+ User FidoNet address: 1:3634/12.42
> > Shoving the .exe file at VirusTotal reveals that the same file had
> > been scanned 3 hours prior, giving these results:
>
> you know something? you'd get better results if you threw these at
> the virus detection engines' maintainers and let them analyze it...
VG> No I wouldn't.
really?
VG> What I'm testing here is the compentency of the entire anti-virus
VG> industry.
no one can test for or protect against that which they know nothing about the
presence of, can they?? can you?
VG> I'm testing that industry by throwing current malware at them and
VG> see how they respond.
virus total is not "the industry"... it is but one company that has installed a
bunch of antivirus and malware detection programs... none of them are any more
reliable than their latest engines and rules... just like a chain is only as
strong as its weakest link...
VG> I'm throwing files at them that in theory they should already have
VG> a line on.
no, you are throwing files are virus total...
VG> They should already have a response system that includes a feed
VG> for these files to get into their own hands.
there is for every one that i've ever seen... you send the files in question
directly to them... not some third party source and expect that third party to
pass it along to everyone else... yo seem to be forgetting about the commercial
aspect of the industry and the "battle to be first" and "be on top as the best"
and such...
VG> They can operate honey-pot e-mail addresses - can't they? It's
VG> cheap to do. Email accounts that are long established and attract
VG> spam.
they do but that doesn't mean that they get sent these files by the those
groups who create them... you are having to access an infested site to acquire
them, aren't you? they, the actual files, aren't being sent to you... a link to
a distribution site is being sent... honey pots don't go and retrieve external
links... they do, however, suck up network data packets and store them for
analysis by humans... it is a long a tedious job...
VG> And by the way - those various companies which have their AV scan
VG> engines hosted by VirusTotal - we're under the impression that
VG> there is some sort of real-time feedback from VT to these companies
VG> regarding these files that are submitted. Perhaps that feedback is
VG> just urban legend?
i don't know what "feedback" you are talking about... when ever i come across
nefarious files, i send them to the companies that i have a business
relationship with... as such, since i do not do norton or mcaffee or m$
schtuff, they do not get anything from me... some of my associates may have
relationships with those companies and may pass the files on to them but no one
can force anyone to do such...
/me thinks your expectations are much too high... turn them down a few notches
and contribute to helping rather than testing and carrying on when your
expectations are not met ;)