Endpoint Protection

 View Only
Expand all | Collapse all

Our email server detected virus

Migration User

Migration UserApr 01, 2014 01:15 AM

Migration User

Migration UserApr 01, 2014 11:43 PM

Migration User

Migration UserApr 02, 2014 05:05 AM

Migration User

Migration UserApr 02, 2014 06:24 AM

Migration User

Migration UserApr 02, 2014 09:07 PM

Migration User

Migration UserApr 02, 2014 10:06 PM

Migration User

Migration UserApr 03, 2014 01:54 AM

Migration User

Migration UserApr 03, 2014 01:56 AM

Migration User

Migration UserApr 07, 2014 03:12 AM

Migration User

Migration UserApr 07, 2014 03:49 AM

Migration User

Migration UserApr 07, 2014 04:00 AM

Migration User

Migration UserApr 07, 2014 05:13 AM

Migration User

Migration UserApr 08, 2014 06:15 AM

Migration User

Migration UserApr 09, 2014 05:12 AM

Migration User

Migration UserApr 10, 2014 06:03 AM

Migration User

Migration UserApr 24, 2014 03:46 AM

ℬrίαη

ℬrίαηApr 25, 2014 06:36 AM

Migration User

Migration UserApr 25, 2014 11:50 AM

Migration User

Migration UserApr 25, 2014 11:56 AM

  • 1.  Our email server detected virus

    Posted Apr 01, 2014 12:02 AM

    Hello,

    Please see attached file, the Symantec always pop-up detected virus, I used Symantec full scan and NOD32 online scan still cannot found, what I can to do for this issue ?

    Thanks.



  • 2.  RE: Our email server detected virus

    Posted Apr 01, 2014 12:14 AM
    Do not attach virus ... You need to submit the file to Symantec for further analysis


  • 3.  RE: Our email server detected virus

    Posted Apr 01, 2014 12:14 AM

    It's know issue.

    You can upgrade latest SEP 12.1.4.

    DWH***.tmp files are detected in the user profile temp directory

    http://www.symantec.com/docs/TECH92399

    When new virus definitions are in place and the quarantine is being scanned, a DWH file is created and detected by Auto-Protect

    http://www.symantec.com/docs/TECH102953



  • 4.  RE: Our email server detected virus

    Broadcom Employee
    Posted Apr 01, 2014 12:26 AM

    the screenshot has detections.

    the file is located under temp folder, can you delete the file if its not required.

    Also run Symhelp for load point diagnostics.

     

     



  • 5.  RE: Our email server detected virus

    Posted Apr 01, 2014 01:15 AM

    Hello,

    How can I exculde this path ?



  • 6.  RE: Our email server detected virus

    Posted Apr 01, 2014 01:36 AM

    See

    When new virus definitions are in place and the quarantine is being scanned, a DWH file is created and detected by Auto-Protect

    Article:TECH102953 | Created: 2007-01-19 | Updated: 2013-04-22 | Article URL http://www.symantec.com/docs/TECH102953

    DWH***.tmp files are detected in the user profile temp directory.

    Article:TECH92399 | Created: 2009-01-16 | Updated: 2012-04-27 | Article URL http://www.symantec.com/docs/TECH92399


  • 7.  RE: Our email server detected virus

    Broadcom Employee
    Posted Apr 01, 2014 01:36 AM

    do not exclude the temp folder, delete the files.

     



  • 8.  RE: Our email server detected virus

    Broadcom Employee
    Posted Apr 01, 2014 08:12 AM

    Hi,

    Backdoor.Trojan is a detection name used by Symantec to identify malicious software programs that share the primary functionality of enabling a remote attacker to have access to or send commands to a compromised computer.

    As the name suggests, these threats are used to provide a covert channel through which a remote attacker can access and control a computer. The Trojans vary in sophistication, ranging from those that only allow for limited functions to be performed to those that allow almost any action to be carried out, thus allowing the remote attacker to almost completely take over control of a computer.

    I would suggest to refer technical write up of Backdoor.Trojan.

    http://www.symantec.com/security_response/writeup.jsp?docid=2001-062614-1754-99&tabid=3



  • 9.  RE: Our email server detected virus
    Best Answer

    Posted Apr 01, 2014 08:14 AM

    Follow the steps here to remove.

    This is a known issue with SEP and these are false positives so to speak



  • 10.  RE: Our email server detected virus

    Posted Apr 01, 2014 11:15 PM
      |   view attached

    Hello

    I can't see  Quarantine in our SEP 11, please see attached image.

     

    Thanks



  • 11.  RE: Our email server detected virus

    Posted Apr 01, 2014 11:43 PM

    You can do this on server side not sep client.



