Endpoint Protection

 View Only
Expand all | Collapse all

SEP on Xenapp Desktop?

  • 1.  SEP on Xenapp Desktop?

    Posted Oct 22, 2013 09:32 AM

    Last night, we were infected with the Cryptolocker virus.  The end user was on a thin client running Xenapp virtual desktop.   The local IT person says the machine had SEP on it.  If that is the case, why wouldn't SEP have blocked this virus? 



  • 2.  RE: SEP on Xenapp Desktop?

    Broadcom Employee
    Posted Oct 22, 2013 09:35 AM

    how did you get to know it's infected?

    can you submit the file to Symantec Security response.



  • 3.  RE: SEP on Xenapp Desktop?



  • 4.  RE: SEP on Xenapp Desktop?

    Posted Oct 22, 2013 09:44 AM

    Did you check the Risk log on the client? Was there anything there?

    Can you verify SEP was enabled and reporting in to the SEPM?

    What is the SEP version? Was components were installed?



  • 5.  RE: SEP on Xenapp Desktop?

    Posted Oct 22, 2013 09:52 AM

    I was not involved in troubleshooting the incident.  Information is still trickling in.  I will submit the file.  However in the interrim, can you tell me if it's possible that this system had SEP on it?  It's not in the console and local IT is being very sketchy on the details.  Is there a way I can find out for sure whether or not SEP was installed and if so when it was installed?

     

     



  • 6.  RE: SEP on Xenapp Desktop?

    Posted Oct 22, 2013 09:55 AM

    you can do a search for symantec endpoint protection in the registry or look for the install directory

    C:\Program Files (x86)\Symantec\Symantec Endpoint Protection



  • 7.  RE: SEP on Xenapp Desktop?

    Broadcom Employee
    Posted Oct 22, 2013 10:41 AM

    Hi,

    Thank you for posting in Symantec community.

    I would be glad to answer your query.

    Symantec detecting this threat as Trojan.Ransomcrypt.F. Additionally generic coverage of this threat using detection Trojan.Ransomcrypt!g3.

    Trojan.Ransomcrypt.F is a Trojan horse that encrypts files on the compromised computer and then prompts the user to purchase a password in order to decrypt them.

    Trojan.Ransomcrypt!g3 is a heuristic detection used to detect threats associated with the Trojan.Ransomcrypt.F family of threats

    To remove this threat refer this article:

    http://www.symantec.com/security_response/writeup.jsp?docid=2013-091122-3112-99&tabid=3

     



  • 8.  RE: SEP on Xenapp Desktop?

    Posted Oct 22, 2013 05:35 PM

    Does SEP 11.6 block Cryptolocker?



  • 9.  RE: SEP on Xenapp Desktop?

    Posted Oct 22, 2013 05:41 PM

    Yes. Defs for both 11.x and 12.1 will detect it. Same for the IPS.



  • 10.  RE: SEP on Xenapp Desktop?

    Posted Oct 22, 2013 05:54 PM

    We were just hit on a traditional desktop machine running 11.6. 



  • 11.  RE: SEP on Xenapp Desktop?

    Posted Oct 22, 2013 05:55 PM

    Also, I submitted the files that I referred to initially to the Security Response team this morning.  No word yet.



  • 12.  RE: SEP on Xenapp Desktop?

    Posted Oct 22, 2013 06:22 PM

    Could be a new variant which did not yet have a detection signature.



  • 13.  RE: SEP on Xenapp Desktop?

    Posted Oct 23, 2013 07:52 AM

    The authors of this threat have a very strong financial motive for crafting files that will evade AntiVirus programs.  There are new variants seen often.  Some details of recent changes can be found in the blog post mentioned earlier:

    Ransomcrypt: A Thriving Menace
    https://www-secure.symantec.com/connect/blogs/ransomcrypt-thriving-menace

    For more, also see these resources:

    Additional information about Ransomware threats
    http://www.symantec.com/docs/TECH211589

    Symantec is constantly updating our protection (AV and other components).  Definitely backup all important data regularly, keep your AV definitions up-to-date, and deploy the IPS component of SEP if you are not already using it!

    Also note: SEP 11.x will reach End-of-Support-Life as of January 5, 2014.   After any outbreaks are contained, migrate to SEP 12.1 ASAP.

    FAQ: Upgrading Symantec Endpoint Protection 11.x to version 12.1.x
    Article URL http://www.symantec.com/docs/TECH207274  



  • 14.  RE: SEP on Xenapp Desktop?

    Posted Oct 30, 2013 12:56 PM

    This new article may be of interest to followers of this thread:

     

    Recovering Ransomlocked Files Using Built-In Windows Tools
    https://www-secure.symantec.com/connect/articles/recovering-ransomlocked-files-using-built-windows-tools