8lbbrown Posted November 14, 2005 Posted November 14, 2005 Running SAV 9.0 on a networked PC, user received the following notification while working on an excel file:Symantec Anti-Virus NotificationScan Type: Auto-Protect ScanThreat: Bloodhound.Exploit.45File: C:\Windows\Temp\~DF3B02.TMPLocation: QuarantineComputer: xxxxUser: xxxxAction Taken: Qaurantine succeeded: Access deniedDate Found: Sunday, 13 November 2005 14:52:39As I understand auto-protect, this service scans files AS THEY ARE ACCESSED. (Opened, moved, copied, etc).The user was working on an excel spreadsheet, there was no other activity on the pc. No other applications in use, and a virus scan was not in progress.So what would have triggered an auto-protect notification? Does this mean that something else touched a file on the users pc? Any help appreciated,With thanks,
eyeball Posted November 14, 2005 Posted November 14, 2005 a quick google search brought this up, have a look and see if it is any use http://isc.sans.org/diary.php?storyid=835thanks
8lbbrown Posted November 14, 2005 Author Posted November 14, 2005 Thanks eyeball - it certainly looks related...But the spreadsheet is used daily (recently more than once) and has only triggered the one alert. I would have thought that every time it was used (it is used for the same tasks each time) that it would trigger the alert, for as long as the offending Symantec signatures were in use?Also, there are no graphics in the spreadsheet, so I am scratching my head to see why excel would be creating emf files?However, there has been no other suspicious activity since Thanks for your help,8lb
eyeball Posted November 15, 2005 Posted November 15, 2005 thats ok glad i could help you, stick around and if anything else crops up please post it and someone will try to help
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now