Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

Threat undetected

Updated: 21 May 2010 | 30 comments
Vortec's picture
0 0 Votes
Login to vote
Today I found a suspicious file on our file servers, it is executable with 145 KB that the SEP has not detected a threat. I sent the file to Symantec's analysis but still no answer. But the analysis of online Kasperky it was detected the following threat: Trojan.W32.Regrun.bac. How can I prevent the spread of this threat until a vaccine is available? Attached images about the threat. Searching the internet I found that other antivirus also detect this threat.

Comments

Thomas K's picture
25
Aug
2009
0 Votes 0
Login to vote

Can you provide the Symantec

Can you provide the Symantec tracking number? I will look into the status of your submission.

Regards,
Thomas

Vortec's picture
25
Aug
2009
0 Votes 0
Login to vote

  Cycletech, i resubmit the

 

Cycletech, i resubmit the file. This time using the site (https:submit.sym...) This time I received the e-mail with the Symantec Tracking Number #12539952.

Vikram Kumar-SAV to SEP's picture
25
Aug
2009
0 Votes 0
Login to vote

 did u submit the files in

 did u submit the files in https:submit.symantec.com/... or kaspersky coz the png file is showing kaspersky submit site i guess

Vortec's picture
25
Aug
2009
0 Votes 0
Login to vote

Vikram, i submit the file

Vikram, i submit the file from SEP Client (Manual Quarantine -> Submit). Not from site in https://submit.....

Vortec's picture
25
Aug
2009
0 Votes 0
Login to vote

I have not received any

I have not received any Symantec Tracking Number, i submit the file from SEP Client (Manual Quarentine -> Submit).

Thanks..

Mithun Sanghavi's picture
25
Aug
2009
1 Vote +1
Login to vote

NSS

Try our new
Norton Security Scan!

http://security.symantec.com/sscv6/WelcomePage.asp

Mithun Sanghavi
Symantec Technical Support Engineer, SEP
MIM | MCSA | SCTS | ITIL v3

Follow me on Twitter: @mithun_sanghavi

Don't forget to mark your thread as 'SOLVED' with the answer that best helped yo

Mithun Sanghavi's picture
25
Aug
2009
1 Vote +1
Login to vote

Answers:

1. CHECK FOR KNOWN OS VULNERABILITIES AND DOWNLOAD PATCHES TO PROTECT THEM:

2. To disable System Restore (Windows Me/XP)
If you are running Windows Me or Windows XP, we recommend that you temporarily turn off System Restore. Windows Me/XP uses this feature, which is enabled by default, to restore the files on your computer in case they become damaged. If a virus, worm, or Trojan infects a computer, System Restore may back up the virus, worm, or Trojan on the computer.

Windows prevents outside programs, including antivirus programs, from modifying System Restore. Therefore, antivirus programs or tools cannot remove threats in the System Restore folder. As a result, System Restore has the potential of restoring an infected file on your computer, even after you have cleaned the infected files from all the other locations.

Also, a virus scan may detect a threat in the System Restore folder even though you have removed the threat.

3. Disable all start up Programs from msconfig.

4. Disable all BHO (Browser Helper Objects) from IE and other Browsers.

Incase you have Symantec installed On your Computer.

Please try to Submit the Files to Symantec Response Team

by:

https://submit.symantec.com/gold/

 

Mithun Sanghavi
Symantec Technical Support Engineer, SEP
MIM | MCSA | SCTS | ITIL v3

Follow me on Twitter: @mithun_sanghavi

Don't forget to mark your thread as 'SOLVED' with the answer that best helped yo

Thomas K's picture
25
Aug
2009
0 Votes 0
Login to vote

Vortec, You submitted your

Vortec, You submitted your file through the retail site. Retail should only be used with the consumer products. What level of support do you have?

Thomas

Bijay.Swain's picture
25
Aug
2009
1 Vote -1
Login to vote

WHy this happens so many

WHy this happens so many times that symantec miss  and others catch.
This happen not only to me but most of the guys here posting.
I want to know is symanc woking n this.

Mithun Sanghavi's picture
25
Aug
2009
2 Votes 0
Login to vote

Wrong Perception....

Hello,

Please try to understand 1 simple logic.

Any Antivirus installed is Like a Watch Guard or a Cop on your machine. you could not expect Antivirus to catch eveything and anything. It requires customers co-operation in every detections made.

Please make sure we have our Perceptions changed.

