Endpoint Protection

 View Only
  • 1.  System Infacted Virus

    Posted Nov 27, 2012 11:53 PM
      |   view attached

    HI,

    Our lot of system are infacted virus problem.

    Virus name :W32.Downadup

    Check attach picture



  • 2.  RE: System Infacted Virus
    Best Answer

    Posted Nov 27, 2012 11:56 PM

    HI,

    Check same thread

    https://www-secure.symantec.com/connect/forums/virus-information

    https://www-secure.symantec.com/connect/forums/w32downadupb-pop-ups

     

    Check this comments

    Mithun Sanghavi Symantec Employee Technical Support Accredited

    Hello,

    Same issue in the current Thread: https://www-secure.symantec.com/connect/forums/virus-information

    Work on the Plan of Action as given below for a 100% result.

    Plan of Action:

    1) Make sure ALL Computers are installed with Symantec EP with latest / updated with virus defintions and

    2) Install MS08-67 patch download [KB 958644] on ALL computer.

    http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx

    3) Install ALL Latest Microsoft Secuirty Patches / Sevice Packs on ALL machines

    4) Disable Auto play with GPO

    http://support.microsoft.com/kb/953252

    5) Disable Scheduled Tasks with GPO

    http://support.microsoft.com/kb/310208

    6) Enable Security Auditing with GPO

    http://support.microsoft.com/kb/300549

    7) Scan ALL the machines...

    NOTE: *ALL means ALL client machines and server machines (make sure you don't miss any machine)

    Inaddition to this, please check the Article provided below and work upon the same.

    1) Best Practice for Downadup.B and Additional information on the same.

    https://www-secure.symantec.com/connect/articles/best-practice-downadupb-and-additional-information-same

    2) Simple steps to protect yourself from the Conficker Worm

    http://www.symantec.com/docs/TECH93179

     



  • 3.  RE: System Infacted Virus

    Broadcom Employee
    Posted Nov 28, 2012 12:10 AM

    important thing is to apply the MS patch to all the machines in the environment. Are you using the IPS feature of SEP on these machines?



  • 4.  RE: System Infacted Virus

    Posted Nov 28, 2012 12:49 AM

     

    Step 1 : Scan and remove W32.Downadup with this special tool

    1. Download the Downadup removal tool from http://download.precisesecurity.com/bd_rem_tool.zip and save it on your Desktop or any accessible location.

    This tool is available free. It can delete members of the Downadup family of Trojan. The tool is created with removal function; it cannot protect the computer from threats.

    2. Double click on downloaded file, chose "Extract all files..." from the File menu, and follow the wizard's instructions. You can use any other archiver, like WinZip. This will create a folder called bd_rem_tool.

    3. Double click on the file "bd_rem_tool_gui.exe" (or just "bd_rem_tool_gui"). Make sure that all files have been extracted from the zip archive, because all the contents are required for the removal tool to run. Follow the tool's instructions.

    4. If you have Restricted Access (not Admin) on Windows Vista and XP, right click the "bd_rem_tool_gui" program and choose "Run as Administrator". Enter the computer Administrator User name and Password when prompted. This will scan the computer for presence of W32.Downadup. Remove all detected threats.

    5. Reboot your computer when scanning is finished.

    Step 2 : Run a scan with your antivirus program

    1. Repeat the process of starting Windows in Safe Mode with Networking.
    2. Open your antivirus program and download the most recent update. This method ensures that your antivirus program can detect even newer variants of W32.Downadup.

    Updating your antivirus software is a one-click process. Please refer to your software manual for complete instructions.

    3. Once updating is finished, run a full system scan on the affected PC. After the scan, delete all infected items. If unable to clean or delete, better place the threat in quarantine.

    Step 3: Run another test with online virus scanner

    Another way to remove W32.Downadup without the need to install additional antivirus software is to perform a thorough scan with free online virus scanner. It can be found on websites of legitimate antivirus and security provider.

    1. Click the button below to proceed to the list of suggested Online Virus Scanner. Choose your desired provider. You can run each scan individually, one at a time, to ensure that all threats will be removed from the computer. This may require plug-ins, add-on or Activex object, please install if you want to proceed with scan.

    2. After completing the necessary download, your system is now ready to scan and remove W32.Downadup and other kinds of threats.
    3. Select an option in which you can thoroughly scan the computer to make sure that it will find and delete entirely all infections not detected on previous scan.
    4. Remove or delete all detected items.
    5. When scanning is finished, you may now restart the computer in normal mode.

    reference: http://www.precisesecurity.com/worms/w32downadupe



  • 5.  RE: System Infacted Virus

    Posted Nov 28, 2012 05:22 AM

    HI,

    Also Check this

    Best Practice for Downadup.B and Additional information on the same.

    https://www-secure.symantec.com/connect/articles/best-practice-downadupb-and-additional-information-same



  • 6.  RE: System Infacted Virus

    Posted Nov 28, 2012 05:42 AM

    An additional link that will be of interest:

    The Downadup Codex, Edition 2.0
    https://www-secure.symantec.com/connect/blogs/downadup-codex-edition-20



  • 7.  RE: System Infacted Virus

    Posted Nov 28, 2012 10:50 PM

    Hi Irk_Mar,

    All system must have NTP as well as PTP component and Remove all sharing folder access where you are facing Downadup.B virus.

    For more help go through the below artical.

    https://www-secure.symantec.com/connect/articles/best-practice-downadupb-and-additional-information-same#comment-8019741



  • 8.  RE: System Infacted Virus

    Posted Nov 29, 2012 12:00 AM

    @ikr_mak did this solve your issue ?



  • 9.  RE: System Infacted Virus

    Posted Dec 03, 2012 10:38 PM

    Thanks :)