New virus discovered W32/Autorun-Ase
Has anyone run into this virus yet? It is called "W32/Autorun-Ase". It has propagated to about 50 workstations this week. SEP MR4 is installed on all the workstations in our company, up-to-date with the latest sigs, and it is not being detected. It was discovered by our network engineers who saw some strange activity, and came to me wanting to know why SEP has not picked it up yet. He was also able to detect it with Sophos. The virus installs itself in the registry as a TaskMan entry and installs the file "wnzip32.exe" in the Recycle Bin where it usually will be skipped by virus scanners.
Does anyone know if SEP has a sig update or utility to get rid of it yet? I have checked the knowledgebase and download section and can't find anything on it.
Thanks!
Larry
Comments
This sounds like a new threat
This sounds like a new threat or a new varient of an existing threat. I am not finding anything on Symantec's or Threat Experts sites about this one. You should sumbit a sample for analysis ASAP. Symantec can then create a new def for this threat.
http://www.symantec.com/business/security_response...
Best,
Thomas
Submit suspicious file
Q) How do I submit suspicious files to Symantec?
A) You can submit up to 9 files in a compressed file at once via Symantec's Web Submission Site.
or
You may submit a file from local quarantine or Central quarantine using Scan and Deliver.
For details see the document How to submit a file to Symantec Security Response using Scan and Deliver available at
http://service1.symantec.com/SUPPORT/ent-security....
Q) Is this a secure submission site?
A) Yes. This tool uses SHTTP and SMTP. It also takes advantage of Secure Socket Layer (SSL) and 128-bit encryption, providing a secure method of transporting the files to Symantec. If you have not previously used the web submission site, please contact support for the URL.
Q) What information is needed to submit through the web submission site?
A) You will need to provide your name, company name, email address and Contact ID number. Please note: the Contact ID field is a numeric field. If your Contact ID contains one or more hyphens (-), please omit them.
Q) How many files may I submit?
A) You may upload multiple files at once by using WinZip or a similar application. A zipped file should not be password-protected. The maximum size for one submission is 10MB. Please submit no more than 9 files in any zip file regardless of size.
Q) May I provide information or ask questions at this site?
A) The web submission form includes a field to detail symptoms you believe are associated with this file. Security Response engineers do not provide answers to questions posed in this form. If you need further information, please contact support.
Q) What happens next?
A) The submission process follows the steps below:
You will receive an automated email reply that contains the Tracking number for this submission. Please retain this number. The sender's address will be SecurityResponse@Symantec.com. Note: if you have a TAM (Technical Account Manager) he or she will receive a copy of all automated email messages sent to you.
Your submission will be immediately scanned by our automated system using current certified and current rapid release definitions. If this file has been previously submitted, you will receive an automated closing email. The email will include the known determination and, if malicious or a security risk, instructions on how to retrieve definitions that will detect the file.
If the file has not been seen before it will be queued for review by the next available engineer.
The Security Response engineer who reviews the file will make a determination on the status of the file. If clean, he or she will close the submission process and an automated email message will be sent identifying the file as clean.
If it is determined the file is malicious or a security risk, the engineer will create a signature that will trigger a detection on this file. He or she will then pass the submission on to a QA engineer.
Once the QA engineer has verified that the signature correctly identifies the file, that engineer will close the submission process and an automated email message will be sent. This message will indicate the determination on the file and include instructions on how to download definitions that contain the detection.
Q) What if I want to submit a file that I believe is being falsely detected?
A) Please submit the file via the Symantec's Web Submission Site.
How to submit a file to Symantec Security Response using Scan and Deliver available at http://service1.symantec.com/SUPPORT/ent-security....
Thanks & Regards Sandip C Sali
URL for sample submission
Larry
Hope below URL will help u to submit the suspected files -
http://www.symantec.com/business/security_response/submitsamples.jsp
You need to select the Symantec User ( Cuastomer) catagory -
Retail (Home) Users
Online Threat Submission Form
Basic Maintenance/Essential Support Users
Please contact Basic Maintenance/Essential Support for the Web address
Business Critical Services Support Users
Please contact Business Critical Services Support for the Web address
Thanks and Best Regards,
________________________________________________________
Gagan Biswas
Would you like to reply?
Login or Register to post your comment.