I recently got a common virus.
It creates a folder "
resycled" with a file
boot.com inside it. It also adds an autorun.inf file to the root of the drive. On execution it injects
dll.dll into 2 system processes.
Neither my Norton 2009 nor the Kaspersky AVP Tool could detect it. I had to remove it manually by unloading the
dll.dll from the processes and then manually deleting the virus files. I had turned off automatic loading of autorun.inf.
I then uploaded the resycled folder having boot.com along with autorun file to VirusTotal and most of the AV detected it.
Then I uploaded only the resycled having the boot.com file inside it. To my surprise, neither Norton nor Kapersky detected it.
With Autorun file :
http://www.virustotal.com/analisis/6...49b6e2adf6f862
Without Autorun File :
http://www.virustotal.com/analisis/0...5fcd6e25b4dee1
and here's a sample of the boot.com file :
http://rapidshare.com/files/155514118/resycle.zip.html
The virus is relatively less harmful. Norton was able to detect the temp files from where the virus originated and was able to remove registry entries made by it and also some of the folders and files created by it but it failed to detect
boot.com
ThreatExpert reports
:
http://www.google.co.in/search?hl=en...G=Search&meta=
So I don't trust my AV Norton or Kaspersky
. Both failed to detect it. Even Microsoft (Onecare) was able to detect it. My question is do you trust your AV ?