W32.SillyFDC virus
Background:
Currently running Symantec AV 10.1.5.5002
I need assistance with interpreting or coming to a conclusion of where certain types of files are originating from.
We have workstations that are provided from a vendor with their custom WinXP w/SP3 image installed on the harddrive. These workstations are on their own separate subnet.and internet access has been blocked. After the machines are shipped to us we network them, join the windows domain server, install symantec from the network, and then we perform a Full scan of the workstation harddrives and we find the files below. The scan detects the W32.SillyFDC virus. Once thing to note is that we only detect this type of virus on the workstations provided from the vendor. The vendor has Symantec EP11 and they scan their image and nothing is flagged. We are trying to determine if these files are false positives or if our SAV client settings are set too agressively in detecting this particular virii.
Any information you provide would be greatly appreciated.
Virus Detected: w32.SillyFDC
Files Detected:
c:\windows\system32\odbcasvc.exe
c:\documents and settings\sbuser\local settings\temp\s.exe
c:\windows\system32\recycled\info.exe
d:\recycled\info.exe
c:\windows\uda.exe
Thanks in advance.
The silly virus was known to
The silly virus was known to spread through infected removable storage, aka thumb drives and the like.
There is an online portal, save yourself the long hold times. Create ticket online, then call in with ticket # in hand :-)
http://mysupport.symantec.com
"We backup data to restore, we don't backup data just to back it up."
Is it possible to get this
Is it possible to get this type of virus through a network share? Everyone claims no one uses a USB stick drive when setting up these workstations. Also, everyone's telling me that our virus detection level is too sensitive, and our heuristic scanning settings are set to use Bloodhound virus detection technology with default level of protection. Any thoughts?
Thanks again.
Would you like to reply?
Login or Register to post your comment.