Endpoint SWAT: Protect the Endpoint Community

 View Only
  • 1.  Trojan.Poweliks: A threat inside the system registry

    Posted Nov 03, 2014 03:32 AM

    According to the article : https://www-secure.symantec.com/connect/blogs/trojanpoweliks-threat-inside-system-registry  there are 2 IPS signatures available listed as the folllowing:

    Intrusion Prevention
     

     

    I have located both signatures in SEP 12 except that System Infected: Trojan.Powelik Activity is not available in SEP 11.  Does anyone know if this is only applicable to SEP 12 and not SEP 11 for this definition.?

    Thanks

     



  • 2.  RE: Trojan.Poweliks: A threat inside the system registry

    Posted Nov 03, 2014 03:59 AM

    Yes it can applicable in 11.x as well

    http://www.symantec.com/security_response/definitions/multipledaily/detail.jsp?mdid=2014-08

    http://www.symantec.com/security_response/writeup.jsp?docid=2014-080408-5614-99

    Trojan.Poweliks Trojan 08/03/2014

    Supports the following versions of Symantec antivirus software:

    • Norton AntiVirus / Norton Internet Security (later than 2012)
    • Norton AntiVirus / Norton Internet Security 2008/2009/2010/2011/2012
    • Norton 360 (later than 6.0)
    • Norton 360 version 2.0/3.0/4.0/5.0/6.0
    • Symantec Endpoint Protection 11.0
    • Symantec Endpoint Protection Small Business Edition 12.0
    • Symantec Endpoint Protection 12.1
    • Symantec Protection Engine 7.x for Windows


  • 3.  RE: Trojan.Poweliks: A threat inside the system registry

    Posted Nov 03, 2014 05:11 AM

    @AJ_01 - How come the one signature it isn't displayed on the IPS signatures list on SEP 11 console?



  • 4.  RE: Trojan.Poweliks: A threat inside the system registry

    Posted Nov 03, 2014 06:28 AM

    That's interesting, should be available for both. May want to check in with support.



  • 5.  RE: Trojan.Poweliks: A threat inside the system registry
    Best Answer

    Posted Nov 03, 2014 06:43 AM

    Seen that behavior before on a SEPM on v.11 with other IPS signatures. Agree with .Brian, but would certainly be moving any SEP 11 client to a SEPM on 12.1.5. January 05th, 2015 is fast approaching....



  • 6.  RE: Trojan.Poweliks: A threat inside the system registry

    Posted Nov 03, 2014 07:59 AM

    Already started doing that. Thanks. Customer informed that SEP 11 needs to be either removed from environment or upgrade to SEP12.



  • 7.  RE: Trojan.Poweliks: A threat inside the system registry

    Posted Nov 11, 2014 07:05 AM

    Just a quick note that may be of interest to those who find this thread via a search: Symantec now offers a tool that can help, in addition to our AV and IPS signatures.

    Trojan.Poweliks Removal Tool
    http://www.symantec.com/security_response/writeup.jsp?docid=2014-111020-0511-99

    Hope this helps! &: )

    Mick