Screenshot: Once you see data in C:\windows\system32\dns\dns.log you know that it's working. As that request goes over the UTM, the APT system is picking it up and flagging your DC as the source.

Regardless of the virus' behavior, the primary objective of computer hackers who program viruses such as like C2/Generic-A is to delete, destroy, or steal data.

Look for the client who try to resolve the domain you get from ATP log, and check the log in C:\windows\system32\dns\dns.log, Perform Antivirus Full Scan Monitor the ATP traffic log for few days.

The DNS is our domain controller.

FabianFranken 0 21 Mar 2016 7:19 AM Yep, here too (Germany).

Click the Debug Logging tab.

Do share with me if you find any other ways or resolutions.

I will cross check with the web filte logs, thank you for the suggestion. We have blocked Russia.Is this a Sophos UTM?

We need to find that client, you can log DNS requests on your DC and find the IP issuing the request. For me it seems that they are trying to resolve these domain names at all available IP's, like scanning for open resolvers and since the domain is in ATP there's an

By now, your computer should be completely free of C2/Generic-A infection.

Details about the alert: Threat name….: C2/Generic-A Details……..: http://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/C2~Generic-A.aspx Time………..: 2015-04-30 16:27:26 Traffic blocked: yes Source IP address or host: When pulling up the web filter log, the activity that

Some viruses can keep adding shortcuts of other programs on your desktop, while others can start running unwanted programs, also referred as “PUP” (Potentially Unwanted Programs) to intentionally slow down your SUBSCRIBE Message Author Comment by:Quintin Smith2016-05-03 Comment Utility Permalink(# a41576881) Thanks. You can learn more about Viruses here. Connect with top rated Experts 10 Experts available now in Live!

Your internal network is not exploited and the ATP has done it's job in protecting you.

To achieve a Gold competency level, Solvusoft goes through extensive independent analysis that looks for, amongst other qualities, a high level of software expertise, a successful customer service track record, and Although it has been removed from your computer, it is equally important that you clean your Windows Registry of any malicious entries created by C2/Generic-A. Sophos Central Synchronized security management. Seems to go to all our public interfaces.

Hi everyone, looks like I have a similar situation to a few people.

A client is sending the DNS request to your DC,2.

Started Sunday morning, all chinese IPs:2016:03:20-03:46:53 wall-1 afcd[31331]: id="2022" severity="warn" sys="SecureNet" sub="packetfilter" name="Packet dropped (ATP)" srcip="" dstip="" fwrule="63001" proto="17" threatname="C2/Generic-A" status="1" host="YwTB6532e13e.app.anmorencai.com" url="-" action="drop" 2016:03:20-03:47:51 wall-1 afcd[31331]: id="2022" severity="warn" sys="SecureNet" sub="packetfilter"