1. Symantec/
  2. Security Response/
  3. Attack Signatures/
  4. System Infected: Don Bot Activity

System Infected: Don Bot Activity

Severity: High

This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.

Description

This signature detects communication from a compromised machine to its controlling server.

Additional Information

Symantec antivirus programs use Trojan horse as a generic detection when detecting many individual but varied Trojan horse programs for which specific definitions have not been created.

In these cases, a generic detection is used because it protects against many Trojans that share similar characteristics.

Affected

  • Windows 2000
  • Windows 95
  • Windows 98
  • Windows Me
  • Windows NT
  • Windows Server 2003
  • Windows XP

Response

The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.

1. Disable System Restore (Windows Me/XP).
2. Update the virus definitions.
3. Run a full system scan
  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube