I've run into yet another instance of symantec doing what it does best... and that is suck.
When one of my users emails me saying they have a virus... I hope for the best, maybe it's just a spoof IE pop up or something harmless. We spend $2000 per year on our symantec endpoint security renewal so... hell, it should work right?
WRONG. I spent 30 minutes messing with this girls computer and had to grab a spare computer to put her on because it's going to take a good amount of time to get her system back up and running without this Personal Anti virus BU#$@*U( which has disabled task manager and regedit from running.
When I have a virus, my first course of action shouldn't be to install another anti virus product if i already have one that cost $2000. Symantec sucks... that is the point of this thread. Your product is meaningless if it can't do it's job.
End Solution?
I'm switching to VIPRE by sunbelt software for $10 per seat for 50 seats. So instead of $2000 it's going to be $500 and it's actually going to work as opposed to this crap symantec is selling.
You can't pin it all on the AV. Nothing is going to catch everything. Users have to show some intelligence and discretion when on the net. Norton internet security 2009 is one of the best IMO. I've used Norton 360 for 2 years and haven't had any issues.
You can switch. That's your choice. That doesn't mean it'll be better.
5 rogue security applications : fraudtool.win32 and advancedvirusremover
1 backdoor bot
2 trojans
33 traces of virtumonde adware/malware
We use opendns which helps some w\ people browsing to random internet sites.
Anyhow. Full scan w\ vipre antivirus+antispyware, reboot and everything is fine.
Symantec = "quarantine" reboot, infection still rampant.. popups all over the place, need to download another program to remove the infections !
This was the same thing w\ my moms computer last month... i think she was using norton 2007 or something and had a similar fake antivirus virus take over her system... loaded up vipre and bam... all better.
"Symantec's antivirus engine gets very high marks from all the independent testing labs. Both West Coast Labs and ICSA Labs certify it for virus detection and cleaning; West Coast Labs adds checkmark certification for Trojan detection. Symantec has passed all of the last 10 Windows-based VB100% tests from Virus Bulletin—in fact, the last time it failed was in 1999. BitDefender, Kaspersky, and McAfee all failed to achieve VB100% in at least one of the last 10 tests; Trend Micro Internet Security Pro v2 no longer participates in this test.
Austrian test lab AV-Comparatives gave Symantec an ADVANCED+ rating (the highest) in its most recent eval of on-demand virus scanning. In the lab's proactive non-signature-based test, Symantec rated ADVANCED, with few false positives. Kaspersky matched those results while ESET flipped them—it got ADVANCED+ for proactive detection and ADVANCED for signature-based detection.
Magdeburg-based AV-Test rated Symantec Very Good (the highest rating) in four categories: detection of malware, low false positives, fast scanning, and fast response to new malware. It also rated Symantec Good for detection of adware/spyware and proactive detection of new, unknown threats. All of the other vendors I've reviewed scored Satisfactory or lower in at least one category. These independent labs results indicate that Norton 360's antivirus component is top-notch."
Message edited by aford10 on 09-18-2009 at 08:43:11 PM
"Kaspersky detected 88 percent of the malware samples. That's decent, but the beta version of Norton Internet Security 2010 detected 97 percent. Kaspersky left behind many EXE files and tons of nonexecutable malware traces, scoring 6.7 of 10 possible points—a hair below average.
In a parallel test using commercial keyloggers, Kaspersky scored 1.6 points, even lower than the 1.8 attained by the beta of Microsoft Security Essentials. Fortunately for Kaspersky, I give much less weight to this test.
I broke out separate scores for removing rootkits (both malware and keyloggers) and scareware. The average in both cases is 5.6 points; Kaspersky came in below that with 5.1 points against rootkits and 3.0 points against scareware."
look at this
ico Online Armor Personal Firewall 3.5.0.14 99% 10+ Excellent GET IT NOW! pdf
ico PC Tools Firewall Plus 6.0.0.69FREE 99% 10+ Excellent GET IT NOW! pdf
ico Comodo Internet Security 3.11.108364.552FREE 97% 10+ Excellent GET IT NOW! pdf
ico Kaspersky Internet Security 2010 9.0.0.459 96% 10+ Excellent GET IT NOW! pdf
ico Outpost Firewall Free 2009 6.5.2724.381.0687.328FREE 93% 10+ Excellent GET IT NOW! pdf
ico Outpost Security Suite Pro 2009 6.5.4.2525.381.0687 92% 9 Excellent GET IT NOW! pdf
ico Online Armor Personal Firewall 3.5.0.14 FreeFREE 92% 10+ Excellent GET IT NOW! pdf
ico Jetico Personal Firewall 2.0.2.8.2327 89% 10+ Very good N/A pdf
ico Malware Defender 2.2.2 89% 10+ Very good GET IT NOW! pdf
ico Privatefirewall 6.0.20.14 88% 10+ Very good N/A pdf
ico Netchina S3 2008 3.5.5.1FREE 85% 9 Very good N/A pdf
ico ZoneAlarm Pro 8.0.059.000 72% 9 Good Not recommended pdf
ico Lavasoft Personal Firewall 3.0.2293.8822 67% 8 Good Not recommended pdf
ico Norton Internet Security 2009 16.2.0.7 66% 8 Good Not recommended pdf
So, the system in question that prompted this thread was cleaned on thursday w\ Vipre. after rebooting and rescanning, nothing was found and all seemed well. I gave this poor girl her computer back mid way through thursday and I had friday off.
So, on friday somehow this girls computer is infected again... I don't know what happened because my co worker pulled it offline, and re-installed the old version of symantec we have because I guess she didn't remember where our new install is? idk... anyhow. I ran vipre and it came up w\ the Virtumonde again, and a new fake av program, or maybe it morphed... idk.
I didn't clean w\ vipre because I wanted a comparison w\ symatec. I did a full scan w\ symantec which today I see ran 411 minutes, almost 7 hours and found less than the 5 minute vipre quick scan. but anyhow, symantec said it had cleaned by deletion a few items and so I reboot only to find that the system is as infected, or maybe worse. Upon hitting ctrl alt del, the wallpaper is a poorly worded warning that the computer is infected " Your're computer is infected!" your're, really?
booting into safe mode at this point yields a blue screen of death! nice. After a couple reboots I managed to get task mgr opened fast enough and open msconfig to stop all startup programs and rebooted again and that's where I'm at now. Vipre is running a full scan and has found :
I'm going to let vipre do its thing AGAIN... and see where we're at. This system has already passed it's antivirus life cycle w\ me though... if I spend any more time messing w\ viruses on it I may as well just reinstall windows as it will be quicker and I can be pretty sure everything is working fine.
I agree. But I needed to rant at the time I created this thread. I just think that for the amount of money we paid for the symantec endpoint, that it should be more effective. I shouldn't have to download free ware or other AV programs if I've got one that I paid $2000 for.
I just got a new quote from vipre today. $1095 for 3 years (50 licenses) + 50 licenses for home users so employees can also put it on their home computers.... compared to $2000 per year for symantec this is just phenomenal.
I would caution tho, I've seen AV's throw up this list of malware that they've found and it was all BS. It just makes them look better if they find some pretend malware and clean it up.
Not saying Vipre is, just throwing that out there.