Video Screencast Help

folder.exe virus removal

Created: 14 Aug 2012 • Updated: 14 Aug 2012 | 6 comments

my all network pc infected to anything usb device inside data folder he create to folder .exe

 

 

Discussion Filed Under:

Comments 6 CommentsJump to latest comment

K33's picture

 

Update your system latest Defination.

https://www-secure.symantec.com/connect/forums/need-virus-removal-tool

If not, there are useful some tools that are provided by Symantec for help with finding those hard to detect threats.

1.       The Power Eraser Tool eliminates deeply embedded and difficult to remove threats that traditional virus scanning doesn't always detect.

2. The SERT (Symantec Endpoint Recovery Tool)is useful in situations where computers are too heavily infected for the Symantec Endpoint Protection client installed upon them to clean effectively.

3. The Load point Analysis Tool generates a detailed report of the programs loaded on your system. It is helpful in listing common loadpoints where threats can live.

Rapid Release Virus Definitions –

http://www.symantec.com/business/security_response/definitions/download/detail.jsp?gid=rr

Power Eraser tool –

http://security.symantec.com/nbrt/npe.asp?lcid=1033&origin=default

How To Use the Symantec Endpoint Recovery Tool with the Latest Virus Definitionshttp://www.symantec.com/business/support/index?page=content&id=TECH131732&locale=en_US

Support Tool with Power Eraser Tool included –

http://www.symantec.com/business/support/index?page=content&id=TECH105414&locale=en_US

How to use the Load Point Analysis within the Symantec Support Tool to help locate suspicious files http://www.symantec.com/business/support/index?page=content&id=TECH141402

If you are unable to remove the threat(s) from your systems, please submit the suspected files to Symantec or ThreatExpert for analysis. New signatures will be created and included in future definition sets for detection.

http://www.symantec.com/business/security_response/submitsamples.jsp

http://www.threatexpert.com/submit.aspx

Check this fourms........

https://www-secure.symantec.com/connect/forums/folder-name-exe-virus

https://www-secure.symantec.com/connect/forums/symantec-endpoint-protection-could-not-catch-newfolderexe-virus

 

 

cus000's picture

More information needed.... what AV are you using? SAV/SEP.... and what version?

 

 

Try run SEP Support tool... capture the sample and submit to Symantec... my wild guess this could be W32.lmaut....

SameerU's picture

Please submit the suspicious files to Symantec Security Response

Regards

 

ABN's picture

Hello Supportit,

As first action of business kindly disable Autorun in your network.

The below link may help.

http://www.symantec.com/docs/TECH104447

Once done, a full system scan with latest definitions (preferably rapid release) will help.

Mithun Sanghavi's picture

Hello,

Check this Thread with similar Issue: https://www-secure.symantec.com/connect/forums/folder-getting-created-folderexe

Are you running the SEP 12.1 client with latest definitions and carry all the latest Microsoft updates and security patches on the machine?

The symptoms sounds like W32.SillyFDC to me.

  1. Run a scan in safe mode with networking to remove the virus. (Make sure SEP is updated with the Latest definitions)
  2. Disable System Restore before you do this as the virus alse creates entries in the System Restore Points store volumes.
  3. Disable Autoplay for ALL DRIVES Via a GPO (If you're on a domain), and
  4. Disable SImple File Sharing if it's enabled to prevent the infection from propogating itself by binding to files.
  5. Secondly, Submit these files to the Symantec Security Response and they will get detected. https://submit.symantec.com/essential

Using Symantec Support Tool, how do we Collect the Suspicious Files and Submit the same to Symantec Security Response Team.

Hope that helps!!

Mithun Sanghavi
Senior Consultant
MIM | MCSA | MCTS | STS | SSE | SSE+ | ITIL v3

Don't forget to mark your thread as 'SOLVED' with the answer that best helped you.