Endpoint Protection

 View Only
Expand all | Collapse all

How to clean a virus or trojan horse from e-mail with SEP 12.1.3

ℬrίαη

ℬrίαηJan 06, 2014 06:12 AM

  • 1.  How to clean a virus or trojan horse from e-mail with SEP 12.1.3

    Posted Jan 05, 2014 02:31 PM

    Hello to everyone.

    One of my clients that run sep 12.1.3 has detected trojan horse on e-mail but it can not clean or delete. i can not manual delete mail because i do not know which mail is it. Is any way to clean trojan horse from mail ro not???



  • 2.  RE: How to clean a virus or trojan horse from e-mail with SEP 12.1.3

    Posted Jan 05, 2014 02:34 PM

    Assuming you're using the email scanning plugin(?) it will scan your emails for malware, however, there may be cases where it cannot remove it. This can be due to a few reasons, such as the attachment being password protected, in which case SEP will be able to open it and remove the bad file.

    Does your risk log tell what PC this happened on? You should be able to narrow it down to the particular machine.



  • 3.  RE: How to clean a virus or trojan horse from e-mail with SEP 12.1.3

    Posted Jan 05, 2014 03:12 PM

    You need to make sure that Enable Internet AP/ MSOutlook AP is enabled

    https://www-secure.symantec.com/connect/forums/symantec-endpoint-protection-email-scanning-option

    Else you have to look at Messaging Gateway or Brightmail Gateway



  • 4.  RE: How to clean a virus or trojan horse from e-mail with SEP 12.1.3

    Broadcom Employee
    Posted Jan 05, 2014 09:11 PM

    how do you know the email have the trojan?

    does the email has/had attachment?

     



  • 5.  RE: How to clean a virus or trojan horse from e-mail with SEP 12.1.3

    Posted Jan 06, 2014 03:36 AM

    Hello again. First we use thunderbird for email client. Second i know which pc has the trojan but when i try to clean from the same pc it does not deleted. The trojan horse is backdoor spybot.

     



  • 6.  RE: How to clean a virus or trojan horse from e-mail with SEP 12.1.3

    Broadcom Employee
    Posted Jan 06, 2014 03:38 AM

    do you have the file? can you submit it to Symantec security response?

     



  • 7.  RE: How to clean a virus or trojan horse from e-mail with SEP 12.1.3

    Posted Jan 06, 2014 03:58 AM

    First you can scan your system and submit file Symantec Security Response Team

    Using Symantec Help (SymHelp) Tool, how do we Collect the Suspicious Files and Submit the same to Symantec Security Response Team

    http://www.symantec.com/connect/articles/using-sym...



  • 8.  RE: How to clean a virus or trojan horse from e-mail with SEP 12.1.3

    Posted Jan 06, 2014 05:31 AM

    Hi a6viper,

    Can you post the log exceprt from where the threat is detected? 

    A manual scan with the latest definitions should be all that is required to remove the great majority of threats that SEP 12.1.3 detects.  Some need a full system scan in safe mode, and a few need manual removal steps.  Looking at the log should help the experts here on Connect let you know what should happen.

    Many thanks!

    Mick



  • 9.  RE: How to clean a virus or trojan horse from e-mail with SEP 12.1.3

    Posted Jan 06, 2014 06:12 AM

    Try running a full scan in safe mode



  • 10.  RE: How to clean a virus or trojan horse from e-mail with SEP 12.1.3

    Posted Jan 07, 2014 12:53 PM
      |   view attached

    That is the virus log file from the sep client from the pc with the virus and trojan horse

    Attachment(s)

    rar
    sep_virus_log.rar   1 KB 1 version


  • 11.  RE: How to clean a virus or trojan horse from e-mail with SEP 12.1.3

    Posted Jan 07, 2014 01:00 PM

    This is from one of those emails (UPS, FedEx, DHL) that claim they have a package waiting for you and to print out some sort of receipt, shipping lable, etc.

    Either way, this will need to be manually deleted as SEP can't clean inside the backup file. If you have a the email scanner enabled, it either missed it or couldn't clean for whatever reason.

     

     



  • 12.  RE: How to clean a virus or trojan horse from e-mail with SEP 12.1.3

    Posted Jan 07, 2014 01:10 PM

    It will need manually deleted or is any other software that can deleted those mail??



  • 13.  RE: How to clean a virus or trojan horse from e-mail with SEP 12.1.3

    Posted Jan 07, 2014 01:16 PM

    Best bet is to manually delete to get rid of the file. I'm sure you could try another free scanner, although I would expect similar results.

    As for the email, you'll need to delete from within the client or it can be done from the server side by an admin



  • 14.  RE: How to clean a virus or trojan horse from e-mail with SEP 12.1.3

    Trusted Advisor
    Posted Jan 07, 2014 02:50 PM

    Hello,

    Internet Email Auto-Protect protects both incoming email messages and outgoing email messages that use the POP3 or SMTP communications protocol over the Secure Sockets Layer (SSL). When Internet Email Auto-Protect is enabled, the client software scans both the body text of the email and any attachments that are included.

    You can enable Auto-Protect to support the handling of encrypted email over POP3 and SMTP connections. Auto-Protect detects the secure connections and does not scan the encrypted messages. Even if Internet Email Auto-Protect does not scan encrypted messages, it continues to protect computers from viruses and security risks in attachments.

    Email attachments are frequently the culprits in virus attacks. To protect yourself from viruses transmitted through email attachments:

    • Don't open any attachment you were not expecting, even if it comes from a trusted source, such as a family member, co-worker, or friend.
    • If you do not know the sender of a message that includes an attachment, delete the message without reading it.
    • Do not open any attached file ending in .exe, .vbs, or .lnk.
    • Never open an attachment without verifying that it's virus free. To open an attachment, first save it to your hard drive and then scan it with antivirus software, such as Symantec Endpoint Protection.

    Incase of Suspicion, it is recommended to submit the Attachment to the Symantec Security Response Team on https://submit.symantec.com/essential

    OR

    Using Symantec Help (SymHelp) Tool, how do we Collect the Suspicious Files and Submit the same to Symantec Security Response Team

    http://www.symantec.com/connect/articles/using-sym...

    Hope that helps!!