SAV Corporate Edition detected as PWS.Bancos.A Password Stealer

B

Bill Sanderson

The false positive is fixed by defintions 5807, available at about 3 PM
2/10/2006, US Eastern standard time.

--
 
G

Guest

MS has fixed this issue. Update the virus definition to 5807 and it should
work. However, you may have to update it 2-3 times for it to take effect
[don't ask me why :)]...I had to do it twice for it to reflect the correct
version.

Once you have version 5807, the pws.bancos.a issue ceases.
 
G

Guest

As you said, I was able to get my SAV working again after going back to the
restore point prior to the problem. Now, the only problem remaining is that
the "File system realtime protection" doesn't seem to be working.

The news articles say the symantec and microsoft came up with a tool to fix
the problems, but I cant find out anything on either vendor's websites.
 
B

Bill Sanderson

If you phone Symantec's support, they should be able to help you out, and it
shouldn't be a paid support call. They have a tool to reverse the registry
settings removed, but you need to phone in to get it.

--
 
G

Guest

Better late than never... and to close this off. Yes, i had to run it 2 to 3
times before it kicked in and ignored the suspected trojan.

After all that, i wonder if i'll jump in and test the new defender tool ;)
I think they've already set up a different group.

I'll wait and watch the posts from people working out the wrinkles on THAT
one.

Thanks, all.

T

Ritesh Kaul said:
MS has fixed this issue. Update the virus definition to 5807 and it should
work. However, you may have to update it 2-3 times for it to take effect
[don't ask me why :)]...I had to do it twice for it to reflect the correct
version.

Once you have version 5807, the pws.bancos.a issue ceases.

Jacob Visser said:
I just downloaded the latest MS Antispyware definitions : Version: 5805
(2006-02-10 07:15:54)

A quick scan subsequently detected 614 Symantec AntiVirus Corporate Edition
10.0.2.2001 registry keys as a severe threat : PWS.Bancos.A Password Stealer
!!!

All keys and values under
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6 where detected as
being the password stealer.

Is this a marketing ploy to eliminate a future concurent after the anouncment
of a future Microsoft anitvirus product ? ;-)
 
B

Bill Sanderson

There are wrinkles in the beta2 version. However, one truth is that this
particular false positive was never one of them--i.e. for those users
running the new version during the relevant time period, they didn't see the
false positive.

I'd recommend testing the new version on test or little used machines--and
if you see a machine with a suspected problem, I'd go for the new version
for cleaning purposes.

--

Athena T said:
Better late than never... and to close this off. Yes, i had to run it 2
to 3
times before it kicked in and ignored the suspected trojan.

After all that, i wonder if i'll jump in and test the new defender tool ;)
I think they've already set up a different group.

I'll wait and watch the posts from people working out the wrinkles on THAT
one.

Thanks, all.

T

Ritesh Kaul said:
MS has fixed this issue. Update the virus definition to 5807 and it
should
work. However, you may have to update it 2-3 times for it to take effect
[don't ask me why :)]...I had to do it twice for it to reflect the
correct
version.

Once you have version 5807, the pws.bancos.a issue ceases.

Jacob Visser said:
I just downloaded the latest MS Antispyware definitions : Version: 5805
(2006-02-10 07:15:54)

A quick scan subsequently detected 614 Symantec AntiVirus Corporate
Edition
10.0.2.2001 registry keys as a severe threat : PWS.Bancos.A Password
Stealer
!!!

All keys and values under
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6 where detected
as
being the password stealer.

Is this a marketing ploy to eliminate a future concurent after the
anouncment
of a future Microsoft anitvirus product ? ;-)
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top