Endpoint Protection

 View Only
Expand all | Collapse all

SEP and Photo.exe

Migration User

Migration UserJul 09, 2013 06:49 AM

  • 1.  SEP and Photo.exe

    Posted Jul 09, 2013 06:18 AM

    Has anyone come across Photo.exe, which keeps materialising on our Windows Server 2003 share drive, in various locations. i am not sure if it is being created by share drive clients on on the windows server itself. I have ran SEP and Malwarebytes, Malicious Software rmoval tools, to no avail.

    Thanks in advance.



  • 2.  RE: SEP and Photo.exe

    Broadcom Employee
    Posted Jul 09, 2013 06:22 AM

    submit the file to Symantec Security response if you feel it is suspicious.



  • 3.  RE: SEP and Photo.exe

    Posted Jul 09, 2013 06:29 AM

    Hi,

    You can submit the file for submission in symantec.

    https://submit.symantec.com/websubmit/retail.cgi

    Using Symantec Help (SymHelp) Tool, how do we Collect the Suspicious Files in SEP 12.1  and Submit the same to Symantec Security Response Team.

    https://www-secure.symantec.com/connect/articles/u...

    Symantec Help (SymHelp)

    http://www.symantec.com/docs/TECH170752



  • 4.  RE: SEP and Photo.exe

    Posted Jul 09, 2013 06:49 AM

    Thank you, will do.



  • 5.  RE: SEP and Photo.exe

    Posted Jul 09, 2013 07:16 AM

    It would seem that the likely issue here is that someone with a mapped drive to this server causes it to continuously be re-infected.

    Have you checked the remote connections to the server and what file(s) they have open or are accessing?

    Have you disabled autorun?



  • 6.  RE: SEP and Photo.exe

    Posted Jul 09, 2013 07:55 AM

    Thanks Pete, We will investigate remote connections and test with Autorun disabled



  • 7.  RE: SEP and Photo.exe

    Trusted Advisor
    Posted Jul 09, 2013 11:00 AM

    Hello,

    Are running the SEP 12.1 client with latest definitions and carry all the latest Microsoft updates and security patches on the machine?

    Run a scan in safe mode with networking to remove the virus.

    Could you zip each of the folders and submit the zip files (without password) to the Symantec Security Response Team on : 

    https://submit.symantec.com/websubmit/essential.cgi

    We also offer a self-service site to analyze files, at http://www.threatexpert.com, which can give you more information on the files you submit to it.

    What to do when you suspect that a Symantec AntiVirus product is not detecting viruses

    http://www.symantec.com/docs/TECH99222

    In your case, it is also advisable to follow few important steps:

    1) Make sure all these machines are Patched with ALL Latest MS security patches and service packs.

    2) Make sure the machines are installed with the Latest Symantec virus definitions.

    3) Disable the Autorun Feature on the machine via GPO. http://support.microsoft.com/kb/967715

    4) Disable System Restore before you do this as the virus also creates entries in the System Restore Points store volumes.

    Also, check this Article:

    Using Symantec Help (SymHelp) Tool, how do we Collect the Suspicious Files and Submit the same to Symantec Security Response Team.

    Hope that helps!!



  • 8.  RE: SEP and Photo.exe

    Posted Jul 09, 2013 11:15 AM

    Hello,

    submissions to:

    https://www.virustotal.com

    and

    http://www.threatexpert.com

    would be useful too.



  • 9.  RE: SEP and Photo.exe

    Posted Jul 09, 2013 11:20 AM

    Analysis the virus file from "www.virustotal.com"

    Virus can detected by other AV not by Symantec then sumit the file to symantec security response team

    http://www.symantec.com/security_response/submitsamples.jsp

    If virus detected by symantec then scan it in safe mode n/w to clean it.

    Run the SPE tool and submit report to symantec

     How to run Symantec Power Eraser with the SymHelp utility

     

    Article:TECH203683  |  Created: 2013-03-08  |  Updated: 2013-05-23  |  Article URL http://www.symantec.com/docs/TECH203683

    https://www-secure.symantec.com/connect/articles/about-new-symhelp-tool-sep-121ru2



  • 10.  RE: SEP and Photo.exe

    Posted Jul 09, 2013 12:10 PM

    Thank you all, we will work on many of the solutions and suggestions proposed above.



  • 11.  RE: SEP and Photo.exe

    Posted Jul 19, 2013 11:06 AM

    You are welcome, just remember to flag the discussion as resolved.



  • 12.  RE: SEP and Photo.exe
    Best Answer

    Posted Oct 25, 2013 07:50 AM

     

     
    Please update the current status in thread or mark as Solved with the helpful one.
     


  • 13.  RE: SEP and Photo.exe

    Posted Oct 25, 2013 08:03 AM

    NoelP

    please mark the answer that best helped as the solution. The one you marked does not provide the solution



  • 14.  RE: SEP and Photo.exe

    Posted Oct 25, 2013 09:56 AM

    This solggested solution resolved the issue for me, Thanks