Endpoint Protection

 View Only
Expand all | Collapse all
ℬrίαη

ℬrίαηNov 18, 2009 01:09 PM

Rafeeq

RafeeqNov 18, 2009 01:18 PM

  • 1.  JS/Agent.MZT

    Posted Nov 18, 2009 01:09 PM
    Is there a write up on this trojan somewhere?


  • 2.  RE: JS/Agent.MZT

    Posted Nov 18, 2009 01:18 PM
    No writing in symantec so far :(


  • 3.  RE: JS/Agent.MZT

    Posted Nov 18, 2009 01:19 PM
    Ok, I wasn't able to find much anywhere on this. Our proxy servers are getting an unusually high amount of alerts on this


  • 4.  RE: JS/Agent.MZT

    Posted Nov 18, 2009 01:24 PM
    Can you submit a sample to Symantec? This can help get detection included for this new threat in future definitions.

    http://www.symantec.com/business/security_response/submitsamples.jsp




  • 5.  RE: JS/Agent.MZT

    Posted Nov 18, 2009 01:26 PM
    The naming convention is differnet for different antivirus vendors.
    Not sure what name symantec / or under what category this virus comes in.
    I'm sure that symantec is much more capable of detecting virus when compared to others :)
    Not able to find symantec name hence failed to  find the writeup


  • 6.  RE: JS/Agent.MZT

    Posted Nov 18, 2009 01:31 PM
    Right now, I only have the links to sites but I don't have a specific file. Wil lthat work?


  • 7.  RE: JS/Agent.MZT

    Posted Nov 18, 2009 01:34 PM
    You need to submit the infected file / so that symantec can reverse engineering and find the virus code in that and develop the definitions for that.


  • 8.  RE: JS/Agent.MZT

    Posted Nov 18, 2009 01:49 PM
    I'll try but since it's not being detected, I'll have to visit the sites to see what files are being downloaded.


  • 9.  RE: JS/Agent.MZT
    Best Answer



  • 10.  RE: JS/Agent.MZT

    Posted Nov 18, 2009 08:46 PM
    I submitted several samples to Symantec for analysis


  • 11.  RE: JS/Agent.MZT

    Posted Nov 19, 2009 08:08 AM
    Is there a number I can call to track status of the samples I submitted? I received the emails confirming submission but want to check on this as the alerts seem to be increasing at an enormous rate.


  • 12.  RE: JS/Agent.MZT

    Posted Nov 19, 2009 10:36 AM
    please mention your tracking number here, I think symantec employees can get the details of your tracking number.


  • 13.  RE: JS/Agent.MZT

    Posted Nov 19, 2009 11:12 AM
    Tracking numbers are as follows:

    13700502
    13700500
    13700453
    13700450


  • 14.  RE: JS/Agent.MZT

    Posted Nov 19, 2009 02:29 PM
    I'm finding that these may be false positives and were deactivated in Panda's latest defs. An update of the defs should take care of it.