Endpoint Protection

 View Only
Expand all | Collapse all

W32.Sality.AE Can't kill by Symantec endpoint

Migration User

Migration UserOct 21, 2010 06:34 AM

  • 1.  W32.Sality.AE Can't kill by Symantec endpoint

    Posted Oct 21, 2010 05:35 AM

    Hello,

    Today I found that our EXE file can't execute. after I check my server  I found that Symantec Endpoint alert this virus.

    W32.Sality.AE

    Symantec endpoint can quarantied but can't kill it on my system. it still generate virus on my server as below.

     

    Please anybody advise the way to clean it on our system.

    I see at symantec instruction on this link. but I don't have time to edit all registry to fix it on every server.

     

    http://securityresponse.symantec.com/security_response/writeup.jsp?docid=2008-042106-1847-99&tabid=3

     

    and I have tried rmsality.exe also. it don't work.

    Please help me.

    thank you.

     



  • 2.  RE: W32.Sality.AE Can't kill by Symantec endpoint

    Posted Oct 21, 2010 05:38 AM

    Update it with latest rapid release update then scan in safe mode...



  • 3.  RE: W32.Sality.AE Can't kill by Symantec endpoint

    Posted Oct 21, 2010 05:39 AM

    our server can't execute EXE now. Please help me. Safe mode is the best way? I can't stop server for scan 1-2 days



  • 4.  RE: W32.Sality.AE Can't kill by Symantec endpoint

    Broadcom Employee
    Posted Oct 21, 2010 05:40 AM

    update the client using the jdb, then scan the system in safe mode.



  • 5.  RE: W32.Sality.AE Can't kill by Symantec endpoint

    Posted Oct 21, 2010 05:43 AM

    Scan may take few hours.Before doing this assure that you are updating with latest rapid release updates.Then scan in safe mode.In safe mode virus cannot act much so removal will be  easier....



  • 6.  RE: W32.Sality.AE Can't kill by Symantec endpoint

    Posted Oct 21, 2010 06:23 AM


  • 7.  RE: W32.Sality.AE Can't kill by Symantec endpoint

    Posted Oct 21, 2010 06:34 AM

    My Definitions update is lasted version already.



  • 8.  RE: W32.Sality.AE Can't kill by Symantec endpoint

    Broadcom Employee
    Posted Oct 21, 2010 06:36 AM

    scan the system in safe mode. it shows pending analysis, usually it requires a reboot to take the affect.

    Disable the system volume restore if it is enabled before the scan.



  • 9.  RE: W32.Sality.AE Can't kill by Symantec endpoint

    Posted Oct 21, 2010 07:31 AM

    I think windows 2003 disable system restore by default. then I will restart and scan full again because my server can't down long time.



  • 10.  RE: W32.Sality.AE Can't kill by Symantec endpoint

    Broadcom Employee
    Posted Oct 21, 2010 07:34 AM

    ok, its always good to start the scan in safe mode for better handling of threats..



  • 11.  RE: W32.Sality.AE Can't kill by Symantec endpoint

    Posted Oct 21, 2010 09:11 AM

    NO, I mean I can scan after boot and user still working to this server.



  • 12.  RE: W32.Sality.AE Can't kill by Symantec endpoint

    Posted Oct 21, 2010 04:12 PM

    ...to reset the ability to run exe files.

    Tool to reset shell\open\command registry keys
    http://www.symantec.com/security_response/writeup.jsp?docid=2004-050614-0532-99

    sandra



  • 13.  RE: W32.Sality.AE Can't kill by Symantec endpoint

    Posted Oct 25, 2010 11:21 PM

    Hello,

     

    At the moment, I can run EXE file but 3-4 hours it will hang again. I think there are some virus on my server but I can't clean it. I am scanning it on my server again. user still accessing to working.



  • 14.  RE: W32.Sality.AE Can't kill by Symantec endpoint

    Broadcom Employee
    Posted Oct 25, 2010 11:34 PM

    i still think scanning in safe mode would be quicker as windows processs will not be active.



  • 15.  RE: W32.Sality.AE Can't kill by Symantec endpoint

    Posted Oct 25, 2010 11:47 PM

    definetly scanning in safe mode will be more effective to clean the threats as in normal mode the processes would be locked by application/OS.



  • 16.  RE: W32.Sality.AE Can't kill by Symantec endpoint

    Posted Oct 26, 2010 03:22 AM

    Hello Theseng99

     

    As per the ScreenShot which u have posted, it shows that Pending Analysis Below Action Taken. It means Auto-Protect has not yet received the results from the Side Effect Repair Engine. After the Side Effect Repair Engine finishes the scan, the Action column of the Auto-Protect Results window shows the action that was taken.

    For Details Pls, go through below Link

    http://service1.symantec.com/SUPPORT/ent-security.nsf/ppfdocs/2005092614484748?Open&dtype=corp&src=&seg=&om=1&om_out=prod

    And also try Rebooting the Server.



  • 17.  RE: W32.Sality.AE Can't kill by Symantec endpoint

    Posted Oct 26, 2010 04:21 AM

    Hello,

     

    I found root cause of virus. It is on NAS Drive. it's buffalo share drive and connect via LAN Cable. As below Drive U: is NAS and try to generate virus when people try to access it. (file U:\rbuix.exe is virus that is generated)

     

     

    NAS drive can't logon to safe mode How can we do? I try to scan map drive U: from our server.



  • 18.  RE: W32.Sality.AE Can't kill by Symantec endpoint

    Posted Oct 26, 2010 09:34 AM

    I would recommend that you use Symantec Endpoint Recovery Tool and update it with the latest definitions.  You can find the recovery tool on file connect. Here is the a KB that explains how to update the boot CD.

     

    Install latest defs for the recovery tool:

    http://www.symantec.com/business/support/index?page=content&id=TECH131732&locale=en_US



  • 19.  RE: W32.Sality.AE Can't kill by Symantec endpoint

    Posted Oct 26, 2010 02:04 PM

    Is there an autorun.inf file on the NAS device?  Disable autorun if you haven't already.

    sandra