Endpoint Protection

 View Only
  • 1.  Downloader.Upatre found in Outlook 2011 attachment

    Posted Apr 29, 2014 03:55 PM

    Good afternoon. With the latest edition of SEP (12.1.4) we have started to deploy to OSX 10.8 and 10.9. A couple of our test users have come up with the above mentioned virus. Maybe this should be pursued from the other side (Office for Mac), but as we are kind of new at Mac support in general, I'll try here.

     

    I ran a full scan on both users which came up emtpy. They both still show up in the Adminsitrator Daily Summany Report as "Still Infected" and I can confirm that I still see the attachment in the filesystem. While I could certainly just trash the attachment, I can't tell which message it goes to. For peace of mind, does anyone know how to backtrack from the detection:

     

    Filename: /Users/<username>/Documents/Microsoft User Data/Office 2011 Identities/Main Identity/Data Records/Message Attachments/0T/0B/0M/147K/x26_147089.olk14MsgAttach

     

    to the actual message? Just see where it came from, if nothing else. Thanks for any help.



  • 2.  RE: Downloader.Upatre found in Outlook 2011 attachment

    Posted Apr 29, 2014 03:58 PM

    This will be tough unless can tie the path names to the message itself. Obviously you have the username and timestamp so you can check exchange and try to match up that way



  • 3.  RE: Downloader.Upatre found in Outlook 2011 attachment

    Posted May 02, 2014 08:25 AM

    Do you need more assistance with your question?

    If you could post an update for followers of this thread that would be most helpful.

    Thanks and take care,
    Brian