 closed for everyone except the mail server. Causing big disruption with the small to medium business clients.

    This is an virus that's pretty old and this gets though endpoint.

    By now I'm wondering why symantec's AV products can be bypassed so often when to product is up to date, with full protection enabled...

    Even when infected, endpoint was unable to detect the virusses. We had to use an competitors off-line scan solution to find en disinfect the computers.

    My goal btw is not to handle every individual case but to discus the general performance of the product.

    Any response from symantec would be greatly appriciated.

     

    Dominic



  • 2.  RE: Anserin outbreak

    Broadcom Employee
    Posted May 22, 2013 05:05 AM

    you should be opening a support ticket and take help of security response for the issue.



  • 3.  RE: Anserin outbreak

    Posted May 22, 2013 05:15 AM

    pete_4u2002, like i said; i don't want to handle individual cases by opening support tickets. I what to know why symantecs AV products don't do their jobs and discus about that.

    That way if someone else has this problem they can read this topic and learn from the conclusions and/or tips and tricks we end up with.



  • 4.  RE: Anserin outbreak

    Posted May 22, 2013 07:10 AM

    Which version? 

    Which features are disabled if any? 

    What security best practices (disable autorun, etc.) are in place?



  • 5.  RE: Anserin outbreak

    Broadcom Employee
    Posted May 22, 2013 07:18 AM

    Hi,

    You need to know the best practices for responding to active threats on a network

    Best Practices for Troubleshooting Viruses on a Network

     
    Responding to a virus infection comprises the following five steps:

    Step 1. Identify the Threat and Attack Vectors
    Step 2. Identify the Infected Computers
    Step 3. Quarantine the Infected Computers
    Step 4. Clean the Computers Infected

    It's always recommended to have SEP client installed with all three features i.e. AV/AS, PTP & NTP with the latest definitions

    Machine should have latest Windows patches and Service pack.

    Disable Autorun if using SEP 11 version. In SEP 12.1 auto run is disabled by default.

    Update third party software to their latest versions.

    If you think SEP is still not able to detect the threat then need to identify the source of these attacks and submit the suspicious files.

    Enable Risk tracer to see from where the virus is coming

    http://www.symantec.com/business/support/index?page=content&id=TECH102539 

    How to Use the Web Submission Process to Submit Suspicious Files

    http://www.symantec.com/docs/TECH102419

    Symantec Security Response usually takes half a day to a day (depend upon entitlement) to provide a response. In the interim, you can try these sites for a quick analysis:

    Virus Total: http://www.virustotal.com/

    ThreatExpert: http://www.threatexpert.com/submit.aspx

    Common loading points for viruses, worms, and Trojan horse programs on Windows 2000/XP/2003
     
    http://www.symantec.com/docs/TECH99331 
     
    If it's a virus outbreak and not able to stop spreading threat then please log a case with Support as a 1D to receive immediate assistance.  


  • 6.  RE: Anserin outbreak

    Posted May 22, 2013 07:41 AM

    What version of SEP are you running and what components are you using for it?

    Here are some KBAs for 11.x and 12.1 which will get you started

    11.x

    Security Response recommendations for Symantec Endpoint Protection settings

    Article:TECH122943  |  Created: 2010-01-03  |  Updated: 2010-11-16  |  Article URL http://www.symantec.com/docs/TECH122943

     

    12.1

    Security Response recommendations for Symantec Endpoint Protection 12.1 settings

    Article:TECH173752  |  Created: 2011-11-07  |  Updated: 2011-11-21  |  Article URL http://www.symantec.com/docs/TECH173752

     



  • 7.  RE: Anserin outbreak

    Trusted Advisor
    Posted May 22, 2013 07:58 AM

    Hello,

    Could you please let us know what version of SEP are you running?? Is that SEP 11.x or SEP 12.1 ??

    I would suggest you to run the SymHelp utility on the client machine with suspicious activies, which would then scan the machine for suspicious files. Check this Article:

    Using Symantec Help (SymHelp) Tool, how do we Collect the Suspicious Files and Submit the same to Symantec Security Response Team.

    https://www-secure.symantec.com/connect/articles/using-symantec-help-symhelp-tool-how-do-we-collect-suspicious-files-and-submit-same-symante

    Scanning a file with a competitor's antivirus program detects a virus, but scanning with Symantec AntiVirus or Symantec Endpoint Protection does not

    http://www.symantec.com/docs/TECH98929

    What to do when you suspect that a Symantec AntiVirus product is not detecting viruses

    http://www.symantec.com/docs/TECH99222

    In your case, it is also advisable to follow few important steps:

    1) Make sure all these machines are Patched with ALL Latest MS security patches and service packs.

    2) Make sure the machines are installed with the Latest Symantec virus definitions.

    3) Disable the Autorun Feature on the machine via GPO. http://support.microsoft.com/kb/967715

    4) Disable System Restore before you do this as the virus also creates entries in the System Restore Points store volumes.

    Make sure to review some of the best practices:

    http://www.symantec.com/business/theme.jsp?themeid...

    Also, tighten up security on the SEP client. Out of the box settings do not cut it:

    http://www.symantec.com/business/support/index?pag...

    Hope that helps!!