Re: Searching For Virus Info

From: Brad Arlt (arlt_at_cpsc.ucalgary.ca)
Date: 11/25/03

  • Next message: Vishal: "Re: Searching For Virus Info"
    Date: Tue, 25 Nov 2003 15:59:41 -0700
    To: Mike <mjcarter@ihug.co.nz>
    
    

    On Tue, Nov 25, 2003 at 08:57:27PM +1300, Mike wrote:
    > HI Everyone,
    > I've recently had to try and find a virus name by it's characteristics and
    > The problem I have is that if I don't know or can't remember the virus name

    If you have the virus on hand just scan it, using HouseCall from
    TrendMicro (or similar service) if you lack antivirus software.

    If you lack the virus then search the various antivirus companies'
    databases. I recommend and use Sophos and TrendMicro for this purpose
    all the time. Both usually describe the vector(s) and output of the
    virus quite well, allowing for searches for specific strings found in
    the virus and vague network symptoms.

    > Is there a service I'm unaware of?

    Not that I know of. I have never had the need for more than 5 minutes
    of searching though.

    If you cannot figure out the virus, most (Sophos at least) encourage
    you to submit the file and they will tell you the story. You usually
    need to be a customer though... so you would normally just scan the
    file and use the name given by the scanning software.

    -----------------------------------------------------------------------
       __o Bradley Arlt Security Team Lead
     _ \<_ arlt@cpsc.ucalgary.ca University Of Calgary
    (_)/(_) Joyously Canadian Computer Science

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: Vishal: "Re: Searching For Virus Info"

    Relevant Pages

    • Re: SOPHOS Antivirus
      ... I work for a reseller of Sophos antivirus. ... The virus signatures only update once a ... >> By definition a firewall has no mail filtering function. ... NAV Corporate and SBE provide all that you state SOPHOS ...
      (alt.computer.security)
    • Re: SOPHOS Antivirus
      ... yours is the first real Sophos complaint while have read ... | a virus. ... When NAI bought McAfee their support went down the tubes. ... NAV Corporate and SBE provide all that you state SOPHOS ...
      (alt.computer.security)
    • Re: Virus Scanning Software for FreeBSD
      ... > wants to wait for FreeBSD 4.3-RELEASE to install things on their server. ... >> Is anyone aware of any virus scanning solutions for freebsd, ... I am using Sophos, ...
      (FreeBSD-Security)
    • Re: virus problem
      ... He was the one who gave me sophos (think he paid them an amount ... >> prompts me to this virus but cannot delete it. ... Create a new folder on your Desktop or the C: ... Restart your computer in Safe Mode. ...
      (microsoft.public.windowsxp.security_admin)
    • Re: SOPHOS Antivirus
      ... We use Sophos anti-virus on servers and clients. ... All updates ... however fails to deal with the virus accordingly. ... > must be the only reason large organisations use SOPHOS. ...
      (alt.computer.security)