“Here you have” Virus (aka W32/VBMania@MM)

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

“Here you have” Virus (aka W32/VBMania@MM)

Not applicable

New virus, described here:

http://www.avertlabs.com/research/blog/index.php/2010/09/09/widespread-reporting-of-here-you-have-vi...

Is this virus recognized by the PAN devices?  I'm not sure how to look that up, or I would do so myself.

If not, any thoughts on mitigating risk?  I don't see .scr files in file blocking.

Thanks,

Grant

--------------

1 accepted solution

Accepted Solutions

L1 Bithead

Palo Alto Web site  >  Support  >  Threat Database
drop down and select Virus.

I was just there looking for the same thing.

View solution in original post

13 REPLIES 13

L1 Bithead

Palo Alto Web site  >  Support  >  Threat Database
drop down and select Virus.

I was just there looking for the same thing.

Thanks, it looks to me like it's not recognized.

Any thoughts on mitigation?

L0 Member

It might be listed under a different name. Trend Micro recognizes it as WORM_MEYLME.B.

Not applicable

I don't see anything on any virus. You would think you could just select from the drop down and hit enter and it would pull up a list, but I get nothing, even when I put something in there still nothing.

unfortunately, no.

if you're not seeing anything, you're doing it wrong.

type w32 , change type to virus, hit find, and see an enormous list.

This was slated to be included in last night's emergency Threat/AV content release for PAN OS 3.1.x.

PAN OS 3.0.x will be addressed with next Tuesday's content release.

I still dont see this added into the threat database...is it known by a different name in Palo Alto land?

Hi,

Coverage for "Here you have" virus is as follows:

3.1

Virus Name: Trojan/Win32.swisyn.bofj

Content release: 271 (daily content release)

Release date: 5th August


Virus Name: Trojan/W32.swisyn.bxoh

Content Release: 299-364 (Daily A/V content update)

Release Date: 10th Sep

3.0

Virus Name: Trojan/Win32.swisyn.0804

Content release: 203 (weekly content release)

Release date: 25th August

Thanks,

Sandeep

Thanks,

What about the ability to block .scr files. It seems odd to me that there is a way to custmize nearly everything but not a way to add a file extention to the picklist???

Is .scr going to be included in some future release? Or the ability for the end user to add his own file extensions for blocking?

.scr files are included in the category "Portable Executables" (aka PE).

on my firewall i created a file block rule for the PE filetype in both directions.

Message was edited by: bpappas

Apparently the PA support guy I talked to yesterday did not know this... Is this knowledge in a document somewhere?

How do we search for this? looking for VBmania, or "here you have" comes up with no results.

As much as vendors have their own names for malware, its pointless when we can't search for

it so we can let our customer know they're protected.

  • 1 accepted solution
  • 5213 Views
  • 13 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!