|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Re: Alert: W32.NewApt.Worm being sent to NTBugtraq subscribers
Subject: Re: Alert: W32.NewApt.Worm being sent to NTBugtraq subscribers
From: Weld Pond (weld
L0PHT.COM)
Date: Thu Dec 16 1999 - 20:16:53 CST
- Next message: Adam L. Simms: "NT System Policy Security Breac"
- Previous message: NAI Labs: "Windows NT LSA Remote Denial of Service"
- In reply to: Russ: "Re: Alert: W32.NewApt.Worm being sent to NTBugtraq subscribers"
- Reply: Weld Pond: "Re: Alert: W32.NewApt.Worm being sent to NTBugtraq subscribers"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
OK, you said not to reply but I have further proof that the antivirus
companies are just copying each others data without thinking about it.
A funny thing happened on Nov 19, 1999. A l0phtcrack customer emailed our
support address to complain that Trend Micro's antivirus program was
detecting a "virus" in the l0phtcrack 2.52 executable file. It detected
something called the TROJ_L0PHTCRACK virus. The customer wanted to make
sure they were not infected. Trend Micro had included a TROJ_L0PHTCRACK
signature in their version 610 signature file.
Then on Dec 16 we got another message from a customer complaining that
NAI's VirusScan with the version 4056 signature file was now detecting the
"Lophtcrack" (sic) virus. The program actually pops up a message box
stating "The file l0phtcrack.XXX on YYY is infected with the virus
Lophtcrack. Unable to clean file."
L0phtCrack was first released in 1997 and the latest version was released
in Jan. 1999. Is it a coincidence that both AV vendors are just getting
around to deciding L0phtCrack is a virus/trojan? I don't think so. My
hypothesis is someone at Trend Micro decided it was a virus and NAI
blindly copied their data. But who really knows.
L0phtCrack is obviously neither a trojan or virus. These AV messages are
erroneous.
-weld
- Next message: Adam L. Simms: "NT System Policy Security Breac"
- Previous message: NAI Labs: "Windows NT LSA Remote Denial of Service"
- In reply to: Russ: "Re: Alert: W32.NewApt.Worm being sent to NTBugtraq subscribers"
- Reply: Weld Pond: "Re: Alert: W32.NewApt.Worm being sent to NTBugtraq subscribers"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
This archive was generated by hypermail 2b27 : Thu Dec 16 1999 - 23:03:58 CST