Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-virus software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old February 15th, 2005, 05:33 PM
hojtsy hojtsy is offline
Frequent Poster
 
Join Date: Dec 2003
Posts: 350
Default W32.Dopbot worm strangeness

Three major antivirus companies describe the actions of the new Dopbot worm in a quite different way.

Symantec says that it sets:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\restrictanonymous=0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\EnableDCOM=Y

Sophos says that it sets:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\restrictanonymous=2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\EnableDCOM=N

Trend Micro says that it sets:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\restrictanonymous=0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\EnableDCOM=N

Quite a big difference! Symantec's version decreases security, Sophos's increases. It doesn't seem to be a typo, as this fact is clearly stated on both sites. Regarding the naming: Sophos W32/Dopbot-A = Symantec w32.dopbot.

I am interested which site is correct. Or did they found three completely different samples at exactly the same time?
-hojtsy-
  #2  
Old February 15th, 2005, 06:33 PM
Randy_Bell's Avatar
Randy_Bell Randy_Bell is offline
Updates Team
 
Join Date: May 2002
Location: Santa Clara, CA
Posts: 3,053
Default Re: W32.Dopbot worm strangeness

Quote:
Originally Posted by hojtsy
I am interested which site is correct. Or did they found three completely different samples at exactly the same time?
-hojtsy-
Being a NAV Chauvinist Pig, I will support Symantec!
  #3  
Old February 16th, 2005, 03:33 AM
Firecat's Avatar
Firecat Firecat is offline
Incredibly Massive Poster
 
Join Date: Jan 2005
Location: The land of no identity :D
Posts: 7,672
Default Re: W32.Dopbot worm strangeness

Being a former TrendMicro user, I will support Trend
__________________
Last edited by Radu : Today, at 5:32 AM. Reason: Found new malicious code

  #4  
Old February 16th, 2005, 04:59 AM
Ianb Ianb is offline
Frequent Poster
 
Join Date: Nov 2004
Location: UK
Posts: 231
Default Re: W32.Dopbot worm strangeness

Looks like Symantec are right. This worm exploits the DCOM vunerability so surely the reg must be set to EnableDCOM=Y
  #5  
Old February 16th, 2005, 06:38 AM
hojtsy hojtsy is offline
Frequent Poster
 
Join Date: Dec 2003
Posts: 350
Default Re: W32.Dopbot worm strangeness

Quote:
Originally Posted by Ianb
Looks like Symantec are right. This worm exploits the DCOM vunerability so surely the reg must be set to EnableDCOM=Y
That's not much proof. There were worms in the past which patch/fix a vulnerability after using it to infect the computer.
-hojtsy-
  #6  
Old February 16th, 2005, 02:57 PM
Firecat's Avatar
Firecat Firecat is offline
Incredibly Massive Poster
 
Join Date: Jan 2005
Location: The land of no identity :D
Posts: 7,672
Default Re: W32.Dopbot worm strangeness

Now come on...All three companies are mediocre...trust one and only one...KASPERSKY!!!!!
__________________
Last edited by Radu : Today, at 5:32 AM. Reason: Found new malicious code

 

Wilders Security Forums > Security Products > other anti-virus software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 04:11 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums