Virus not detecting

Anil Kumar H's picture

Thuough I submitted the infected files to symantec(  Tracking #13479960 ) on 2nd so far no virus updates are released to remove the virus. but all other antivirus applications are capable of detecting & removing the virus

Anil Kumar H's picture

download virus from this link

download virus from this link & check...

edited

check this also..

edited

Prachand's picture

The submssion that you have

The submssion that you have done is resolved.
You would have received an email regrading the same from Symantec.

Prachand Kumar
MCSE-2003 Symantec Technical Specialist (SCTS)

Anil Kumar H's picture

I got this, this means they

I got this, this means they have released the virus definitions???...but im updating daily..but still its not detecting ...when the definitions will be released..

developer notes:
 Notepad.rar is a container file of type  RAR
zaqxsw.exe Our automation was unable to identify any malicious content in this submission.
 The file will be stored for further human analysis  This file is contained by   Notepad.rar
KHATRA.exe Our automation was unable to identify any malicious content in this submission.
 The file will be stored for further human analysis  This file is contained by   Notepad.rar
Desktop.ini contains no malicious code although it can be used for malicious purposes. It is safe to delete this file.   This file is contained by   Notepad.rar
Notepad.exe Our automation was unable to identify any malicious content in this submission.
 The file will be stored for further human analysis  This file is contained by   Notepad.rar
mhyog.cmd Our automation was unable to identify any malicious content in this submission.
 The file will be stored for further human analysis  This file is contained by   Notepad.rar
AUTORUN.inF is a malformed autorun.inf file which is used by a malicious program. You should delete this.  This file is contained by   Notepad.rar
qazwsx.exe Our automation was unable to identify any malicious content in this submission.
 The file will be stored for further human analysis  This file is contained by   Notepad.rar
RESTORE.exe Our automation was unable to identify any malicious content in this submission.
 The file will be stored for further human analysis  This file is contained by   Notepad.rar
bharath-babu.exe Our automation was unable to identify any malicious content in this submission.
 The file will be stored for further human analysis  This file is contained by   Notepad.rar

Prachand's picture

It means that  the submssion

It means that  the submssion will be relooked by some engineer. as the automated process was not able to detect any malicious content in the files submitted.

Prachand Kumar
MCSE-2003 Symantec Technical Specialist (SCTS)

Anil Kumar H's picture

when all other AV detecting

when all other AV detecting it has virus Symantec should take up these things on priority...

pete_4u2002's picture

yes, i do agree with you.

yes, i do agree with you. Have you recevied another mail for this tracking number as per the mail form Prachand? Does that definition released for this threat? 

Anil Kumar H's picture

so for no definitions

so for no definitions released...when I come to office first I scan those files with latest definitions...its not at all detecting...Symantec please wake up on these calls...

if u google u can find n number of threads on khatra.exe

Prachand's picture

Title: 'What to do when a

Title: 'What to do when a competitor's antivirus, adware scanner, or spyware scanner detects a threat that Symantec AntiVirus does not detect'
Document ID: 2001101708255048
> Web URL: http://service1.symantec.com/support/ent-security.nsf/docid/2001101708255048?Open&seg=ent

Prachand Kumar
MCSE-2003 Symantec Technical Specialist (SCTS)

Prachand's picture

Plaese check this

Plaese check this

http://www.threatexpert.com/files/KHATRA.exe.html

Khatra.exe is getting detected but with diffrent NAME 

W32.Harakit [Symantec]
Trojan Horse [Symantec]

http://www.threatexpert.com/threats/w32-harakit.html

http://www.symantec.com/business/security_response/attacksignatures/detail.jsp?asid=23239

Prachand Kumar
MCSE-2003 Symantec Technical Specialist (SCTS)

Anil Kumar H's picture

please downlaod virus from

please downlaod virus from this site & run on ur machine & check...u will find the diffference, its diffenent virus

Edited - please do not post URLs to known infected files...

Prachand's picture

If that's case re submitt the

If that's case re submitt the file and log a case with Tech Support and ask the submssion to relooked

Prachand Kumar
MCSE-2003 Symantec Technical Specialist (SCTS)

Anil Kumar H's picture

I resubmitted file but I get

I resubmitted file but I get closing submission mail tat file will be kept for huma analysis...

Prachand's picture

Anil it  would be really

Anil it  would be really great if you could get a case logged in for the issue.

Prachand Kumar
MCSE-2003 Symantec Technical Specialist (SCTS)

Bijay.Swain's picture

This may be a new variant of

This may be a new variant of some threat .

Anil Kumar H's picture

atlast khatra.exe is detected

atlast khatra.exe is detected as W32.SillyFDC