Virus/Spyware Foool.exe not Detected by SAVCE 10.2 - Symantec Removal Tool for this virus not found
Hi.
Recently we found in almost 10 PC, the Foool.exe virus, but SAVCE never detected it.
(it was detected by tools/instructions like: http://www.prevx.com/filenames/842274819921361408-0/FOOOOL.EXE.html)
http://www.incodesolutions.com/threats/System32Rootfoooolexe.php
General Description:
Is a potentially dangerous virus.....
This Process Deletes Other Processes From Disk ....
Fooool.exe does appear to be related to an infection, and the symptoms are as you describe: it puts a Fooool.exe in the root of every (removable) drive, and an AUTORUN.INF. It corrupts Explorer.exe and it makes some Registy entries pointing to the infected files.
The question is: Why Symantec hasn`t any information about this Virus?
When Symantec will develop a tool ...?
Thanks...?
Comments
May be a new variant of an existing threat or a new threat that we haven't come across yet or maybe we have detected it and definitions are being created as I type this.
Either way please submit potentially infected files to Symantec Security Response for analysis. If it is found to be a new threat/variant, definitions will be created to remove it.
Security Response's Submission URL:
https://submit.symantec.com/gold
Hope that helps!
Yep that is the way. You will have to submit to Symantec and they will do the reactive support for you. :smileywink:
Thanks you very much, David for your fast and kindly answer.:smileyhappy:
My client - knows the link..but the virus was removed by the mencioned tools, because it was the priority for him.
There are many articles in the internet about this virus....
I think an antivirus company must to pay attention to this virus advices...and to make its own research, independently of the clients threat sending (or not) by the Security Response's Submission URL.
Anyway, im very grateful to you.
http://forums.mcafeehelp.com
http://forums.mcafeehelp.com/showthread.php?p=506857
it will definately work..!!
Would you like to reply?
Login or Register to post your comment.