Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

Symantec AV Definition Change Today

Updated: 22 May 2010 | 3 comments
tekkid's picture
0 0 Votes
Login to vote

Just giving everyone a head's up....  Anytime Symantec says there "might" be a problem, makes me nervous.  Symantec, could you elaborate more on what this is going to do and impact?  This is the first I've heard of it.

 

Discovered: February 6, 2009
Updated: February 6, 2009 1:02:01 AM
Type: Trojan, Virus
Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000

Symantec’s antivirus products contain a highly sensitive detection technology designed to detect entirely new malware threats without traditional signatures. This technology is aimed at detecting malicious software that has been intentionally mutated or morphed by attackers.

If one or more files on your computer have been classified as having a Suspicious.MH690.A threat, this indicates that the files have suspicious characteristics and therefore might contain a new or unknown threat. However, given the sensitive nature of this detection technology, it may occasionally identify non-malicious, legitimate software programs that also share these behavioral characteristics. Therefore, it is recommended that users manually check all files detected as Suspicious.MH690.A by Symantec antivirus products for potential misidentification, and submit any suspect files to Symantec Security Response for further analysis. For instructions on how to do this, read Submit Virus Samples.

In rare cases where a legitimate file has been misidentified and subsequently quarantined, your computer may behave abnormally or you may find that one or more applications no longer function as expected. In such rare situations, you should open the Quarantine in your Symantec antivirus product. From here, you may review the list of all fil

 

Comments

David-Z's picture
06
Feb
2009
0 Votes 0
Login to vote

Hello Tekkid,

 

I can probably clear some of this up for you.

 

Symantec is releasing a new heuristic signature as part of our definitions today. Files detected by it will be identified as Suspicious.MH690. This new signature is NOT enabled by default. In order to take advantage of it you will need to increase your Bloodhound (TM) Heuristic Virus Detection level to "Maximum level of protection" or "Level 3". At the default and minimum levels the signature is disabled.

 

Hope that helps!

 

If you have any additional questions please feel free to ask. =)

Message Edited by David-Z on 02-06-2009 10:08 AM
tekkid's picture
06
Feb
2009
0 Votes 0
Login to vote

Thank you for the prompt answer.   I can't think why we would bump that up unless we were pretty certain something was loose on the network.   That makes me feel a whole lot better going into the weekend.

Someone Else's picture
16
Mar
2009
0 Votes 0
Login to vote

"New" heuristic question

So here's a queston.  Was this "new" heuristic available with the default (as opposed to maximum) setting on the consumer products?  If yes, is there a plan to move this heuristic into the default setting for SEP at some point?