CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Win32.YOK.Supersearch False Positive?

 
Post new topic   Reply to topic       All -> FavForums -> Zone Alarm [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
gorgelink

Sergeant
Sergeant


Joined: Dec 02, 2004
Posts: 75
Location: USA

PostPosted: Mon Aug 07, 2006 7:24 pm    Post subject: Win32.YOK.Supersearch False Positive?
Reply with quote

Hi,

In the last few days, users keep reporting the detection of a trojan Win32.YOK.Supersearch.

Details here:

http://forum.zonelabs.org/zonelabs/board/message?board.id=Antivirus&message.id=13104

http://forum.zonelabs.org/zonelabs/board/message?board.id=Antivirus&message.id=13092

http://forum.zonelabs.org/zonelabs/board/message?board.id=security&message.id=15997

Looks to me like a false positive.

Ewido is a dedicated anti-Trojan. It found nothing (I did deep registry scan and then scan of all files on the computer).

Lavasoft Adaware - dedicated antispyware application - found nothing. It deep scans the registry.

NAV found nothing.

All three with latest definitions.

00021494 .... 046 indicates an Internet Explorer add-on toolbar. Such toolbars are frequently used by adware - but very rarely by Trojans. The Win32.YOK, Supersearch is supposed to be a Trojan.

I have an Opera with in-built Google search (and Amazon search). I just updated to Opera 9.01, so maybe that's the source of the FP. Don't know. Would love to have an answer.

G.

Back to top
View users profile Send private message
Hoov

Zone Alarm Host
Zone Alarm Host
PIRT Handler

Joined: Jun 21, 2002
Posts: 4613
Location: USA
1st Responders Phishing Squad Premium RootKit Detection Hosts Rootkit Responders Team F@H

PostPosted: Tue Aug 08, 2006 3:25 am    Post subject:
Reply with quote

Did you report this?


_________________
For ZoneAlarm help http://www.donhoover.net
Back to top
View users profile Send private message Send email Visit posters website
gorgelink

Sergeant
Sergeant


Joined: Dec 02, 2004
Posts: 75
Location: USA

PostPosted: Tue Aug 08, 2006 12:32 pm    Post subject: Sure did
Reply with quote

Sure did, Hoov. I am aware of two other users who have written to Tech Support.

BUT

If it comes from you it carries far more weight. Can you please convey our queries to Tech Support?

Have a cool summer.

G.

Back to top
View users profile Send private message
gorgelink

Sergeant
Sergeant


Joined: Dec 02, 2004
Posts: 75
Location: USA

PostPosted: Wed Aug 09, 2006 11:16 am    Post subject: Where is Tech Support?
Reply with quote

New antispyware definitions file 310 was released today and the FP remains.

I call it FP (False Positive) because ONLY a registry entry is identified by ZA.

None - NOT ONE - of the files associated with YOK. Supersearch is found on my computer.

YOK. Supersearch installs MANY files on the infected computer + a toolbar. These are nowhere to be found on my computer. ZA only identifies a registry entry.

Additionally, no other dedicated anti-Trojan and anti-spyware applications find this threat - only ZA! Ewido, Adaware, Spysweeper - all excellent products that tell me my computer is 100% clean. Only ZA comes up with this registry entry.

It is a pity that ZA Tech Support do not respond to us in times of distress.

g.

Back to top
View users profile Send private message
Hoov

Zone Alarm Host
Zone Alarm Host
PIRT Handler

Joined: Jun 21, 2002
Posts: 4613
Location: USA
1st Responders Phishing Squad Premium RootKit Detection Hosts Rootkit Responders Team F@H

PostPosted: Thu Aug 10, 2006 6:32 am    Post subject:
Reply with quote

I have let them know about it.


_________________
For ZoneAlarm help http://www.donhoover.net
Back to top
View users profile Send private message Send email Visit posters website
gorgelink

Sergeant
Sergeant


Joined: Dec 02, 2004
Posts: 75
Location: USA

PostPosted: Thu Aug 10, 2006 5:13 pm    Post subject: It is a False Positive!
Reply with quote

A week late - and after they had advised everyone to delete the registry entry - Tech Support confirmed earlier today that Win32.YOK.Supersearch is a false positive.

Will they fix it as soon as possible?

No way.

MAYBE on Friday, they say.

Meanwhile this is what happened to me - read the unbelievable details:

CastleCops Link/p812120-Restored_item_from_quarantine_disappeared.html#812120

G.

Back to top
View users profile Send private message
Hoov

Zone Alarm Host
Zone Alarm Host
PIRT Handler

Joined: Jun 21, 2002
Posts: 4613
Location: USA
1st Responders Phishing Squad Premium RootKit Detection Hosts Rootkit Responders Team F@H

PostPosted: Thu Aug 10, 2006 6:49 pm    Post subject:
Reply with quote

I got the word that it will be fixed in the update tomorrow.

False positives are a fact of life no matter what scanner you use, or what kind of scanner it is. So far ZoneLabs has had relatively few false positives compared to other scanners I have used.


_________________
For ZoneAlarm help http://www.donhoover.net
Back to top
View users profile Send private message Send email Visit posters website
gorgelink

Sergeant
Sergeant


Joined: Dec 02, 2004
Posts: 75
Location: USA

PostPosted: Fri Aug 11, 2006 2:46 pm    Post subject: You are right - clarification
Reply with quote

You are right, Hoov - False positives are an inevitable part of the game. I have no problem wit that and ZAP is a great and wondrous product. I have been a loyal user, fan, and gratis sales promoter for years now.

BUT

I think Tech Support made two errors of judgement this time around:

1. Taking its sweet time to tackle the problem. Other firm (Ewido, Symantec, Adaware) fix FPs in a matter of day or two. EIGHT DAYS is unacceptable.

2. Advising people to delete the registry entry without checking their complaints and queries in-depth. It is irresponsible. They should have advised people to QUARANTINE.

Thanks for always being there for us.

G.

Back to top
View users profile Send private message
Hoov

Zone Alarm Host
Zone Alarm Host
PIRT Handler

Joined: Jun 21, 2002
Posts: 4613
Location: USA
1st Responders Phishing Squad Premium RootKit Detection Hosts Rootkit Responders Team F@H

PostPosted: Sat Aug 12, 2006 4:31 am    Post subject:
Reply with quote

I am not sure if this is a ZoneAlarm scanner or if it is licensed for use like the virus scanner. If it is the first, then they are just getting off the ground with this, and like other companies it may take them a while to get immediate updates, if it is licensed, then they may not be getting immediate updates because the company is busy maintaining their primary product.

As for the registry / quarantine, I agree.


_________________
For ZoneAlarm help http://www.donhoover.net
Back to top
View users profile Send private message Send email Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Zone Alarm All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer