Endpoint Protection

 View Only
  • 1.  WindowsRecovery Malware fix via Application Fingerprinting

    Posted May 04, 2011 09:19 AM

    My clients have been repeatedly hit with this, and I was wondering, because the signature file changes regularly on this, if there was a way to effectively block this with SEP, maybe via the application fingerprinting method? 

     



  • 2.  RE: WindowsRecovery Malware fix via Application Fingerprinting

    Broadcom Employee
    Posted May 04, 2011 09:57 AM

    you can use the application and device control policy for stopping the application from executing.



  • 3.  RE: WindowsRecovery Malware fix via Application Fingerprinting
    Best Answer

    Trusted Advisor
    Posted May 04, 2011 10:56 AM

    Hello,

    I believe, this is what you are looking for.

     

    How to use Application and Device Control to limit the spread of a threat.
     
     
     
    Since it's a Malware, leave it to the Symantec Endpoint Protection v.11.

     

    This malware is mere a FakeAV.

    It is very important you to carry this software on all machines with latest version of definitions.

     

    There are number of Articles which suggests wide area of Prevention ways and Resolution steps.

    Here are the few of the article which you can go through to get your questions answered.

    1) How to troubleshoot FakeAV if it is not detected

     
    2) Using Symantec Support Tool, how do we Collect the Suspicious Files and Submit the same to Symantec Security Response Team. 
     
     
    3) Containing An Outbreak: How to clean your network after an incident

    http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/containing_an_outbreak.pdf

    4) Hardening Symantec Endpoint Protection with an Application and Device Control Policy to increase security
     
     
    Also, check these which may help as well.
     
    How to block known virus executables that run from %UserProfile% using Application and Device Control
     
     
     
    Hope these Excellent Articles help you the best!!!


  • 4.  RE: WindowsRecovery Malware fix via Application Fingerprinting

    Posted May 04, 2011 12:35 PM

    FYI, The latest Rapid Release definition (Sequence #122802) added a modified signature for Trojan.FakeAV.

     

    http://www.symantec.com/business/security_response/definitions/download/detail.jsp?gid=rr