Mithun Sanghavi
Symantec Technical Support Engineer, SEP
MIM | MCSA | SCTS | ITIL v3

Follow me on Twitter: @mithun_sanghavi

Don't forget to mark your thread as 'SOLVED' with the answer that best helped yo

kavin's picture
25
Aug
2009
0 Votes 0
Login to vote

You said that symantec is not

You said that symantec is not detecting the threat then how have you submitted the file from the Qurantine?

Can you plese zip the file & submit to the https://submit.symantec.com 

you will get the tracking number after the submission.:)

Vortec's picture
25
Aug
2009
0 Votes 0
Login to vote

 Kavin, i already did.

 Kavin, i already did.

Mithun Sanghavi's picture
25
Aug
2009
2 Votes 0
Login to vote

Whats the Tracking Number..??

Hi,

I believe since you have submitted those files, you might have received email on the same...with a tracking number int he Subject line...

Could you please provide us that Tracking number...???

Mithun Sanghavi
Symantec Technical Support Engineer, SEP
MIM | MCSA | SCTS | ITIL v3

Follow me on Twitter: @mithun_sanghavi

Don't forget to mark your thread as 'SOLVED' with the answer that best helped yo

Vortec's picture
25
Aug
2009
0 Votes 0
Login to vote

Symantec Tracking Number is #12539952

Since I had already responded to Cycletech:

Cycletech, i resubmit the file. This time using the site (https:submit.sym...) This time I received the e-mail with the Symantec Tracking Number #12539952.

Thanks and regards...

Vortec


Mithun Sanghavi's picture
25
Aug
2009
0 Votes 0
Login to vote

Result:

Result:

Our automation was unable to identify any malicious content in this submission.
The file will be stored for further human analysis

It would take 24 / 48 hours for further human analysis

Mithun Sanghavi
Symantec Technical Support Engineer, SEP
MIM | MCSA | SCTS | ITIL v3

Follow me on Twitter: @mithun_sanghavi

Don't forget to mark your thread as 'SOLVED' with the answer that best helped yo

gilbert08's picture
25
Aug
2009
3 Votes +3
Login to vote

I agree with Mithun, you

I agree with Mithun, you could not expect Antivirus to catch eveything and anything. It requires customers co-operation in every detections made.and especially we need to escalate the concern to technical support asap.

mssym's picture
25
Aug
2009
0 Votes 0
Login to vote

Symantec is one of the giants

Symantec is one of the giants in av field, if I run a online scan from virustotal.com and two or more companies detects the threat, then I would say Symantec should detect it as well. If not, I would think Symantec might need to think about how come other vendors detect it and they did not, I agree there are lots of viruses and Symantec cannot detect all of them at all the time, but Symantec is av company, when I bought the product, I did not see anywhere on a box or documents come with the spftware saying it cannot detect all the virus.
We all like Symantec av product, some people posted these ype of informaiton on this forum, I think they just wish Syamntec can improve on certian detection, otherwise they can post those informaiton on anywhere on the internet.
  

Bijay.Swain's picture
25
Aug
2009
0 Votes 0
Login to vote

Yes I like Symantec for their

Yes I like Symantec for their support but would like to see some improvement in detection rate which will make them unbeatable.

Int3rn3t's picture
26
Aug
2009
0 Votes 0
Login to vote

I agree with Bijay.. Mithun

I agree with Bijay..
Mithun --So do you mean to say its our wrong perception if we think a Antivirus should catch virus.
So what's the right perception--Once you get infected submit the files.
Is there any automated way symantec is only dependant on customer's submission.
Are the sensors still working or the reccession has brought them down.

Int3rn3t's picture
26
Aug
2009
0 Votes 0
Login to vote

<<Any Antivirus installed is

<<Any Antivirus installed is Like a Watch Guard or a Cop on your machine>>

But what if daily there is a burgalry in your house what will you do ?

Mithun Sanghavi's picture
26
Aug
2009
1 Vote +1
Login to vote

Check the Latest Report

Check this:

http://www.top10list.com/top,10,antivirus,protection/top-ten-antivirus-protection.asp

One Question and Little Logic Thinking could change your Perception:

"Does all Antivirus give you a 100% protection...?? "

If yes, I think then we would not have the word "Hackers" or "Virus creators"...

Think about it....

Again... if you truely believe that a Antivirus is the best for your network then trust it.... it truely is.

If any user is thinking that the Antivirus is not the right one, i believe he would keep on changing Antiviruses and Land up nowhere and his perception (Perception: "This is not giving me total protection") would remain same with whichever Antivirus he / she installs on his network...

