Endpoint Protection

 View Only
  • 1.  Removal of WannaCry using Symantec

    Posted Jan 24, 2018 12:18 AM

    Recently we had a few instances of the WannaCry ransomeware in our environment. My understanding is that it was a new variant and we have yet to be able to determine if running a scan with Symantec will remove the infection, we have determined using Malwarebytes will remove this infection and I found 2 previous articles that leads me to believe the general assumption is that it is possible located here. 

    https://support.symantec.com/en_US/article.HOWTO124710.html

    https://www.symantec.com/security_response/writeup.jsp?docid=2017-051310-3522-99&tabid=3

    My primary question now is how would I go about determining if this would be the case with the new variant we've seen? I know if I were to have the hash I'd be able to run it through virustotals to determine if it is detected however I'm unsure if this confirms a scan would remove it. If anyone could fill me in on how to determine if scanning will remove a specific infection that would be great. Thanks.



  • 2.  RE: Removal of WannaCry using Symantec

    Posted Jan 24, 2018 12:07 PM

    If you have a sample then upload it to Symantec for review:

    http://www.symantec.com/docs/TECH102419

    If you ran a full scan with the latest content and it went undetected then there wasn't a signature to match it.