Worm Update #2
Tuesday, April 17, 2007
Symantec has added a new designation for the Rinbot described earlier, W32.Rinbot.BC. They also say that, "Virus definitions dated April 16, 2007 or earlier may detect this threat as W32.Rinbot.A", which is utter crap -- as of the outbreak yesterday, their signatures didn't detect it as anything. After some newer releases arrived in the afternoon, suddenly it was recognized as Rinbot.A, and only now as the new variant.
The bottom line? Signature-based scanners are losing their effectiveness, and fast.
- David
posted by David @ 11:30 AM,