|
|||||||
|
IT sounds like you know you have a virus but those are not the correct install directories for google talk or skype so you know you have a problem right there. Also do you allow such applications in a business environment? IF you did not (I am guessing this si the case) then that should be a red flag right there. Vague questions receive vague answers . . . . . .
|
|
| 03-29-2012, 06:26 AM | |
|
|
|
As for patching java and flash, this may force us to change our policy of testing before releasing the patches. They will need to figure out which is worse; an update that breaks an application or something getting through. Thankfully it appears to only be an annoyance at this point. |
|
|
Ya it is kind of a different security model in today's world of 0 day exploits. Policy and training can help this along though. The model of don't install it if you don't need it helps a lot. Making users run as not admin helps. If you have to use IE, enforce it for internal use only. Use Firefox or Chrome or IE9 for actual web browsing. Apply updates very shortly after they are out. This is really true with security related updates. |
|
|
|
|
|
|
|
About the only thing we have found out so far is that someone else submitted the file to virscan.org on the 15th of this month (matching MD5 hash). I rescanned it there and it again passed all 36 virus checks.
Our fingerprint block is working. People get a message that "the handle is invalid" if they (for some reason) manually launch the file. Hopefully there isn't something else we haven't found. |
|
Are your users set up as admins or power users?
As far as the updates to Adobe Reader, Adobe Flash and Java -- these updates are "usually" tested pretty well before they are put out, so I would not be too worried about "testing" them before you deploy. There is a great deal of push to get these updates installed ASAP due to exploits in the older versions, and I think Adobe and sometimes Java take a little too long to get the newer update out that blocks the concern for the people. This gives a BIG window for hackers to do their thing and take advantage of the holes. Get Ccleaner Slim with no toolbar [ccleaner.com] You will still need to uncheck all the extra shortcuts you don't need . . . Be sure to update before running it.
Get Malwarebytes free edition [cnet.com] Be sure to update before running it. Get SuperAntiSpyware free edition (SAS) [cnet.com] Be sure to update before running it. |
|
I know you are zoned in on one issue, but we need more info on what the users are allowed to do and what they are not allowed to do. If you have an office full of admins who can install software, download whatever they want and go wherever they want with no firewall rules to block things, then you need to go back to basics and start locking down the network to keep your people from doing whatever they want on your system. You can't keep nasties out, even with virus protection, if your users are allowed to do whatever and go wherever.
It's NOT their computer -- it's the computer they USE at work, for work purposes only. If you have people accessing their personal email accounts and visiting Facebook or other social sites, they can click on whatever link and infect your network pretty quickly. Virus protection cannot stop users who get a pop up and click on it and allow something to be loaded. It may detect it, but it won't stop the download of an infection it doesn't have it in it's definitions, or if the user just cancels out when something is found because they can and they are annoyed with it and want to go on with their day. Is your virus protection set to update several times during the day, or just once a day, or once a week, or ? |
|
No word from Symantec yet. No more reports of slow systems since implementing the fingerprint block. Our logs do not show any unusual traffic through our firewall. We are continuing to watch the situation though.
With a few individual exceptions, social media sites are blocked. File sharing sites are blocked. While we do not disable downloads, everything is automatically scanned by our anti-virus software. I've been told our anti-virus is set to check every two hours for updates and it pushes them out when we receive them. |
|
sounds like bad files to me..
always be suspicious of odd files stored or loaded from user profile directories (especially if 'directory' in OP sample path is random or gibberish), and i don't think EXEs of these names belong in the same folder nor should they be binary identical. When you buy more, you save more. And when you save more, you can buy more.
And when you buy more, you save more. It all starts when you BUY MORE. Posting or uploading a picture? Meet your new best friend! [codeplex.com] |
|
Have you tried submitting the file to us on our malwarebytes forums?
http://forums.malwarebytes.org/in...owforum=51 We can get it added in hours if you submit it. We update 5-7 times a day. Drop me a pm on the forum and i will look at it as soon as possible. Last edited by shadowwar; 04-06-2012 at 03:50 PM.. |
|
Update: Symantec finally added it to their signatures as a Trojan.Gatak!gen2 threat over the weekend. I've been getting notices every few minutes whenever it finds a neutered* copy on my system.
*fingerprint block prevented it from executing in Symantec Endpoint Protection. Interesting to note the Symantec link to the risk worked earlier today but isn't working at the moment. Guess they took it down to rewrite it. Edit: Link is back now. [symantec.com] Mostly useless info though. Last edited by marg_fan; 05-15-2012 at 05:21 AM.. Reason: Added link |
| Thread Tools | Search this Thread |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Create Recovery/Boot Partition? Is it possible? | kpatel1 | Tech Support | 7 | 04-05-2012 12:56 AM |
| Look out for a new virus email!!!!!!!!!!!!!! | -Shadow | Tech Support | 7 | 02-22-2012 08:48 AM |
| Norton disables itself completely after one year | boltman2007 | Tech Support | 21 | 04-13-2011 03:58 PM |
| Use an old HDD as primary on a new PC, possible? | slimwantsfat | Tech Support | 37 | 03-18-2011 09:52 AM |
| Removing viruses tip | callpocket | Tech Support | 3 | 10-24-2010 06:37 PM |