And 45 days after I sent the worm to AVAST

S

Shadow

From: "Shadow" <Sh@dow>
The answer from VT...

"Well, it seems that there's something weird, as besides Avast, GData also doesn't detect
it here (using the Avast engine) so it could be a limitation of the command line scanner,
or maybe they detect it with an AV feature I don't have here :?"

Uploaded oswnbi.tar.gz to your site. I just picked it up at
the local hospital. AVG is running , fully updated, on the machine I
got it from. This time I booted into linux, tar.gz the file and posted
that. So you can see what the autorun.inf looks like. Notice it has
changed name again.
Virustotal
http://www.virustotal.com/analisis/...3d4d64925a263ec09c06ae34ace36e3bcc-1251300636
FWIW
Back to work .....
 
D

David H. Lipman

From: "Shadow" <Sh@dow>

| On Wed, 26 Aug 2009 06:08:41 -0400, "David H. Lipman"

| Uploaded oswnbi.tar.gz to your site. I just picked it up at
| the local hospital. AVG is running , fully updated, on the machine I
| got it from. This time I booted into linux, tar.gz the file and posted
| that. So you can see what the autorun.inf looks like. Notice it has
| changed name again.
| Virustotal
| http://www.virustotal.com/analisis/
| af8292fc53daeba7bd615d584af77c3d4d64925a263ec09c06ae34ace36e3bcc-1251300636
| FWIW
| Back to work .....

Got it, thanx !
 
S

Shadow

| Uploaded oswnbi.tar.gz to your site. I just picked it up at
| the local hospital. AVG is running , fully updated, on the machine I
| got it from. This time I booted into linux, tar.gz the file and posted
| that. So you can see what the autorun.inf looks like. Notice it has
| changed name again.
| Virustotal
| http://www.virustotal.com/analisis/
| af8292fc53daeba7bd615d584af77c3d4d64925a263ec09c06ae34ace36e3bcc-1251300636
| FWIW
| Back to work .....
They (virustotal) deleted the link."Link has expired". WTF ?
The older links still work, for the virus I uploaded almost 2 months
ago. Today's link expired and a 2 month old one valid ?
[]'s
 
D

David H. Lipman

From: "Shadow" <Sh@dow>

| On Wed, 26 Aug 2009 19:49:46 -0400, "David H. Lipman"

| Your file has expired or does not exists.

I'll have VT admins look into it.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top