Mithun Sanghavi
Symantec Technical Support Engineer, SEP
MIM | MCSA | SCTS | ITIL v3

Follow me on Twitter: @mithun_sanghavi

Don't forget to mark your thread as 'SOLVED' with the answer that best helped yo

Vortec's picture
26
Aug
2009
0 Votes 0
Login to vote

Undetected AGAIN !!!

 I received a response from the Symantec Response, they confirmed the presence of a threat in the file and told me to upgrade to the latest definitions for later detection. Well, I updated to the latest definition available and stemmed? The SEP has not found again! What impresses me most is that today I made a new test with Avira Free version, I said Free! He detected the threat immediately! What is happening with Symantec?

Thomas K's picture
31
Aug
2009
0 Votes 0
Login to vote

Vortec, You should open a

Vortec, You should open a case with Symantec support. Lets get them involved and see why this is not getting detected. Post your case number so that we can track the progress of your issue.

Thanks,
Thomas

Thomas K's picture
08
Sep
2009
0 Votes 0
Login to vote

Vortec, Did you open a case

Vortec, Did you open a case with Symantec? Give us an update when you have a moment.

Thanks,
Thomas

Vikram Kumar-SAV to SEP's picture
26
Aug
2009
0 Votes 0
Login to vote

 When you get the email from

 When you get the email from Security response did you do the regular liveupdate or you updated the definitions with the rapud release definitions as suggested in the email from security response.

cvonfeldt's picture
27
Aug
2009
0 Votes 0
Login to vote

The biggest and best

this thread has me nervous. I've always looked to symantec as the fallback. when other tools fail, i've had pretty good luck with symantec av.  i had been planning to use endpoint on a server that's been attacked.  but if i read this correctly, maybe i should be looking at other tools as well.

i understand that a single provider can't be 100% effective.  i also have a paranoid thought that some low-end av providers may be playing both sides to promote their product.  i just expect symantec to be on top of these.

Mithun Sanghavi's picture
27
Aug
2009
0 Votes 0
Login to vote

arquivos.exe is a threat.

arquivos.exe

is a threat. Please install the latest available definitions by following the instructions at the end of this email message.

Rapid Release Virus Definitions

http://www.symantec.com/business/security_response/definitions/download/detail.jsp?gid=rr

OR

ftp://ftp.symantec.com/AVDEFS/norton_antivirus_corp/rapidrelease/

Download the :

symrapidreleasedefsv5i32.exe | FTP

which supports the following versions of Symantec Endpoint Protection 11.0  

Mithun Sanghavi
Symantec Technical Support Engineer, SEP
MIM | MCSA | SCTS | ITIL v3

Follow me on Twitter: @mithun_sanghavi

Don't forget to mark your thread as 'SOLVED' with the answer that best helped yo

Vikram Kumar-SAV to SEP's picture
27
Aug
2009
0 Votes 0
Login to vote

 @cvonfeldt -- When we say

 @cvonfeldt -- When we say multiple vendors..it means in layer of security appliances where all work on virus definitions you should have different vendors so that if one misses other will catch it.

Whereas Host Based AV is in question SEP is the best..keeping in mind that it does more than just catching viruses 

Nourbakhsh's picture
27
Aug
2009
1 Vote +1
Login to vote

One of the Best Security Software, But Settings are Important

To all Symantec Customers,

I'm using Symantec for our Network Security around 8-9 years. From version 7.x up to SEP 11.x MR4 MP2 . As i know, Symantec needs to be Configured very well ( i mean by Professionals ) to work verywell * achive Best result for Securing our Networks .
On the other hand, Documents and Manuals, are Complecate and not very simple to Undrestand for every body, so the result will be existing situation that we see ( Lot's of Complains from some Customers about Threats that Symantec can't undrestand them ).
As we know, some features like Proactive or Tracing are Unic in Symantec Antivirus if Compare it with other AV on the world. Also the SEPM Console that uses Java for new themes of Management Console, will give Admins, Lot of Very Important Info about Security Status of Hole Networks Very Fast & Easy in Brief @ one look that is Very well & Best rather than others AV's .
I belive that, Sometimes Symantec can't cach the new threats, but for me this is very Strange that, if you send that threat by Yahoo! mail Services, it will say that " This file is Infected by ***** Virus " , and as we know, Yahoo is Using Norton for Scanning file that is one of Symantec Products ...
So, i Can't Undrestand, Why Norton can get this Threat, but our Symantec Can't even undrestand it ??? Sorry, if my English is not so good.

Best Regards, J. Nourbakhsh

bjohn's picture
31
Aug
2009
0 Votes 0
Login to vote

Wait...              Were you

Wait...
             Were you praising the product or complaining about the product ? :)