Desktop antivirus - it's dead

M

Michael Arends

kurt wismer answered:
What's in a Name? said:
After much thought,Virus Guy came up with this jewel: [snip]
Swap out your patched vgx.dll for an older one, then try this page:

http://209.85.165.104/search?q=cache:fbdJRQS1FxwJ:zert.isotf.org/testv
ml.htm+testvml.htm&hl=en&ct=clnk&cd=1&gl=ca

It's the google cached version of this:

http://zert.isotf.org/testvml.htm

or this:

http://www.isotf.org/zert/testvml.htm

Which doesn't seem to exist any more, but was designed to trigger the
VML vulnerability.

Presumably NOD-32 should intercept the code before IE is crashed by
it.
I just checked it out (with an unpatched W2K) and Nod alerted and
blocked loading of page! I guess it works!

thanks for the verification... i think it's safe to say now that nod32
qualifies as a first line of defense at the end-point
(http://anti-virus-rants.blogspot.com/2007/04/defensive-lines-in-end-point-anti.html)
I know i'm coming in to the conversation late. But NOD alerted ME too.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top