Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 14th, 2007, 08:35 PM
irrationalgeek irrationalgeek is offline
Infrequent Poster
 
Join Date: Jul 2007
Posts: 35
Default SAS Misses Detection of Worm-Win32/Winko.A

Can SAS have an update so that it can remove the Worm-Win32/Winko.A malware please?

CounterSpy: http://research.sunbelt-software.com...hreatid=153652

Mcafee: http://vil.nai.com/vil/content/v_142642.htm


__________________
AV: Kaspersky Antivirus 7
AS: SAS Pro 3.9, CS 2.5


Last edited by irrationalgeek : August 14th, 2007 at 08:42 PM.
  #2  
Old August 14th, 2007, 08:50 PM
lodore lodore is offline
Incredibly Massive Poster
 
Join Date: Jun 2006
Posts: 8,876
Default Re: SAS Misses Detection of Worm-Win32/Winko.A

hello irrationalgeek,
why dont you submit a support ticket?
http://www.superantispyware.com/csrcreateticket.html
does kaspersky detect that worm?
if not can you please sent it to kaspersky so they can update there bases.
the email address is below.
newvirus[AT]kaspersky.com
it might already be the in kaspersky definitions already thou.
has that worm infected your computer?
lodore
__________________
useful tools:cure it SAS Hitman Pro mbam KL Eset windows defender offline Sophos
  #3  
Old August 14th, 2007, 08:55 PM
irrationalgeek irrationalgeek is offline
Infrequent Poster
 
Join Date: Jul 2007
Posts: 35
Default Re: SAS Misses Detection of Worm-Win32/Winko.A

Yes. I've submitted a support ticket, thing is the infection is on a computer that I just can't get to right now.

If I could I'd do a scan with Kaspersky on it too.
__________________
AV: Kaspersky Antivirus 7
AS: SAS Pro 3.9, CS 2.5

  #4  
Old August 14th, 2007, 08:58 PM
lodore lodore is offline
Incredibly Massive Poster
 
Join Date: Jun 2006
Posts: 8,876
Default Re: SAS Misses Detection of Worm-Win32/Winko.A

oh i understand the situation now.
even drweb cure it might be able to remove it
link in my sig.
shame avptool isnt final yet.
lodore
__________________
useful tools:cure it SAS Hitman Pro mbam KL Eset windows defender offline Sophos
  #5  
Old August 14th, 2007, 11:38 PM
irrationalgeek irrationalgeek is offline
Infrequent Poster
 
Join Date: Jul 2007
Posts: 35
Default Re: SAS Misses Detection of Worm-Win32/Winko.A

Completed online diagnostic. Now waiting to see if there are new signatures that enable SAS to remove this annoying worm.
__________________
AV: Kaspersky Antivirus 7
AS: SAS Pro 3.9, CS 2.5

  #6  
Old August 15th, 2007, 02:35 AM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,412
Default Re: SAS Misses Detection of Worm-Win32/Winko.A

I used SAS some time ago and I noticed its worm detection was not so good( very brief experience). Can anybody confirm this?
__________________

Ubuntu 12.10
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #7  
Old August 15th, 2007, 02:57 AM
EASTER's Avatar
EASTER EASTER is online now
Massive Poster
 
Join Date: Jul 2007
Location: U.S.A. (South)
Posts: 4,517
Default Re: SAS Misses Detection of Worm-Win32/Winko.A

Quote:
Originally Posted by aigle
I used SAS some time ago and I noticed its worm detection was not so good( very brief experience). Can anybody confirm this?

Don't forget even though SAS picks up even some databased viruses/worms, it is NOT an Anti-Virus. Your AV should have alerted to it and even a HIPS! will jump up an ALERT on anything strange or new.

Regards EASTER
__________________
★AX 64 Time MachineCurrent Version 1.1.0.996 ★
★Shadow Defender★| EQSecure v4.0 Beta3 |#Sandboxie 4.08 beta# |FirstDefense-ISR|★FileChangeAlarm★ |Reserve Space|
Maxthon 4 | X Iron 17.0 | Chromium 19.0 | Pale Moon 20.1

Microsoft Windows 8 64bit (UEFI/GPT) Secure Boot¶
¶Linux Mint 14 MATE¶
  #8  
Old August 15th, 2007, 03:41 AM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,412
Default Re: SAS Misses Detection of Worm-Win32/Winko.A

In my experience, worms are most common threat in the area I live, esp the USB worms. It,s nice to have an added layer for them. I am saying it for ordinary users who use only signature based security. I someimes install AV for some of people who don,t know anything about malware and I thought of adding SAS free but it lacks worms/ trojan detection. AVG AS detects most worms/ trojans so I will prefer that for ordinary users.

I am not sure about BOClean but it too lacks detection of worms I think. Anyone?

In the end, I have no choice except for an AV only when I have to set-up free security for an ordinary user. They can,t use non-sig based security. Even the popup of an AV might be confusing for them.

Personally If my AV does miss a worm, no problems, I am sure I can catch it via my Sandbox/ HIPS/ CH etc.
__________________

Ubuntu 12.10
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #9  
Old August 15th, 2007, 04:46 AM
GES/POR's Avatar
GES/POR GES/POR is offline
Very Frequent Poster
 
Join Date: Nov 2006
Location: Armacham
Posts: 1,476
Default Re: SAS Misses Detection of Worm-Win32/Winko.A

Never come in contact with worms at least not that i know off but seen many trojans and offcourse spyware on others pc's.
  #10  
Old August 15th, 2007, 04:55 AM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,412
Default Re: SAS Misses Detection of Worm-Win32/Winko.A

I think it depends upon the location one lives.
In my area I see Brontok USB worm very common with some other worms and trojans.
__________________

Ubuntu 12.10
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #11  
Old August 15th, 2007, 05:00 AM
GES/POR's Avatar
GES/POR GES/POR is offline
Very Frequent Poster
 
Join Date: Nov 2006
Location: Armacham
Posts: 1,476
Default Re: SAS Misses Detection of Worm-Win32/Winko.A

Kind of common spread malware depends on culture?
  #12  
Old August 15th, 2007, 01:11 PM
fcukdat's Avatar
fcukdat fcukdat is offline
Malware Researcher
 
Join Date: Feb 2005
Location: England,UK
Posts: 569
Default Re: SAS Misses Detection of Worm-Win32/Winko.A

Quote:
Originally Posted by irrationalgeek
Can SAS have an update so that it can remove the Worm-Win32/Winko.A malware please?

CounterSpy: http://research.sunbelt-software.com...hreatid=153652

Mcafee: http://vil.nai.com/vil/content/v_142642.htm



If you don't get your update as quick as you need it then maybe since CounterSpy offers a free time limited trial of its software then this would be an option in your cleaning of the infected PC.

HTH
__________________
Ade Gill
Malwarebytes Researcher
  #13  
Old August 15th, 2007, 11:14 PM
irrationalgeek irrationalgeek is offline
Infrequent Poster
 
Join Date: Jul 2007
Posts: 35
Default Re: SAS Misses Detection of Worm-Win32/Winko.A

Quote:
Originally Posted by fcukdat
If you don't get your update as quick as you need it then maybe since CounterSpy offers a free time limited trial of its software then this would be an option in your cleaning of the infected PC.

HTH

Also have a license of CS so I installed it and got rid of the worm. Hope the updated signatures with removal of Winko.A are close though.
__________________
AV: Kaspersky Antivirus 7
AS: SAS Pro 3.9, CS 2.5

 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 12:30 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums