Endpoint Protection

 View Only
Expand all | Collapse all

Threat undetected

Mithun Sanghavi

Mithun SanghaviAug 25, 2009 01:06 PM

Migration User

Migration UserAug 25, 2009 03:30 PM

  • 1.  Threat undetected

    Posted Aug 25, 2009 12:49 PM
    Today I found a suspicious file on our file servers, it is executable with 145 KB that the SEP has not detected a threat. I sent the file to Symantec's analysis but still no answer. But the analysis of online Kasperky it was detected the following threat: Trojan.W32.Regrun.bac. How can I prevent the spread of this threat until a vaccine is available? Attached images about the threat. Searching the internet I found that other antivirus also detect this threat.


  • 2.  RE: Threat undetected

    Posted Aug 25, 2009 12:53 PM
    Can you provide the Symantec tracking number? I will look into the status of your submission.

    Regards,
    Thomas


  • 3.  RE: Threat undetected

    Posted Aug 25, 2009 12:58 PM
     did u submit the files in https:submit.symantec.com/... or kaspersky coz the png file is showing kaspersky submit site i guess


  • 4.  RE: Threat undetected

    Posted Aug 25, 2009 01:03 PM
    I have not received any Symantec Tracking Number, i submit the file from SEP Client (Manual Quarentine -> Submit).

    Thanks..


  • 5.  RE: Threat undetected

    Posted Aug 25, 2009 01:06 PM
    Vikram, i submit the file from SEP Client (Manual Quarantine -> Submit). Not from site in https://submit.....


  • 6.  RE: Threat undetected

    Trusted Advisor
    Posted Aug 25, 2009 01:06 PM
    Try our new

    Norton Security Scan!



    http://security.symantec.com/sscv6/WelcomePage.asp



  • 7.  RE: Threat undetected

    Trusted Advisor
    Posted Aug 25, 2009 01:14 PM
    1. CHECK FOR KNOWN OS VULNERABILITIES AND DOWNLOAD PATCHES TO PROTECT THEM:

    2. To disable System Restore (Windows Me/XP)
    If you are running Windows Me or Windows XP, we recommend that you temporarily turn off System Restore. Windows Me/XP uses this feature, which is enabled by default, to restore the files on your computer in case they become damaged. If a virus, worm, or Trojan infects a computer, System Restore may back up the virus, worm, or Trojan on the computer.

    Windows prevents outside programs, including antivirus programs, from modifying System Restore. Therefore, antivirus programs or tools cannot remove threats in the System Restore folder. As a result, System Restore has the potential of restoring an infected file on your computer, even after you have cleaned the infected files from all the other locations.

    Also, a virus scan may detect a threat in the System Restore folder even though you have removed the threat.

    3. Disable all start up Programs from msconfig.

    4. Disable all BHO (Browser Helper Objects) from IE and other Browsers.



    Incase you have Symantec installed On your Computer.

    Please try to Submit the Files to Symantec Response Team

    by:

    https://submit.symantec.com/gold/


     


  • 8.  RE: Threat undetected

    Posted Aug 25, 2009 01:34 PM
     

    Cycletech, i resubmit the file. This time using the site (https:submit.sym...) This time I received the e-mail with the Symantec Tracking Number #12539952.



  • 9.  RE: Threat undetected

    Posted Aug 25, 2009 01:54 PM
    Vortec, You submitted your file through the retail site. Retail should only be used with the consumer products. What level of support do you have?

    Thomas


  • 10.  RE: Threat undetected

    Posted Aug 25, 2009 02:22 PM
    WHy this happens so many times that symantec miss  and others catch.
    This happen not only to me but most of the guys here posting.
    I want to know is symanc woking n this.


  • 11.  RE: Threat undetected

    Trusted Advisor
    Posted Aug 25, 2009 02:36 PM
    Hello,

    Please try to understand 1 simple logic.

    Any Antivirus installed is Like a Watch Guard or a Cop on your machine. you could not expect Antivirus to catch eveything and anything. It requires customers co-operation in every detections made.

