In article <(E-Mail Removed)> , Colin
Wilson <(E-Mail Removed)> writes
>> I've recently disinfected a few machines and AVG is just not catching
>> enough. Of the 9 suspicious files I found AVG triggered on just 1, best
>> were Dr Web and Kaspersky (8/9) followed by VBA32 (6/9), AntiVir (4/9),
>> BitDefender (3/9), ArcaVir, NOD32, Fortinet & VirusBuster (2/9), AVG &
>> Norman (1/9), Avast, ClamAV & UNA missed the lot. Files were submitted
>> via Jotti's Malware Scan http://virusscan.jotti.org/
>
>Interesting - have you tried throwing Sysclean at the infected files ?
>
>If you still happen to have the infected file(s) I wouldn't mind a copy
>to test for myself - is it possible the virus was a new variant that
>hadn't been added in at that point in time ? (many will update
>themselves regularly when they manage to take hold to try to avoid
>detection)
>
>Unmunge the following for a working email address:
>btinternet.com@btiruseless (if you could put "newsgroup" in the subject
>line it'll help it bypass my filters too :-) )
Sorry I haven't tried Trend. I was disinfecting a machine and was looking at
running processes and run settings in the registry before letting the tools
work and was surprised at a few being left behind on a multi-infected
machine. That made me submit the leftovers to Jotti with the interesting
results, top marks to them and the virus engines that have permitted their
tools to be used in that way.
I do have the culprits from the latest clean, most in evidence is zlob and
generic trojan downloaders, the last packaged with Virtumonde,
mytoolbar888 & <something>fraud adware/spyware but forgive me for
being a bit anal in not being prepared to distribute them. If it helps, m/c1
was infected through chat, m/c2 was through over zealous porn delving and
m/c3 through crack site downloads. If you're looking for sources of
malware then a trawl of cracks for popular programs would be a good
starting place but I'd do any experimenting on a well quarantined machine.
--
fred
Plusnet - I hope you like vanilla