funsec mailing list archives

Re: mac trojan in-the-wild


From: "Dude VanWinkle" <dudevanwinkle () gmail com>
Date: Wed, 31 Oct 2007 19:14:43 -0400

On 10/31/07, David Harley <david.a.harley () gmail com> wrote:
err doesn't virustotal only detect windows viruses?

Strictly speaking, VT doesn't detect anything. It just reports what certain
scanners report. (I know that sounds patronizing: bear with me...) But a
couple of those scanners should detect Mac malware. VirusBarrier isn't one
of the scanners they use, though, and I haven't yet seen anything on this on
the McAfee, Sophos or Symantec web sites. But that may only mean that those
vendors haven't been able to secure a sample through "normal" channels --
Intego are long-established, but strictly Mac and a bit out of the
mainstream.

They dont have virex listed in the scanners, but ClamAV could
be the BSD version.. I guess

I don't think ClamAV does Mac-specific malware, generally, even ClamXav
which is just the Clam engine on a Mac platform.

If you respond to this, please don't go all anti-AV on me tonight: I've been
mauled enough for one evening, and I'm just trying to help...

No worries :-)

I had evaluated av solutions for a university and found out that
McAfee Virex did not detect windows viruses. I thought this was just
standard operating procedure for AV, as scanning every OS for every
virus might be too CPU intensive for an app.

-JP
_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: