Endpoint Protection

 View Only
  • 1.  fake -viruses

    Posted Apr 27, 2011 05:11 PM

    dear all ,

     

    Our users are severly attacked by fake antivirus like win7 internet security 2011 viruses 

     

    Is there a way to protect sever attack?

     

    Thank you 

     

    Sep 11.0.6+mp2



  • 2.  RE: fake -viruses

    Posted Apr 27, 2011 05:21 PM

    1. Bump up your AV settings to the recommended levels.

    Security Response recommends the following Scan Settings

     

    Antivirus Security Setting Default Setting High Security Policy Security Response Recommendation
    Lock settings Some Some All
    Remediation: terminate processes No No Yes
    Remediation: terminate services No No Yes
    Auto-Protect action taken for security risks Quarantine/Log Quarantine/Log Quarantine/Delete
    Network Auto-Protect Disabled Enabled Enabled
    Bloodhound Level Default (2) Default (2) Default (3)
    SEP Startup System Start System Start System Start
    Auto-Protect Scan Modify and access Modify and access Modify and access

    Security Response recommends the following setting changes to Truscan for best protection

     

    Truscan Default Setting Security Response Recommendation
    Scan Sensitivity 9/Low 100
    Action on Detection Log Terminate
    Scan Frequency 1:00 00:15

     

    2. Follow the "Best Practices", and make sure your users are educated on safe web practices to prevent these types of threats from getting in to your environment.

    http://www.symantec.com/business/theme.jsp?themeid=stopping_malware&inid=us_sr_carousel_panel7_best_practices

     

    3. Add Safe Web Lite to your clients to help identify malicious sites.

    http://safeweb.norton.com/lite

    Best,

    Thomas



  • 3.  RE: fake -viruses

    Posted Apr 27, 2011 05:53 PM

    To this I would add:

    - Ensure you're using Network Threat Protection:

    Best practices regarding Intrusion Prevention System technology
    http://www.symantec.com/docs/TECH95347

    - Utilize Application and Device Control to limit how these things access your computers (test first!):

    How to use SEP to protect against rogue "browser helpers"
    https://www-secure.symantec.com/connect/articles/how-use-sep-protect-against-rogue-browser-helpers

    - Ensure systems are fully patched with all Windows critical updates and updates for Adobe (Flash, Reader), Java, Quicktime, etc. [edit: oh, this duplicates your #2 smiley]

    sandra



  • 4.  RE: fake -viruses

    Trusted Advisor
    Posted Apr 28, 2011 05:39 AM

    Hello,

    There are number of Articles which suggests wide area of Prevention ways and Resolution steps.

    Here are the few of the article which you can go through to get your questions answered.

    1) How to troubleshoot FakeAV if it is not detected

     
    2) Using Symantec Support Tool, how do we Collect the Suspicious Files and Submit the same to Symantec Security Response Team. 
     
     
    3) Containing An Outbreak: How to clean your network after an incident

    http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/containing_an_outbreak.pdf

    4) Hardening Symantec Endpoint Protection with an Application and Device Control Policy to increase security
     
     
     
     
    Hope these Excellent Articles help you the best!!!


  • 5.  RE: fake -viruses

    Broadcom Employee
    Posted Apr 28, 2011 07:59 AM


  • 6.  RE: fake -viruses

    Posted Apr 28, 2011 09:07 AM

    Let's move back a step from all the boilerplate Best-Practices & HowTos to one of the key areas for the Symantec defense, their authoring & distribution of their definition files. I have a few questions on Symantec denfinition release schedule.

    * How long does it take for newly identified viruses/malware variants to be added to a rapid release definition?

    * How long does it take for newly added signatures of viruses/malware variants that appeared in a rapid release to be fully tested and migrated over to an official standard definition release?

    I saw that the Norton Safe Web was suggested. I personally haven't had any experiences with it. Is it using a signature based definition file or is it scanning the remote website page on the fly? How does NSW handle malicious websites that only live at a particular domain/IP for a few hours before moving shop to another address? 



  • 7.  RE: fake -viruses

    Posted May 09, 2011 12:53 PM

    @ glentc, Please read this page for details on the different types of virus definitions and their publishing frequency.

    http://www.symantec.com/business/popup.jsp?popupid=sr_help_popup

     

    Norton Safe Web is a reputation based service, see this link for more information - http://safeweb.norton.com/about