Viruses Detected by Norton but not eTrust

Discussion in 'other anti-virus software' started by SonicMonkey, Jun 14, 2004.

Thread Status:
Not open for further replies.
  1. SonicMonkey

    SonicMonkey Registered Member

    Joined:
    Jun 9, 2004
    Posts:
    17
    I was on a computer that was acting strange. It was loaded with etrust inoculateIT so I ran a full scan. It found nothing. Then I ran a Norton A/V Web search and it turned up 4 viruses! AS far as I can tell the etrust definitions are up to date. What do you make of this? is it normal for there to be a large difference in detection?
     
  2. bigc73542

    bigc73542 Retired Moderator

    Joined:
    Sep 21, 2003
    Posts:
    23,873
    Location:
    SW. Oklahoma
    go to the online scans link in my signature and run an online scan or two and see what the results are. I would suggest useing trend micro house call and command on demand scans. that way you can confirm or deny the existence of the viri.
     
  3. solarpowered candle

    solarpowered candle Registered Member

    Joined:
    Jan 9, 2003
    Posts:
    1,181
    Location:
    new zealand
    I did not think that e trust had any scanners that operated only with InoculateIT any more (all support for Inoculan/InoculateIT 4.x has been discontinued since march 17 2004 )

    exceptions to that are Inoculan v4.x for Netware. and Inoculan v4.x Exchange Antivirus Option on Microsoft Exchange 5.5 and ArcServe 2000/Inoculan 4.x bundle customers till the end of the year. But if its a home pc its not likely it would fallinto that . Perhaps the pc hasnt been updated for some time now . The latest InoculeITsigniture version is 23.65.40 ( 15/06/2004)
    http://www3.ca.com/support/vicdownload/

    E trust 6.2 is the newest engine and version and that contains Vet . They seem to be using Vet now in preference to inoculateIT in therir latest anti virus solutions or offerings.
     
    Last edited: Jun 15, 2004
  4. bigc73542

    bigc73542 Retired Moderator

    Joined:
    Sep 21, 2003
    Posts:
    23,873
    Location:
    SW. Oklahoma
    The early version 6 still just has the inoculate engine, it just updates with the same defs as inoculate in version 7 with both engines.
     
  5. SonicMonkey

    SonicMonkey Registered Member

    Joined:
    Jun 9, 2004
    Posts:
    17
    I have to go back to the comp to make sure, But Under the Help menu > About it says InoculateIT version 6. Also it should be noted that this software was loaded by the owner's company which uses etrust. I did see something about the Vet engine. I have to go and fool around with it some more. Also I will run those other online viri scans.
     
  6. Arin

    Arin Registered Member

    Joined:
    May 1, 2004
    Posts:
    997
    Location:
    India
    dear SonicMonkey, its a great ID. i think you are a fan of Monkey's Audio. anyway it'd be nice if you mention the names of those viruses and the infected files.
     
  7. SonicMonkey

    SonicMonkey Registered Member

    Joined:
    Jun 9, 2004
    Posts:
    17
    Thanks, actually I got the name from the movie Hi Fidelity with Jack Black when he names his band the Sonic F@#king Death Monkeys. Pretty funny stuff. Anyways, here are the viri norton online scan found:

    W32.Bizten
    Trojan.StartPage
    Trojan.Startpage (again)
    Download.Trojan

    None of these I think are real serious unless Download.Trojan downloads another one. I haven't gotten the chance to run the other scans someone above recomended, but I will.

    Another INteresting point: One of those messenger windows popped up and told me that Backdoor.SDBot.Server.Variant was on the computer. Now this is a potentially serious virus, but I can't tell if this warning was actually messenger spam or from etrust since Norton Didn't find it. I have since disabled messenger service and will see if it pops up again.
     
  8. solarpowered candle

    solarpowered candle Registered Member

    Joined:
    Jan 9, 2003
    Posts:
    1,181
    Location:
    new zealand
    Thanks for posting those . As far as I can see e trust does cover the following .
    Trojan.StartPage
    Also known as: W32/Cardown.A (F-Secure) , Win32/Cardown.Trojan , Trojan.StartPage (Symantec), TROJ_STARTPAGE.Q (Trend), Trojan.Win32.StartPage.y (Kaspersky)
    E trust know it as Win32.Startpage.G Description Published: October 3, 2003 http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?ID=37230

    Download Trojan http://www3.ca.com/securityadvisor/virusinfo/search.aspx?mode=tmc&pst=Download.Trojan
    This is also covered by e trust . and its 19 aliases

    Trojan.Win32.Bizten is not as far as im aware on e trust list ( unless its using another name than what semantics uses , however I think its spyware and more of a browser hijacker . The sort of stuff javacools BHO or spybot would take care of .

    Backdoor.SDBot.Server. also on e trust list and its 2 Aliases
    Perhaps it may be worth checking the settings on the pc for e trust and that the hueristics are checked and that the real time monitor has allowed pop up notification for any virus .(this is allowed by the default settings but may have been altered. ) One of the nice things about etrust v7 is that it has 2 engines (vet and inoculateIT) one can be used as the real time monitor and the other as the local scanner , giving one that extra security . good luck sonic.
     
    Last edited: Jun 16, 2004
Loading...
Thread Status:
Not open for further replies.