Endpoint Protection

 View Only
  • 1.  SEP scanning possible rootkit?

    Posted Jun 17, 2010 01:05 AM
    Hi, I am currently having problem which is whenever a scan is running, I can see that the scanning will scan the files below which I tried to locate physically but was not found. I can see it being scanned but there is no alert on any virus detection. c:\windows\hide_evr2.sys c:\windows\9129837.exe c:\windows\system32\VirusRemoval.vbs c:\windows\system32\NewVirusRemoval.vbs This situation is similiar to one of the posting (https://www-secure.symantec.com/connect/forums/9129837exe). I have tried using icesword but does not show me any of the above is running. My antivirus is updated as of today. I am not sure where can I go from here as I do not encounter anything suspicious. It is just that I was looking at the scanning and it stop and scan those file for a spilt second and I think the file name is a bit funny so I made some searching. I read that SEP does not scan for anticipated malicious file (which is what I first suspect) so I am not sure if my PC is really compromised. Please help. Thanks.


  • 2.  RE: SEP scanning possible rootkit?

    Broadcom Employee
    Posted Jun 17, 2010 01:24 AM
    submit the suspicious file to the Symantec Virus team.

    https://submit.symantec.com/websubmit/essential.cgi


  • 3.  RE: SEP scanning possible rootkit?

    Posted Jun 17, 2010 01:36 AM

    as i mentioned earlier, was not able to locate the physical file. so i have no file which i can submit......thanks.



  • 4.  RE: SEP scanning possible rootkit?

    Broadcom Employee
    Posted Jun 17, 2010 01:39 AM
    in that case, you open a support case. The Engineer will ask you to run the SEPsupport tool which includes the LoadPoint and after analyzing they will help you to identify the suspicious file for submission.