    Please make sure we have our Perceptions changed.



  • 12.  RE: Threat undetected

    Posted Aug 25, 2009 02:53 PM
    You said that symantec is not detecting the threat then how have you submitted the file from the Qurantine?

    Can you plese zip the file & submit to the https://submit.symantec.com 

    you will get the tracking number after the submission.:)


  • 13.  RE: Threat undetected

    Posted Aug 25, 2009 03:30 PM
     Kavin, i already did.


  • 14.  RE: Threat undetected

    Trusted Advisor
    Posted Aug 25, 2009 04:49 PM
    Hi,

    I believe since you have submitted those files, you might have received email on the same...with a tracking number int he Subject line...

    Could you please provide us that Tracking number...???


  • 15.  RE: Threat undetected

    Posted Aug 25, 2009 05:08 PM
    Since I had already responded to Cycletech:

    Cycletech, i resubmit the file. This time using the site (https:submit.sym...) This time I received the e-mail with the Symantec Tracking Number #12539952.

    Thanks and regards...

    Vortec



  • 16.  RE: Threat undetected

    Trusted Advisor
    Posted Aug 25, 2009 05:13 PM

    Result:

    Our automation was unable to identify any malicious content in this submission.
    The file will be stored for further human analysis




    It would take 24 / 48 hours for further human analysis



  • 17.  RE: Threat undetected

    Posted Aug 25, 2009 09:14 PM
    I agree with Mithun, you could not expect Antivirus to catch eveything and anything. It requires customers co-operation in every detections made.and especially we need to escalate the concern to technical support asap.


  • 18.  RE: Threat undetected

    Posted Aug 25, 2009 10:31 PM
    Symantec is one of the giants in av field, if I run a online scan from virustotal.com and two or more companies detects the threat, then I would say Symantec should detect it as well. If not, I would think Symantec might need to think about how come other vendors detect it and they did not, I agree there are lots of viruses and Symantec cannot detect all of them at all the time, but Symantec is av company, when I bought the product, I did not see anywhere on a box or documents come with the spftware saying it cannot detect all the virus.
    We all like Symantec av product, some people posted these ype of informaiton on this forum, I think they just wish Syamntec can improve on certian detection, otherwise they can post those informaiton on anywhere on the internet.
      


  • 19.  RE: Threat undetected

    Posted Aug 26, 2009 12:26 AM
    Yes I like Symantec for their support but would like to see some improvement in detection rate which will make them unbeatable.


  • 20.  RE: Threat undetected

    Posted Aug 26, 2009 06:09 AM
    I agree with Bijay..
    Mithun --So do you mean to say its our wrong perception if we think a Antivirus should catch virus.
    So what's the right perception--Once you get infected submit the files.
    Is there any automated way symantec is only dependant on customer's submission.
    Are the sensors still working or the reccession has brought them down.


  • 21.  RE: Threat undetected

    Posted Aug 26, 2009 06:13 AM
    <<Any Antivirus installed is Like a Watch Guard or a Cop on your machine>>

    But what if daily there is a burgalry in your house what will you do ?


  • 22.  RE: Threat undetected

    Trusted Advisor
    Posted Aug 26, 2009 08:00 AM
    Check this:

    http://www.top10list.com/top,10,antivirus,protection/top-ten-antivirus-protection.asp


    One Question and Little Logic Thinking could change your Perception:

    "Does all Antivirus give you a 100% protection...?? "

    If yes, I think then we would not have the word "Hackers" or "Virus creators"...

    Think about it....


    Again... if you truely believe that a Antivirus is the best for your network then trust it.... it truely is.

    If any user is thinking that the Antivirus is not the right one, i believe he would keep on changing Antiviruses and Land up nowhere and his perception (Perception: "This is not giving me total protection") would remain same with whichever Antivirus he / she installs on his network...


