Endpoint Protection Small Business Edition

 View Only
  • 1.  CRITICAL: NETWORK VIRUS DETECTED

    Posted Jul 25, 2015 10:18 AM

    Hello Experts

    I have Symantec Endpoint Protection Small Business Edition , i have got an virus message on my network computers which name is W32.Pykspa!gen1
    Malware , please suggest me what can do for delete this virus permanently our more then 100 Computer is infected from this virus , i have scan many time but nothing anything , user have show popup of virus in 15 min. plese give me fixing tips 

     

    Computer
    User
    IP Address

    Risk
    Risk Type

    Risk Count

    Date Time

    Group

    Action
    Source

    File / Entry

    Deb-PC
    Guest
    10.61.6.213

    W32.Pykspa!gen1
    Malware

    1

    07/25/2015 18:02:01

    My Company\Laptops and Desktops

    Cleaned by deletion
    Auto-Protect

    C:\Users\Public\Documents\Baidu\Common\I18N\I18N.pif

    Onva-PC
    Guest
    10.61.6.213

    W32.Pykspa!gen1
    Malware

    1

    07/25/2015 18:01:56

    My Company\Laptops and Desktops

    Cleaned by deletion
    Auto-Protect

    C:\Users\Public\Documents\Documents.exe

    Kom-PC
    Guest
    10.61.6.213

    W32.Pykspa!gen1
    Malware

    1

    07/25/2015 18:01:48

    My Company\Laptops and Desktops

    Cleaned by deletion
    Auto-Protect

    C:\Users\Public\Documents\Baidu\Common\Common.exe



  • 2.  RE: CRITICAL: NETWORK VIRUS DETECTED

    Posted Jul 27, 2015 09:21 AM
    Looks like SEP is deleting the risk. What's the concern?


  • 3.  RE: CRITICAL: NETWORK VIRUS DETECTED

    Broadcom Employee
    Posted Jul 27, 2015 09:22 AM

    Hi,

    As per action it's been cleaned by deletion. What' the file at given address?

    W32.Pykspa!gen1 is a heuristic detection used to detect threats associated with the W32.Pykspa.A, W32.Pykspa.D, W32.Pykspa.E, and W32.Pykspa.F families of threats.

    W32.Pykspa!gen1 - Removal

    http://www.symantec.com/security_response/writeup.jsp?docid=2010-122307-1602-99&tabid=3

     



  • 4.  RE: CRITICAL: NETWORK VIRUS DETECTED

    Posted Jul 27, 2015 09:17 PM

    The infection being detected is on a worm which propagates by some means (such as Autoplay feature of Windows and mapped drives). The worm is probably hiding on computer(s) that has no AV or on a shared drive and repeatedly spreading to the rest of the computers in the network. You need to find this source computer(s) and remove the infection to get rid of it. Please follow the best practice to stop the infection from propagating and take steps to find the source of the infection.

    Few best ways to stop/reduce the speed of propagation of the infection:

    1) Disable Windows Autoplay feature on all the computers in the network (I would suggest to keep it disabled forever and this would save the network from worms). On computer that are part of domain, this can be done through group policy. On computers that are part of workgroups that has to be done locally. 

    2) Password Protect Shared Drives (at least until the issue is resolved). DO this especially when you have customers/users who connects through VPN from outside your network.

    Identify the source of the Infection and removing the infection:

    1) Enable Risk Trace in SEPM (This needs the firewall component of the SEP client to be enabled, hope you have them enabled already). After enabling Risk Tracer, the SEPM would be able to find the sources in a few hours.

    2) Ensure that all the computers in the network has the AV software installed and that they have up-to-date virus definition. Comparing the list of computer in the network (domain and/or workgroup) with the list of machines reporting to SEPM to get a list of machine that are not reporting to SEPM. Take necessary steps to make them report to SEPM or ensure that an AV software is installed and up-to-date on them. If you have VPN users/customers, ensure that their computers have AV installed and are up-to-date.

    References:

    http://www.symantec.com/docs/TECH91705
    http://www.symantec.com/docs/TECH122466



  • 5.  RE: CRITICAL: NETWORK VIRUS DETECTED

    Posted Aug 06, 2015 09:57 AM

    Hi Sisin,

    Just checking to see if you have any update on this thread?

    I recommend ensuring that endpoints ar erunning scheuled or manual scans- Auto-Protect is hwat's detecting everything in your log.

    Many thanks!

    Mick



  • 6.  RE: CRITICAL: NETWORK VIRUS DETECTED

    Posted Aug 13, 2015 02:35 AM

    Hello Sisin,

    Is the issue resolved? Let us know if you need help.