Endpoint Protection Small Business Edition

 View Only
  • 1.  Most infected virus and its protection/resolution

    Posted Apr 14, 2013 01:55 PM

    Dear All,

    Can anyone give me some details based on his/her exp. about Most infected virus and its protection/resolution. I wanted to know what are commonly top 10 virus issues faced in any organization even this is dynamic and cant be specific for specific org but still I would like to get some commonly infected virus/worms/trojans and its proactive resolutions.



  • 2.  RE: Most infected virus and its protection/resolution

    Posted Apr 14, 2013 07:59 PM

    The biggest I've dealt with in the past is Sality and TDSS. Sality usually comes from USB devices so we use an ADC policy to lockdown the USB drives so that they're read-only. This has stopped the threat significantly. We also use some scripting to kick off a process that cleans it remotely.

    Don't really have a top ten. The others that we deal with are usually just one off viruses and we get the PC removed from the network and cleaned before putting it back on.



  • 3.  RE: Most infected virus and its protection/resolution
    Best Answer

    Trusted Advisor
    Posted Apr 15, 2013 10:43 AM
      |   view attached

    Hello,

    You may like to check the "Internet Security Threat Report" from:

    http://www.symantec.com/threatreport/?inid=us_sr_flyout_publications_istr

    Symantec Intelligence Report: February 2013

    http://www.symanteccloud.com/en/us/mlireport/SYMCINT_2013_02_February.pdf

    Also, check the BLOG, which speaks on :

    Top 5 Security Predictions for 2013 from Symantec

    https://www-secure.symantec.com/connect/blogs/top-5-security-predictions-2013-symantec-0

    and the Whitepaper (attached) on "Top Ten Web Threats And How to Eliminate Them"

     

    Currently, I find Trojan.FakeAv and W32.Changeup which you may be interested in:

    How to troubleshoot FakeAV if it is not detected

    http://www.symantec.com/docs/TECH157781

    How to clean up a W32.Changeup infection

    http://www.symantec.com/docs/TECH201560

    Turning up settings in SEP to deal with fakeav

    https://www-secure.symantec.com/connect/forums/tur...

    Hope that helps!!