Endpoint Protection

 View Only
Expand all | Collapse all

Home Anytivirus 2010

Migration User

Migration UserJul 21, 2009 12:01 PM

Migration User

Migration UserJul 29, 2009 09:22 AM

  • 1.  Home Anytivirus 2010

    Posted Jul 21, 2009 10:21 AM
    If this is posted in the wrong area I am sorry.

    Why does Symantec Endpoint not see Anything like Home Antivurus 2010 Or that older version Antivirus 2009. It would be nice if Endpoint could not only see these but fix them on the spot.

    While it's true the users click on the email or website but my question is why can't Symantec Endpoint A/V catch it?


  • 2.  RE: Home Anytivirus 2010

    Posted Jul 21, 2009 11:19 AM
    what do you mean in home antivirus 2010 and what SEP cannot see?


  • 3.  RE: Home Anytivirus 2010

    Posted Jul 21, 2009 11:54 AM
    Hi,

    all malwares are continuosly updated by their writers to be undetected. If you find some undetected variants, you have to submit them to our Security Response, call the Support for more details.

    Regards,




  • 4.  RE: Home Anytivirus 2010

    Posted Jul 21, 2009 12:01 PM
    I Agree to Giuseppe


  • 5.  RE: Home Anytivirus 2010

    Posted Jul 21, 2009 12:47 PM
    Thats the newer version of Antivirus 2009 "I did not pick the name" But I have seen it with several customers.




  • 6.  RE: Home Anytivirus 2010

    Posted Jul 21, 2009 12:51 PM
    I would agree if it was NEW, However this is not a new Virus/Malware It is old still Symantec Endpoint Did NOT catch it, like the Antivirus 2009 version. I would really like to know why.

    If you want you can email me direct on this one. steven@Deltyme.com.


  • 7.  RE: Home Anytivirus 2010

    Posted Jul 22, 2009 09:07 AM
    Did you compare the samples you have with the samples we have? Do you think the malware writers stay calm when their "product" cannot work because it is detected? They modify it until it is again not detected...


  • 8.  RE: Home Anytivirus 2010

    Posted Jul 22, 2009 09:47 AM
    Every malware have different behavior and malicious contents, malware authors create new variant every time the old one has already cured in other word the author continously develop what AV cant detect and malware exploit the vulnerability of the system.
    I suggest that  your AV is always up to date


  • 9.  RE: Home Anytivirus 2010

    Posted Jul 22, 2009 01:31 PM

    As interesting as the mechanics and history of malware is...

    Has Symantec or anyone else made any headway on a removal tool or at a least publishing a manual removal guide?

    Thanks.



  • 10.  RE: Home Anytivirus 2010

    Posted Jul 22, 2009 01:44 PM


  • 11.  RE: Home Anytivirus 2010

    Posted Jul 28, 2009 10:03 AM
    Has Symnatec created a removal tool for this Home Antivirus 2010, I have not done anything yet to remove it and Endpoint can't even find it.

    Please let me know ASAP

    Thank You


  • 12.  RE: Home Anytivirus 2010

    Posted Jul 28, 2009 10:52 AM
    Did you send us the viral sample as suggested above?

    Regards,



  • 13.  RE: Home Anytivirus 2010

    Posted Jul 29, 2009 09:22 AM
    what viral sample are you looking for


  • 14.  RE: Home Anytivirus 2010

    Posted Jul 31, 2009 06:27 AM
    Hi,

    to detect a malware not already detected we need a sample of it. Did you already find in your machine any suspicious files that run the malware?

    If you are not able to find it, you can call our Technical Support to obtain help on this.

    Regards,


  • 15.  RE: Home Anytivirus 2010

    Posted Jan 26, 2010 02:54 PM
    Without discussing the malware in a specific manner, one issue is this: 

    This malware in particular I have seen change the userinit.exe link for login.  One version changed the userinit.exe to wsausupdater.exe.  What this means is that IF an AV program just deletes the EXE file without first repairing the registry link that has been changed, the client computer will no longer have login's work.  This can be fixed of course with a Bartpe CD or a remote registry editor, but it does kick the level of complexity up much higher to resolve the workstation.

    So the question for Symantec would be:  How do you handle that type of malware that changes the userinit.exe setting in the registry.  Is the SEMP product sophisticated enough to fix that registry link without just deleting the bad EXE file?




  • 16.  RE: Home Anytivirus 2010

    Posted Jan 26, 2010 03:01 PM
     Yes..Symantec is seeing this old trick from long time..Certified definitions for Symantec will be able to repair it.However RapidRelease Def might delete that entry..As I had faced similar issue 2-3 yrs back.


  • 17.  RE: Home Anytivirus 2010

    Posted Jan 26, 2010 03:07 PM
    Obviously that would be an advanced FAQ but it would be helpful to have out there.