  • 12.  RE: Our email server detected virus

    Posted Apr 02, 2014 02:16 AM

    Yes, found it, but still detecting the  Quarantine .



  • 13.  RE: Our email server detected virus

    Posted Apr 02, 2014 05:02 AM

    Can I delete the C:\Users\Administrator\AppData\Local\Temp\2\notes2AE250 folder ?



  • 14.  RE: Our email server detected virus

    Posted Apr 02, 2014 05:05 AM

    And can I exculde this path ?



  • 15.  RE: Our email server detected virus

    Posted Apr 02, 2014 06:24 AM

    You can't exclude this path



  • 16.  RE: Our email server detected virus

    Posted Apr 02, 2014 09:07 PM

    Hello all,

    What I can to do now ?

    Thanks



  • 17.  RE: Our email server detected virus

    Posted Apr 02, 2014 09:41 PM

    Did you follow the steps for deleting the quarantine I posted above?



  • 18.  RE: Our email server detected virus

    Posted Apr 02, 2014 10:06 PM

    I have done Solution part, but it won't work.


     



  • 19.  RE: Our email server detected virus

    Posted Apr 02, 2014 10:11 PM

    meaning it won't delete? is an error being thrown?



  • 20.  RE: Our email server detected virus

    Posted Apr 03, 2014 01:54 AM

    Yes

    no error



  • 21.  RE: Our email server detected virus

    Posted Apr 03, 2014 01:56 AM

    Did you try to disable tamper protection



  • 22.  RE: Our email server detected virus

    Posted Apr 03, 2014 09:01 AM

    We are using SEP 11.x, tamper protection is on SEP 12.x?



  • 23.  RE: Our email server detected virus

    Posted Apr 03, 2014 09:21 AM

    In SEPM 12.x tamper protection default on but SEPM 11.x you can enable below way.

    To enable or disable Tamper Protection:

    1. In the main window, in the sidebar, click Change Settings.
    2. Beside "Client Management", click Configure Settings.
    3. On the "Tamper Protection tab", check or uncheck Protect Symantec security software from being tampered with or shut down.
    4. Click OK.




    http://www.symantec.com/business/support/index?page=content&id=TECH102688



  • 24.  RE: Our email server detected virus

    Posted Apr 04, 2014 04:08 AM

    Hello,

    I can't see the "Tamper Protection tab" in "Client Management" > Configure Settings (SEP version is 11.0)

    Thanks



  • 25.  RE: Our email server detected virus

    Posted Apr 07, 2014 03:12 AM

    Anyone can help ?

     

    Thanks



  • 26.  RE: Our email server detected virus

    Posted Apr 07, 2014 03:49 AM

    Have you not seen this setting ?

    Tamper.JPG



  • 27.  RE: Our email server detected virus

    Posted Apr 07, 2014 04:00 AM

    Are you using SEP ?



  • 28.  RE: Our email server detected virus



  • 29.  RE: Our email server detected virus

    Posted Apr 07, 2014 05:13 AM

    Found it, it is checked.



  • 30.  RE: Our email server detected virus

    Posted Apr 08, 2014 06:15 AM

    Hello,

    What I can do now ?

    Thanks



  • 31.  RE: Our email server detected virus

    Posted Apr 09, 2014 05:12 AM

    Anyone can help?



  • 32.  RE: Our email server detected virus

    Posted Apr 10, 2014 06:03 AM

    Hello all,

    No one cal help this issue ?



  • 33.  RE: Our email server detected virus

    Posted Apr 10, 2014 06:26 AM

    You can uncheck that setting and try to remove logs



  • 34.  RE: Our email server detected virus

    Posted Apr 24, 2014 03:46 AM

    The problem fixed, thanks.



  • 35.  RE: Our email server detected virus
    Best Answer

    Posted Apr 24, 2014 04:04 AM

    Please update your thread (Mark as Solution).If multiple post help you please select "Request split solution" option.



  • 36.  RE: Our email server detected virus

    Posted Apr 24, 2014 11:10 PM

    Hi,

    This is not a right solution please update which comments best help you..



  • 37.  RE: Our email server detected virus

    Posted Apr 25, 2014 06:36 AM

    The solution needs to be marked here please



  • 38.  RE: Our email server detected virus

    Posted Apr 25, 2014 11:50 AM

    where



  • 39.  RE: Our email server detected virus

    Posted Apr 25, 2014 11:55 AM

    Once you unmark the current selection, you will then have the ability to mark whichever ones helped.



  • 40.  RE: Our email server detected virus

    Posted Apr 25, 2014 11:56 AM

    You can select which comments best help you