Endpoint Protection

 View Only
  • 1.  Virus Change Host File

    Posted Jul 03, 2010 03:25 AM

    Hi Everyone,

    Recently, I have the users that infected with virus which causing the computer start up with 15 minutes, computer slowness, host file change to system file and everytime open internet explorer will open 30 other websites. Using SEP11 scan nothing. In safe mode, cannot remove the host file also. In registry, startup and system process, there are no any kind of suspected process/file.

    Please advise on this.


  • 2.  RE: Virus Change Host File

    Posted Jul 03, 2010 03:37 AM


  • 3.  RE: Virus Change Host File

    Posted Jul 03, 2010 03:38 AM
    Download and run support tool and do a load point analysis......


  • 4.  RE: Virus Change Host File

    Posted Jul 03, 2010 03:46 AM
    Today is the offday I need Monday just only can get check again at the registry. However for the support tool, I have download the tool already but base on load point result, how can I further know which is the suspected file that I can submit to the Symantec for checking? Please advise.


  • 5.  RE: Virus Change Host File

    Posted Jul 03, 2010 04:02 AM
    Hello,
    You can upload your files in this site. https://submit.symantec.com/websubmit/retail.cgi

    By the way please check startup config with Sysinternals autoruns. http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx

    Best Regards.
    Fatih


  • 6.  RE: Virus Change Host File



  • 7.  RE: Virus Change Host File

    Posted Jul 03, 2010 04:08 AM
    Try the tool fist.
    If you are still confused log a call with symantec
     How to Contact Customer Care and Technical Support



  • 8.  RE: Virus Change Host File

    Posted Jul 03, 2010 04:11 AM
    Hi,

    Thank you for everyone advise. I will log a case to Symantec and run the SEP Support Tool to get the data and send for analysis. Meanwhile, still have anything that I can do for preventation or further checknig to get more information or detecting the virus,


  • 9.  RE: Virus Change Host File

    Posted Jul 03, 2010 04:22 AM
    Have a look at this thread.You will get a lot of informations
    SEP secret sauce for better protection



  • 10.  RE: Virus Change Host File

    Posted Jul 03, 2010 05:17 AM

    Use application & device policy to block modification to registry and host file.


  • 11.  RE: Virus Change Host File

    Posted Jul 03, 2010 05:53 AM
    First what you need to do is replace the host file from a working machine.
     Delete all Temporary Internet files from the browser .

    Navigate to HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Browser Helper Objects   and delete all subfolders and then reboot the machine.

     

     See if that makes any diffrence or not