I've got from majorgeeks & other sites : all of them ask to download
fsdbupdate9.exe (ie latest) & it can't install/run : I used 7zip to open
its contents but don't see any virus pattern file in it.
For TrendMicro, the lpt$vpn.xxx contains virus definitions & by issuing
find/i "name" lpt*
it lists out the virus names
> go to the link and you should see the AV names added or updated
> https://www.f-secure.com/dbtracker/Aquarius/2016-09-05_07.html
Why is AV names being removed, thought they should just be adding on
to make it more complete? Is there such thing as a malware/virus getting
obsoleted?
sunhux
ASKER
Btw, how do I identify from F-Secure's list if a malware is a ransomware?
As long as the description contains the string "lock" or "cryp" ?
But from https://id-ransomware.malwarehunterteam.com ,
there are ransomware with names that don't contain the above 2 strings, eg:
777
7ev3n
7h9r
ACCDFISAv2.0
Alfa
Alpha
AMBA
Apocalypse
Bandarchor
BankAccountSummary
Bart
fsdbupdate9.exe (ie latest) & it can't install/run : I used 7zip to open
its contents but don't see any virus pattern file in it.
For TrendMicro, the lpt$vpn.xxx contains virus definitions & by issuing
find/i "name" lpt*
it lists out the virus names