Endpoint Protection

 View Only
  • 1.  Messages being brodcasted from server

    Posted Jun 01, 2012 12:58 AM

    HI Team,

    In the network we are getting a frequent attacks same viruses again and again. When we scan particular server, in risk logs the same viruses are found to be cleaned, quarantined and log only. We can't scan servers at multiple times. Please provide us solution for removing these viruses permanently.. Below table shows major viruses files.
     
    Filename                 Risk
    setup50045.fon     Trojan.Gen
    setup50045.lnk     Bloodhound.Exploit.343
    myporno.avi.lnk     W32.SillyFDC.BDP!lnk
    pornmovs.lnk     
    DWH27D9.tmp     
     



  • 2.  RE: Messages being brodcasted from server

    Posted Jun 01, 2012 01:05 AM

    Hi Check this forums.

    https://www-secure.symantec.com/connect/forums/block-network-client-when-any-virus-attack-do-not-broadcast-virus-network#comment-6959581

    SEPM is not a Protection features. Its a management utility. So it's not possible with even SNAC.

    Any features is included in the SEP for protection.

    For protection against any type of exploit; customer should have NTP & IPS feature installed.

    Question - Let Suppose one client is infected from virus and SEP client detect it due to some reasons its do not delete and broadcast that virus on network so i want block the network of that client from broadcasting through SEPM can its possible..??

    --> The best way is to isolate the computer from the network to ensure that the threat is not spreading/infecting the other computers on the network 

    If you know the threat characteristic and it's infection vectors you may apply firewall rules/Implement best practices to block certain ports involved, disabling auto play,disabling shares etc.

     

    One other way is to move the affected client to a temp group and implement high security policy... like allowing only required ports and protocols, and with ADC policy to prevent infection through Autorun.inf, network scanning enabled, Bloodhound set to high level, etc.,

    With all being said, the best way is to isolate the computer from the network and ensure complete remedidation before connecting it back to the network



  • 3.  RE: Messages being brodcasted from server

    Posted Jun 01, 2012 02:06 AM
      |   view attached

    HI Ashish,

    Useful article. Thank you for the information

    Can u check attached file give me suggestion.

    Attachment(s)

    zip
    Pivotal Servers.zip   810 KB 1 version


  • 4.  RE: Messages being brodcasted from server

    Trusted Advisor
    Posted Jun 01, 2012 02:38 AM

    Hello,

    It seems there are lot .lnk files being detected.

    W32.SillyFDC.BDP!lnk is a detection for .lnk files created by the W32.SillyFDC.BDP worm. 

    Here is the Plan of Action - 

    1) Make sure all your Client machines are updated with all MS Security Patches and Latest Service Packs.

    2) Make sure all the machines are Running the Latest Patches.

    3)  Create a block rule in ADC for .lnk, and .fon

    You could also download this ADC Rule from here. Once imported to the SEPM, Edit the rule and add .fon extension to the same- 

    http://www.symantec.com/security_response/securityupdates/list.jsp?fid=adc

    Hope that helps!!



  • 5.  RE: Messages being brodcasted from server

    Posted Jun 01, 2012 03:58 AM

    Identify the risk source, also your server must have some kind of open share... please recheck



  • 6.  RE: Messages being brodcasted from server

    Posted Jun 01, 2012 07:34 AM

    Hi Team,

    which symantec protection technologices are installed on SERVER .

    1>Antivirus & Antispayware

    2>PTP

    3>NTP

    which one installed on Server & which one are not installed.why not installed technologies with resons.

    can give me decX.

     

     



  • 7.  RE: Messages being brodcasted from server

    Posted Jun 05, 2012 02:01 AM

    Thanks

    Ashish & Mithun you are usefull articale for my issue.