Endpoint Protection

 View Only

SAV enabled, up to date and running, but skipping known viruses

  • 1.  SAV enabled, up to date and running, but skipping known viruses

    Posted Aug 29, 2008 11:09 AM

    Slight problem, have tested this on a few machines in the organisation. Known virus

     

    http://www.virustotal.com/analisis/d788c83c0444cc35b9fcf16c92e43acf

     

    Supposedly known by Symantec as Backdoor.Paproxy. Scanned with SAV 102.0.298 and it said "no threats found". Put the file into quarantine manually, and submitted to Symantec for analysis. Got the email back saying "already known, Backdoor.Paproxy".

     

    Eh ? Symantec knows about the file, my definitions are 29/08/08 and yet it doesn't recognise it. How come ?? Very dangerous as it would be quite happy to let me run it and create all sorts of chaos. Found another the other day, it acted the same way.

     

    Not giving me a lot of confidence in Symantec, and as we have thousands of copies deployed.....

    Message Edited by AndrewW on 08-29-2008 08:13 AM