Endpoint Protection

 View Only
Expand all | Collapse all
Migration User

Migration UserJan 20, 2014 01:35 PM

Migration User

Migration UserJan 20, 2014 01:42 PM

Migration User

Migration UserJan 20, 2014 03:40 PM

Migration User

Migration UserJan 20, 2014 03:41 PM

Migration User

Migration UserJan 20, 2014 03:49 PM

ℬrίαη

ℬrίαηJan 20, 2014 03:58 PM

ℬrίαη

ℬrίαηFeb 24, 2014 09:17 PM

  • 1.  Autorun.inf

    Posted Jan 20, 2014 01:29 PM

    I would like to add autorun.inf to the exclusion list fro SEP, I have but it still seems to be picking it up. I am not even certain why Autorun.inf is even picked up, I've never seen an autorun.inf cause and malicious issues.

    How can I add it to the exclusions and make sure it is no longer picked up as a threat?



  • 2.  RE: Autorun.inf
    Best Answer

    Posted Jan 20, 2014 01:31 PM

    Do you really want to do that? cool

    Autorun.inf is a major player in the spread of viruses from one system to another.

    And autorun.inf shouldn't be picked up as it is not inherently malicious.

    The detection is likely due from a piece of malware. What's the detection name?

    Is it this?

    SecurityRisk.OrphanInf

    http://www.symantec.com/security_response/writeup.jsp?docid=2011-040403-3248-99



  • 3.  RE: Autorun.inf

    Posted Jan 20, 2014 01:35 PM

    BackOffice.Trojan



  • 4.  RE: Autorun.inf

    Posted Jan 20, 2014 01:36 PM

    Where's the autorun.inf file coming in to play than?

    If you use application and device control, one of the default policies is to block autorun.inf



  • 5.  RE: Autorun.inf

    Posted Jan 20, 2014 01:37 PM

    We're not outta the woods yet with these forums and IE 11, I cannot copy and paste on these boards in IE 11



  • 6.  RE: Autorun.inf

    Posted Jan 20, 2014 01:38 PM

    DefWatch    Suspicious.MH690     01/20/2014 13:03:12     01/20/2014 13:03:12    
    C:\PROGRAMDATA\SYMANTEC\DEFWATCH.DWH\DWHF39A.exe
     

    and I went to the machine with this directory, and this durectoy and file are NOWHERE to be found.

    It is legit up to this part of the directory

    C:\PROGRAMDATA\SYMANTEC

     



  • 7.  RE: Autorun.inf

    Posted Jan 20, 2014 01:39 PM

    The drive letter is "E" so I am under the impression that it is a DVD or a USB



  • 8.  RE: Autorun.inf

    Posted Jan 20, 2014 01:40 PM

    Hmm, wondering if you have the dwhxxx issue:

    When new virus definitions are in place and the quarantine is being scanned, a DWH file is created and detected by Auto-Protect

    http://www.symantec.com/docs/TECH102953

     

    Essentially, it's a false positive and a bug in the product



  • 9.  RE: Autorun.inf

    Posted Jan 20, 2014 01:42 PM

    A bug? No way. :-)



  • 10.  RE: Autorun.inf

    Posted Jan 20, 2014 01:48 PM

    Been around since 11.x days. But judging by what the file being scanned is, that's look like the case



  • 11.  RE: Autorun.inf

    Posted Jan 20, 2014 02:30 PM


    Symantec Endpoint Protection 12.1
    DEL /F /Q "C:\ProgramData\Symantec\Symantec Endpoint Protection\silo

     

    I see NO directory that has "silo"



  • 12.  RE: Autorun.inf

    Posted Jan 20, 2014 02:38 PM

    silo means version number..so whatever version you're on just use that number. 12.1.4 would 12.1.4013.4013



  • 13.  RE: Autorun.inf

    Posted Jan 20, 2014 02:41 PM
    From the TECH article:"Replace silo with the appropriate build number"
     
    i.e. C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.4013.4013.105
     
    sandra


  • 14.  RE: Autorun.inf

    Posted Jan 20, 2014 03:40 PM

    How in the worlds does Silo translate to that?



  • 15.  RE: Autorun.inf

    Posted Jan 20, 2014 03:41 PM

    That folder is empty anyway.



  • 16.  RE: Autorun.inf

    Posted Jan 20, 2014 03:43 PM

    Maybe because it "holds" the relevant product files :)



  • 17.  RE: Autorun.inf

    Posted Jan 20, 2014 03:49 PM

    Amusing...



  • 18.  RE: Autorun.inf

    Posted Jan 20, 2014 03:58 PM

    Shouldn't be as it contain the install surprise



  • 19.  RE: Autorun.inf

    Posted Jan 22, 2014 09:28 PM

    Found this great reference which should give you a better idea of the intended behavior:

    Why Symantec Endpoint Protection does not remove AT, INF, INI, and registry keys related to infections

    http://www.symantec.com/docs/TECH158359



  • 20.  RE: Autorun.inf

    Posted Feb 24, 2014 09:17 PM

    Still bugging you?