View Full Version : Outbreak response.
SDS909
August 13th, 2005, 02:48 AM
About 9 hours after outbreak and me sending it to all of the AV companies.. Note, VBA32 captured the outbreak with Heuristics and was the only AV to detect at the 0-Hour.
http://www.boredmofo.com/downloads/outbreak.JPG
Firefighter
August 13th, 2005, 03:47 AM
-{ Quote: " Note, VBA32 captured the outbreak with Heuristics and was the only AV to detect at the 0-Hour." }-What is that "potentially unwanted program" with McAfee in VirusTotal? Is that heuristics too?
Best regards,
Firefighter!
liang_mike
August 13th, 2005, 08:33 AM
-{ Quote: "What is that "potentially unwanted program" with McAfee in VirusTotal? Is that heuristics too?" }-
That is just McAfee's category for non-virus threats, such as adware and spyware.
VikingStorm
August 13th, 2005, 10:27 AM
Did you actually check it with VirusTotal first?
Because I noticed some of the missing companies like Panda, and McAfee detect it. I just looked at the McAfee sig updates, and they haven't had an update for that malware in the last couple days.
Also, don't viruses have outbreaks and not trojans (or borderline adware I guess)?
SDS909
August 13th, 2005, 11:28 AM
It's a trojan downloader, i've lately often seen some AV's classify TrojanDownloaders as Adware, which I feel is incorrect. This launches a process and proceeds to infect your system with Trojans - I wouldn't classify that as adware by any sense of the word.
I actually didn't send it to Virustotal the first day, so it looks like McAfee possibly detected it with heuristics as a variant, which in that case, VBA32 and McAfee would have offered 0-hour detection.
SDS909
August 15th, 2005, 05:57 PM
3 Days after Outbreak and submission to all companies:
http://www.boredmofo.com/downloads/outbreak2.JPG
I applaud the companies that have responded to this threat. I'm really impressed with VBA32's zero-hour detection of it, and Panda+Kaspersky detection within a couple hours after I sent it in.
I'm pretty disappointed with some companies and their lack of response.
Nick Rhodes
August 16th, 2005, 05:24 AM
Thanks for sharing your findings.
Would be interesting to see a few results to see any trends though.
Also how serious is this threat, does that reflect response times ?
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums