PDA

View Full Version : Kelvir/SDBot variants


selector
July 14th, 2005, 04:10 PM
What is Eset's position on SDBot/Kelvir variants?

I caught one via MSN Messenger which in fact was a self extracting RAR with a Kelvir and SDBot variant within it. NOD32 picked up the SDBot but still does not detect the Kelvir (1.exe) and RAR package (unknown@hotmail.com)

I have submitted both to Eset over a week ago but am concerned that given there are so many SDBot/Kelvir variants that each specific variant is never going to make the high prevalence level.

Looking at VirusTotal several other vendors are detecting the samples I have sent.

webyourbusiness
July 14th, 2005, 04:27 PM
{QUOTE-> What is Eset's position on SDBot/Kelvir variants? <-QUOTE}

They are adding them...

{QUOTE-> I caught one via MSN Messenger which in fact was a self extracting RAR with a Kelvir and SDBot variant within it. NOD32 picked up the SDBot but still does not detect the Kelvir (1.exe) and RAR package (unknown@hotmail.com) <-QUOTE}

Can't comment on a specific variant, but I would recommend losing the messenger - but that's my preference... ;)