Comprehensive Protection: Secure your business from known and unknown threats.
Symantec.com > Enterprise > Security Response

Security Response

Our security research centers around the world provide unparalleled analysis of and protection from IT security threats that include malware, security risks, vulnerabilities, and spam.
Help us improve this website: Take our Security Response User Experience Survey.
90 Day Global Threats, Risks, and Vulnerabilities Timeline
90 Day Global Threats, Risks, and Vulnerabilities Timeline
90 day view of discovered Threats, Security Risks and announced Vulnerabilities brought to you by the DeepSight Threat Management System
RiskThreatVulnerability
Most Active New Threats
Most Active New Threats
Newly discovered threats that Symantec has blocked from customer machines.
Subscribe
NameTypeProtected*Discovered
W32.Pilleuz!gen31Worm02/07/201202/08/2012
Trojan.Zbot!gen30Trojan Virus02/07/201202/06/2012
Infostealer.OffsuploadTrojan02/07/201202/06/2012
W32.BegmianWorm02/07/201202/05/2012
Android.BmasterTrojan02/03/201202/03/2012
Trojan.Zeroaccess!gen8Trojan02/02/201202/02/2012
W32.Pilleuz!gen30Worm02/01/201202/01/2012
Trojan.Zatvex!gen4Trojan02/01/201202/01/2012
SecShieldFraud!gen3Misleading Application02/02/201202/01/2012
W32.FacedrestWorm01/30/201201/29/2012
*For continued protection, make sure that your Symantec subscription and/or license are up to date.
Threat Spotlight: Trojan.
Zeroaccess

Trojan.Zeroaccess is a Trojan horse that uses an advanced rootkit to hide itself. It is often installed through drive-by-download attacks from sites hosting the Blackhole exploit kit. The Trojan can also create an encrypted, hidden file system, download more malware, and open a back door on the compromised computer.


The Trojan is called ZeroAccess due to a string found in the kernel driver code that is pointing to the original project folder called ZeroAccess. It is also known as max++ as it creates a new kernel device object called __max++>.


More information on Trojan.Zeroaccess is available in the threat family writeup.

Best Practices
IT Security Threats With the rapid rise in the number of malware attacks it’s harder than ever to prevent machines from getting infected. But have you done everything you can do? Have you done the things you must do to stay protected? Following some simple best practices can make a tremendous difference in improving your protection. Symantec has assembled a set of best practices for today’s threat landscape.

Use these recommendations to know what you must, should and can do to protect your endpoints from malware.

Want to go further and really beef up protection on your endpoint machines? Symantec Endpoint Protection has a feature called Application and Device Control that gives you additional tools to protect your endpoints. Find out about Application and Device Control and download rulesets especially created by Symantec to increase your protection. Information available here.
White Paper Spotlight
W32.Qakbot is a worm that has been seen spreading through network shares, removable drives, and infected webpages, and infecting computers since mid-2009. Its primary purpose is to steal online banking account information from compromised computers. The malware controllers use the stolen information to access client accounts within various financial service websites with the intent of moving currency to accounts from which they can withdraw funds. There are several information stealing Trojans found in cyberspace today. What makes Qakbot stand apart from most of the others is sophistication and continuous evolution. The purpose of this white paper is to provide an insight into the worm's capabilities.

Download the full 'W32.Qakbot in Detail' white paper.

View the full set of Symantec Security Response white papers.


Stay Secure



Be Informed about IT Threats



Contact Security Response

ThreatCon

Level 1: Normal

Level 1: Normal

Learn more about threat levels

Threat Intelligence

Subscribe
Infostealer.Offsupload uploads 20000+ archives of stolen data to file sharing site  http://t.co/5BBG51Go #Trojan
2 hours ago
#Android.Bmaster - Botmaster's profits exposed  http://t.co/P8jOQP37 #malware
6 hours ago
Server-side Polymorphic #Android Applications  http://t.co/36b9ZQdW #malware
02-02-2012 1:40 AM
 
STAR Antimalware Protection Technologies
Prevent Information Loss and Theft: Let Symantec help protect your business.  Shop Now