Endpoint Protection

 View Only
  • 1.  Bloodhound.SONAR.1 in symantec.exe

    Posted May 19, 2009 03:00 PM
    This is from the Symantec Threat Reporter [edited], a reporting tool by Symantec:

    Virus found:Bloodhound.SONAR.1 on computername

    IP Address: xxx.xxx.xxx.xxx
    User: username
    Alert Date/Time: 2009-05-20 02:11:04
    DB insertDate/Time:2009-05-20 02:40:27
    Source: AV - Heuristic Scan
    File/Path: c:/program files/windows nt/symantec.exe
    Actual Action: Left alone
    Servergroup: servername
    Parent Server: SEP servername
    Client Group: Company/Group/Sub-group

    I already sent instructions for the user to do a full scan. Waiting for results
    Comments, feedback?


  • 2.  RE: Bloodhound.SONAR.1 in symantec.exe

    Posted May 19, 2009 04:24 PM
    I received the screenshot. They only found a Tracking Cookie.


  • 3.  RE: Bloodhound.SONAR.1 in symantec.exe
    Best Answer

    Posted May 20, 2009 08:16 PM
    The file being detected is that of UltraSurf. It seems that it only detects the file as malware whenever the user accessed a site with malicious scripts.