Antivirus: November 2005 Archives

I wonder if I could have bet on this in Vegas? What's this the third or fourth time in 6 months Trend has published writeups on a virus and said that it exploits a recently patched windows vulnerability only to later retract it.

http://www.techworld.com/security/news/index.cfm?RSS&NewsID=4781 Trend Micro has retracted last week’s claim to have discovered a Trojan that could exploit vulnerabilities in the Windows graphics engine.

Some people are reporting false positives in bloodhound.exploit.52. This is Symantec's heuristic detection for the flash vulnerability. Over at the ISC one person has said this has only been an issue for them with people running Flash 7.0.19. If you haven't upgraded this is probably the version you are running.

At least one person reporting the problem is using rapid release versions of the virus definitions 11/10 rev 39 and 11/22 with unknown revision number. So this means if they've submitted the suspect files to Symantec this false positive could get fixed before the virus defs are widely deployed.