Endpoint Protection

 View Only
  • 1.  w32.Gammima.AG

    Posted Oct 16, 2009 01:00 PM
      |   view attached
    Hello,
    Symantec has detected and cleaned the W32.Gammima.AG threat risk, and I have followed the steps to update the registry to remove the threat.

    Unfortunately, each time my computer restarts, the same threat is found and cleaned.  The Original Location is "Unavailable" so I don't know where the threat is coming from.  I have system restore disabled (with Windows XP Pro SP3) and it still happens every day.

    Does anyone know how to stop this from happening?

    Perhaps there is a legitimate program/macro which is running and detected as a security threat?

    Any suggestions would be much appreciated.



  • 2.  RE: w32.Gammima.AG

    Posted Oct 16, 2009 01:11 PM
    W32.Gammima.AG is usually bundled with a rootkit.  The rootkit is probably reinstalling itself as portions get removed.  You'll probably have to do an offline scan from a known good computer or boot CD to get rid of the whole thing.


  • 3.  RE: w32.Gammima.AG

    Posted Oct 16, 2009 01:23 PM
     One of the new RU5 features was a report that actually shows the virus location now.

    But a scan in safemode is a good start...  Then if warranted, one where as above suggested, taking the HDD out and scanning from another PC, or using a WinPE image with SEP installed, to scan from it.  The later is something everyone should have, and Symantec should bundle it in.


  • 4.  RE: w32.Gammima.AG
    Best Answer