 | reply to NetWatchMan
Re: Opaserv - A Complete Guide said by NetWatchMan: Has anyone seen cases where Norton and/or McAfee fail to detect ALL the known Opaserv variants, despite having up-to-date signature definitions? I'm hearing this more and more, but haven't found an end-user patient enough to take the time with me and document the specifics.
So far as I know, NAV detects all of them. I would think McAfee and all the major AVs (the ones I included in my second post) are detecting all of the variants.
Regarding the relative credits, CalamityJane is to be credited with initiating this research (it was her idea folks); we're thinking about doing Yaha variants next, which may be even tougher and more confusing than Opaserv variants (if that is possible). 
I also was hoping that representatives of any vendors we've overlooked could post to this thread and provide info on what their vendor is calling these variants. I especially regret not including Eset/NOD32 detection names because I could not find any info at their site. NOD users are welcome and encouraged to provide info on what their AV is calling each variant. So that we can make this a collaborative thread if desired.
I had a minor scare when I was posting this thread yesterday morning. To keep it manageable, the posting had to be in two parts, an introduction followed by information. I made the first post OK, but then my DSL connection stalled in the middle of the second post, and I was afraid DSLR site had gone down before I could make my second post! Luckily I was able to go in on my son's machine and use a dialup connection to finish making the second post: if someone else had posted before I could get in the second post, it would have messed up the thread, but thankfully that didn't happen. :) -- "But now abide faith, hope, love, these three; but the greatest of these is love." (1 Cor. 13:13) |
 | I would be more than happy to make this guide part of my udp/137 info if that's ok with you guys...I would probably just create a seperate Opaserv page with what you have above.
One of yous drop me an email with all appropriate credit/contact info if you're OK with this. -- Lawrence Baldwin myNetWatchman The Internet Neighborhood Watch |