  • 23.  RE: Threat undetected

    Posted Aug 26, 2009 11:21 PM
     I received a response from the Symantec Response, they confirmed the presence of a threat in the file and told me to upgrade to the latest definitions for later detection. Well, I updated to the latest definition available and stemmed? The SEP has not found again! What impresses me most is that today I made a new test with Avira Free version, I said Free! He detected the threat immediately! What is happening with Symantec?


  • 24.  RE: Threat undetected

    Posted Aug 27, 2009 01:07 AM
     When you get the email from Security response did you do the regular liveupdate or you updated the definitions with the rapud release definitions as suggested in the email from security response.


  • 25.  RE: Threat undetected

    Posted Aug 27, 2009 09:06 AM
    this thread has me nervous. I've always looked to symantec as the fallback. when other tools fail, i've had pretty good luck with symantec av.  i had been planning to use endpoint on a server that's been attacked.  but if i read this correctly, maybe i should be looking at other tools as well.

    i understand that a single provider can't be 100% effective.  i also have a paranoid thought that some low-end av providers may be playing both sides to promote their product.  i just expect symantec to be on top of these.


  • 26.  RE: Threat undetected

    Trusted Advisor
    Posted Aug 27, 2009 09:26 AM
    arquivos.exe

    is a threat. Please install the latest available definitions by following the instructions at the end of this email message.

    Rapid Release Virus Definitions

    http://www.symantec.com/business/security_response/definitions/download/detail.jsp?gid=rr

    OR

    ftp://ftp.symantec.com/AVDEFS/norton_antivirus_corp/rapidrelease/



    Download the :

    symrapidreleasedefsv5i32.exe | FTP

    which supports the following versions of Symantec Endpoint Protection 11.0  


  • 27.  RE: Threat undetected

    Posted Aug 27, 2009 10:16 AM
     @cvonfeldt -- When we say multiple vendors..it means in layer of security appliances where all work on virus definitions you should have different vendors so that if one misses other will catch it.

    Whereas Host Based AV is in question SEP is the best..keeping in mind that it does more than just catching viruses 


  • 28.  RE: Threat undetected

    Posted Aug 27, 2009 03:18 PM
    To all Symantec Customers,

    I'm using Symantec for our Network Security around 8-9 years. From version 7.x up to SEP 11.x MR4 MP2 . As i know, Symantec needs to be Configured very well ( i mean by Professionals ) to work verywell * achive Best result for Securing our Networks .
    On the other hand, Documents and Manuals, are Complecate and not very simple to Undrestand for every body, so the result will be existing situation that we see ( Lot's of Complains from some Customers about Threats that Symantec can't undrestand them ).
    As we know, some features like Proactive or Tracing are Unic in Symantec Antivirus if Compare it with other AV on the world. Also the SEPM Console that uses Java for new themes of Management Console, will give Admins, Lot of Very Important Info about Security Status of Hole Networks Very Fast & Easy in Brief @ one look that is Very well & Best rather than others AV's .
    I belive that, Sometimes Symantec can't cach the new threats, but for me this is very Strange that, if you send that threat by Yahoo! mail Services, it will say that " This file is Infected by ***** Virus " , and as we know, Yahoo is Using Norton for Scanning file that is one of Symantec Products ...
    So, i Can't Undrestand, Why Norton can get this Threat, but our Symantec Can't even undrestand it ??? Sorry, if my English is not so good.

    Best Regards, J. Nourbakhsh


  • 29.  RE: Threat undetected

    Posted Aug 31, 2009 02:31 PM
    Vortec, You should open a case with Symantec support. Lets get them involved and see why this is not getting detected. Post your case number so that we can track the progress of your issue.

    Thanks,
    Thomas


  • 30.  RE: Threat undetected

    Posted Aug 31, 2009 03:37 PM
    Wait...
                 Were you praising the product or complaining about the product ? :)


  • 31.  RE: Threat undetected

    Posted Sep 08, 2009 04:08 PM
    Vortec, Did you open a case with Symantec? Give us an update when you have a moment.

    Thanks,
    Thomas