Viruses still exists in Still infected

Hari Mohan's picture

What do you need to do to remove the viruses from the sytem. On server with version SEP 11.0.2 one of the client shows still infected 10 and security risks 1 how to manage this? The client system is slow. Virus files are in C:/Windows/system32/xx.tmp

shp's picture

If the virus is not removing

If the virus is not removing in normal mode run a full system scan in Safe mode on the client.
Once all the virus is cleaned and server receives new client logs status automatically changes. 

Regards,
Srinivas H.P.
HCL Infosystems Ltd

Acretian's picture

Disable system restore Get

Disable system restore
Get the latest rapid release from the link below
http://www.symantec.com/business/security_response/definitions/download/detail.jsp?gid=rr

Download the one which is related to SEP
Run the exe file and then restart the system in safe mode
Run a full system scan

Cycletech's picture

See  "The 5 Steps of Virus

See  "The 5 Steps of Virus Troubleshooting".

http://service1.symantec.com/SUPPORT/ent-security....

Best,
Thomas

Hari Mohan's picture

I have followed Acretian

I have followed Acretian downloaded rapid release and done as per instructions, but I was not able to restart the system in safe mode may be because of virus. So I have done full scan on normal mode. Now I am getting the viruses 12.tmp, msxm192z.dll. Now what to do?

AravindKM's picture

What is the action taken for

What is the action taken for that viruses by sep? Is it
cleaned ? Or in left alone?

You can also manually delete all files in the temp
directories.

 

Please don't forget to mark your thread solved with whatever answer helped you : )
Thanks & Regards
Aravind

Hari Mohan's picture

1) It says access denied,

1) It says access denied, when I tried to search they are not there.

2) At least can you tell me how to disable the popup which is not allowing the end user to work.

AravindKM's picture

For disabling user pop ups

For disabling user pop ups refer the below link

https://www-secure.symantec.com/connect/forums/annoying-pop-ups-still#comment-3138441
For more about action taken refer below link
http://service1.symantec.com/support/ent-security....
 

 

Please don't forget to mark your thread solved with whatever answer helped you : )
Thanks & Regards
Aravind

AravindKM's picture

If that file is currently not

If that file is currently not available means anti-virus is
able to remove that virus file.(Assuming you are having the necessary powers to
access it). So don't worry about that result.

 

Please don't forget to mark your thread solved with whatever answer helped you : )
Thanks & Regards
Aravind

Hari Mohan's picture

I have taken the help of

I have taken the help of CCleaner and removed the tmp files created and manually removed reader_s.exe and other files found as infecting. SEP should resolve these issues as updates/signatures. So that SEP user can aviod third party tools.

AravindKM's picture

If a file is affected with

If a file is affected with virus antivirus will not delete it if it can be cleaned..
You can refer the below doc for more info.
Explanation of Action field values in Symantec Client Security 3.1 and Symantec AntiVirus 10.1
 

Please don't forget to mark your thread solved with whatever answer helped you : )
Thanks & Regards
Aravind

drew at NF's picture

I deal with infected machines at least weekly

Symantec products are good at preventing infections, but not the best at detecting and removing existing infections.  This is the process I have been using recently (did this successfully on 9 machines at two clients just this week):

  1. Reboot the machine into Safe Mode with Networking, go to http://www.malwarebytes.org and download the latest free version, install it, update it, run quick scan, reboot into Normal Mode and run full scan.
  2. If you can't go to the site on the infected machine, download it on another machine to a thumb drive or network share, install it on the infected machine, update it, run quick scan, reboot into Normal Mode and run full scan.
  3. If you can't go into Safe Mode, try step one then step two above in Normal Mode.  If you can't do this, see the next step.
  4. If you can't go into Safe Mode, or install it, or run it, go the following sites on a non-infected machine and read the pinned posts down in the Computer Help section: http://www.malwarebytes.org/forums/, http://www.malwarebytes.org/forums/index.php?s=bd05435d4ae546e231695349c9708172&showforum=7, and my favorite post of all time http://www.malwarebytes.org/forums/index.php?showtopic=9573

Using the above procedures, I have been able to remove 100% of infections on about 98% of infected machines.  In fact, there have been only 2 machines that I have not been able to disinfect: one machine the hard drive was damaged or dying and I didn't yet know about the Malwarebytes forums on the other one.

Hope this helps!