Blocking vundo, instead of reacting

daishi5

Golden Member
Feb 17, 2005
1,196
0
76
We keep having new infections of this virus all, and our corporate anti-virus never seems to stop it. We are running Symantec Corporate edition 10, and the original Vundo is over 4 years old. Is there any way to stop this from infecting machines instead of formatting them after they are infected?
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
If at all possible, switch your users to low-rights user accounts, instead of Administrator or Power User accounts. And if you do that, you might as well look at Software Restriction Policy to go with it.
 

daishi5

Golden Member
Feb 17, 2005
1,196
0
76
Strange coincidence, I am working on SRPs for another set of workstations right now. That may be a long term solution to look at.
 

dfnkt

Senior member
May 3, 2006
434
0
76
We have SEP11 and it's catching Vundo fine... SEP seems to be fast and efficient so far as well as a breeze to admin since we have it tied into our Symantec Management Platform. Both the virus signature and the vulnerability blocking will catch vundo.