Endpoint Protection

 View Only
  • 1.  ATTACK on Symantec processes, LU, etc.

    Posted Jan 22, 2010 03:44 PM
    Originated from www.yahoo.com
    TWO users in a single office.
    One use Yahoo to search for weather,
    and another to search for a movie on disabilities.
    BOTH computers hit by a risk within a couple minutes of each other.
    What is/was it? I could not stop the processes, and I was not able to do a remote reboot of either computer - it was blocking attempts to shut down remotely.

    WARNING - beware of YAHOO..............
    Domain name:
    Site name:
    API:
    Action:
    Test mode:
    Windows domain:
    User
    Server name:
    Group name:
    Computer Name
    Current:
    When event occurred:
     
    Event type:
    Event time:
    Severity:
    Begin time:
    End time:
    Rule name:
    Alert:
    Send SNMP trap:
    Caller Process ID:
    Caller Process Name:
    Target:
    User name:
    Description:
    ---------------------------------------------------------------------------------------------------------------------------------------------

    Domain name:
    Site name:
    API:
    Action:
    Test mode:
    Windows domain:
    User
    Server name:
    Group name:
    Computer Name
    Current:
    When event occurred:
     
    Event type:
    Event time:
    Severity:
    Begin time:
    End time:
    Rule name:
    Alert:
    Send SNMP trap:
    Caller Process ID:
    Caller Process Name:
    Target:
    User name:
    Description:


  • 2.  RE: ATTACK on Symantec processes, LU, etc.

    Posted Mar 05, 2010 06:29 AM
    Were you able to submit the the two executables mentioned in the logfile above?

    You can run the ESUG loadpoint and create a task just to be sure that the machine did not get infected.

    Aniket


  • 3.  RE: ATTACK on Symantec processes, LU, etc.

    Posted Mar 05, 2010 06:49 AM
    Have u submitted the sample of buyjsysguard.exe to symantec security response team ?


    Regards...
    Ramji Iyyer