Hi all,
today my customer send me his finding based on their forti team (i dont know if its fortigate or fortinet )
and he asked me if Torpig.Mebroot.Botnet.Replaced can be detected and clean / delete / quarantine by mcafee ENS 10.7 or ATP?
i tried to search from kb and forum but there's no valid article about this,(usually my customer satisfied when i give it to them the kb with minimum amcore or ens version can defend against malwares)
need help about this (article or kb)
Thanks
Solved! Go to Solution.
Hello @Dwee
Thank you for reaching out with your query, ENS: 10.7 along with ATP does have the capability to detect malicious trojans, malware, viruses, etc, provided it has signatures at the Artemis, in case if there are no detections, then we would review the samples and work internally to help you with Extra.dat and coverage details.
Do you have any MD5 hash associated with this malware, if yes, I can provide you some more information on detection details?
I would also suggest you raise a Service Request with McAfee by selecting Malware as a point product and submit samples, MD5's to labs by following https://kc.mcafee.com/corporate/index?page=content&id=KB68030 so that one of our TSE's would be able to review and analyze the sample in the database and assist you further in getting more information on the Torpig.Mebroot.Botnet malware.
Thanks
Hello @Dwee
Thank you for reaching out with your query, ENS: 10.7 along with ATP does have the capability to detect malicious trojans, malware, viruses, etc, provided it has signatures at the Artemis, in case if there are no detections, then we would review the samples and work internally to help you with Extra.dat and coverage details.
Do you have any MD5 hash associated with this malware, if yes, I can provide you some more information on detection details?
I would also suggest you raise a Service Request with McAfee by selecting Malware as a point product and submit samples, MD5's to labs by following https://kc.mcafee.com/corporate/index?page=content&id=KB68030 so that one of our TSE's would be able to review and analyze the sample in the database and assist you further in getting more information on the Torpig.Mebroot.Botnet malware.
Thanks
Hi ZeeArhaan,
thanks for your reply, usually from the forti already being dropped /deleted/cutoff (all malicious traffic or data) so parallel ill try ask for it, but generally from your access as Mcafee employee can you search it internally if mcafee ENS already can block or defend againts this malware (torpig) ? try Torpig keyword
thanks
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.
Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership: