Endpoint Protection

 View Only
  • 1.  VirusAlert

    Posted Mar 04, 2014 10:39 PM

    Hi

    We have SEP 12.1 and one of clinet we getting following balloon notification about backdoor Houdini, is this machine infected with this virus and in quorantine we do not see any entry, how we can remove and confirm that this virus is not in client

    aaa.png

     

    Thanks

     



  • 2.  RE: VirusAlert



  • 3.  RE: VirusAlert

    Posted Mar 05, 2014 12:16 AM

    Check the article

    How to collect and submit to Symantec Security Response suspicious files found by the SymHelp utility

    http://www.symantec.com/docs/TECH203027

    Using Symantec Help (SymHelp) Tool, how do we Collect the Suspicious Files and Submit the same to Symantec Security Response Team.

    https://www-secure.symantec.com/connect/articles/using-symantec-help-symhelp-tool-how-do-we-collect-suspicious-files-and-submit-same-symante

     



  • 4.  RE: VirusAlert

    Posted Mar 05, 2014 12:53 AM

    You can scan the system for Virus with SymHelp Utility and clean it.

    How to run Symantec Power Eraser with the SymHelp utility

    Article:TECH203683  |  Created: 2013-03-08  |  Updated: 2013-12-17  |  Article URL http://www.symantec.com/docs/TECH203683
     

     



  • 5.  RE: VirusAlert

    Posted Mar 05, 2014 02:02 AM

    Hi Golani,

    Take these notifications seriously.  Examine the IPS logs to see which .exe is responsible for the traffic: it is most likely wscript.exe, which will be running a .vbs file somewhere on the system.  Locate that and submit it to Security Response for examination!

    Here’s an excellent illustrated guide, with video:

    How to Run Load Point Analysis for Symantec Support

    Article URL http://www.symantec.com/docs/TECH203028

    All the best,

    Mick



  • 6.  RE: VirusAlert

    Posted Mar 05, 2014 08:48 AM

    Post your security log here if you need help reviewing.



  • 7.  RE: VirusAlert

    Posted Apr 30, 2014 03:40 AM

    Do you need more help here ?

    If not please update your thread (Mark as Solution).If multiple post help you please select "Request split solution" option.