Endpoint Protection

 View Only
Expand all | Collapse all

About SEP 11.0.5 RU5 Vs. VBS.Worm Autorun. a & VBS.Worm Autorun. r (not false positive)

  • 1.  About SEP 11.0.5 RU5 Vs. VBS.Worm Autorun. a & VBS.Worm Autorun. r (not false positive)

    Posted Mar 22, 2010 11:15 PM
    To Symantec Support

    about VBS.Worm.Autorun.A & Vbs.Worm.Autorun.r (not false positive)


    i found  vbs worm known as VBS.Worm.Autorun.A & Vbs.Worm.Autorun.r
    detect by F-secure, Kaspersky, BitDifender, Microsoft Malware Protection.

    More than 5 year malware  spread on internet,  except (not detect) by major symantec product
    NIS, NAV, NAVCE, SEP
    Norton Antibot only detect browser Hijack but after All System damage by this malware

    i  try this virus with manual examine, worm contain serious paylod (not false positive)

    Execute  malware on win xp 0r 2003 server. than restart computer
    -Malware create autorun inf on root derectory
    -Block access to explorer or my computer.
    -Damage all MSoffice Document

    after 2 year ago  we send virus sample to url http://www.symantec.com/business/security_response/submitsamples.jsp
    and i try resend virus sample to http://www.symantec.com/business/security_response/submitsamples.jsp
    today.

    no respond & major symantec product NIS, NAVCE, SEP just blind
    Virus definition not change. cant you tell Why ?







  • 2.  RE: About SEP 11.0.5 RU5 Vs. VBS.Worm Autorun. a & VBS.Worm Autorun. r (not false positive)

    Posted Mar 23, 2010 03:16 AM
    Hi Abdi Cinta,

    If you have used the Retail portal for making submissiosn, please know that it is not designed to provide feedback on every submission received.

    I recommend using the portal based on your Symantec contract (Gold, Platinum, Basic, essential, etc) - those submissions will be assigned a tracking number and you will receive correspondence on whether the files submitted are a new threat, already detected, etc.

    Hope this helps!

    Thanks and best regards,

    Mick