Raymond.CC Blog







  #1 (permalink)  
Old 10-19-2008
prashanthpai's Avatar
prashanthpai prashanthpai is offline
Tech God
 
Join Date: Feb 2008
Location: Socket LGA 771
Posts: 1,976
Cool Do you trust your AV ?

I recently got a common virus.
It creates a folder "resycled" with a file boot.com inside it. It also adds an autorun.inf file to the root of the drive. On execution it injects dll.dll into 2 system processes.

Neither my Norton 2009 nor the Kaspersky AVP Tool could detect it. I had to remove it manually by unloading the dll.dll from the processes and then manually deleting the virus files. I had turned off automatic loading of autorun.inf.

I then uploaded the resycled folder having boot.com along with autorun file to VirusTotal and most of the AV detected it.
Then I uploaded only the resycled having the boot.com file inside it. To my surprise, neither Norton nor Kapersky detected it.

With Autorun file :
http://www.virustotal.com/analisis/6...49b6e2adf6f862

Without Autorun File :
http://www.virustotal.com/analisis/0...5fcd6e25b4dee1

and here's a sample of the boot.com file :
http://rapidshare.com/files/155514118/resycle.zip.html

The virus is relatively less harmful. Norton was able to detect the temp files from where the virus originated and was able to remove registry entries made by it and also some of the folders and files created by it but it failed to detect boot.com

ThreatExpert reports:
http://www.google.co.in/search?hl=en...G=Search&meta=

So I don't trust my AV Norton or Kaspersky. Both failed to detect it. Even Microsoft (Onecare) was able to detect it. My question is do you trust your AV ?
__________________
Happy To Help

Last edited by prashanthpai; 10-20-2008 at 02:45 PM..
Reply With Quote
Alt Today
Advertising
Google Adsense
 
Standard Sponsored Links
  #2 (permalink)  
Old 10-19-2008
fletch's Avatar
fletch fletch is offline
Senior Techie
 
Join Date: Sep 2008
Location: UK/ Midlands
Posts: 201
No I don;t trust my AV but that is why its best to scan with stand alone antimalware programs as well,

Makes you wonder what else they miss that goes undetected
Reply With Quote
  #3 (permalink)  
Old 10-19-2008
ceyfer's Avatar
ceyfer ceyfer is offline
Star
 
Join Date: May 2007
Location: 13°15'N - 123°41'E
Posts: 2,443
My answer is simple - Like human beings software have flaws too

FBI said that there's no 100% computer security - ur PC is 100% safe when its turn off

Apart from the sayings imagine there are 3-4 million malwares across the cyberworld and living inside physical boxes and Antivirus vendors cant filter all of those,despite the fact that addition of new tech innovations like Proactive features/HIPS/Heuristic tech...still not able to guarantee.

If I were u just sent the sample to the AV vendors - It's a good initiative
Reply With Quote
  #4 (permalink)  
Old 10-19-2008
prashanthpai's Avatar
prashanthpai prashanthpai is offline
Tech God
 
Join Date: Feb 2008
Location: Socket LGA 771
Posts: 1,976
I've already sent it.
Quote:
FBI said that there's no 100% computer security - ur PC is 100% safe when its turn off
^ True Indeed

Last edited by prashanthpai; 10-19-2008 at 11:00 PM..
Reply With Quote
  #5 (permalink)  
Old 10-19-2008
Mark's Avatar
Mark Mark is offline
Star
 
Join Date: Jun 2008
Location: UK
Posts: 3,000
yes true..

I trust my Anti Virus.. dunno why.. I just do..
__________________
Reply With Quote
  #6 (permalink)  
Old 10-19-2008
Raymond's Avatar
Raymond Raymond is offline
Administrator
 
Join Date: Nov 2006
Location: Malaysia
Posts: 7,725
Nope, a turned off computer is not even considered safe. I once a read that FBI said that the "safest computer will be the one that is turned off, buried 6 feed underground".... wait a minute, and he's even sure that's safe enough.

In short, there's no safe computer. And I do not trust antivirus. To me, it's just an alert tool rather than total protection.
Reply With Quote
  #7 (permalink)  
Old 10-20-2008
diddo09's Avatar
diddo09 diddo09 is offline
Junior Techie
 
Join Date: Aug 2008
Posts: 157
Cool

I have a clean file. When I scan with Norton 2009, it doesnt detect any malware threats. Yesterday, when I uploaded to VirusTotal.com ~ two scan engines said that the file contains malware [aka~suspicious file]. Does it mean that two scan engines have positive test or the others fail to detect the file.

http://www.virustotal.com/analisis/2...e22a6ba74909df

Thanks,

diddo09
Reply With Quote
  #8 (permalink)  
Old 10-20-2008
prashanthpai's Avatar
prashanthpai prashanthpai is offline
Tech God
 
Join Date: Feb 2008
Location: Socket LGA 771
Posts: 1,976
That file is safe
Reply With Quote
  #9 (permalink)  
Old 10-20-2008
Raymond's Avatar
Raymond Raymond is offline
Administrator
 
Join Date: Nov 2006
Location: Malaysia
Posts: 7,725
Quote:
Originally Posted by diddo09 View Post
I have a clean file. When I scan with Norton 2009, it doesnt detect any malware threats. Yesterday, when I uploaded to VirusTotal.com ~ two scan engines said that the file contains malware [aka~suspicious file]. Does it mean that two scan engines have positive test or the others fail to detect the file.

http://www.virustotal.com/analisis/2...e22a6ba74909df

Thanks,

diddo09
If you're unsure, it's time to analyze the file with ThreatExpert.
http://www.raymond.cc/blog/archives/...for-analyzing/
http://www.raymond.cc/blog/archives/...picious-files/
Reply With Quote
  #10 (permalink)  
Old 10-20-2008
shan's Avatar
shan shan is offline
Star
 
Join Date: Jun 2008
Location: Sri Lanka
Posts: 1,936
just like raymond i dont trust my av. thats one reason why i use mcafee its alerts are simple than kaspersky
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Why You Shouldn't Trust Facebook with Your Data: An Employee's Revelations safeguy General Forum 10 01-17-2010 08:50 AM
Can we still trust Comodo? safeguy General Forum 32 08-31-2009 01:58 PM
can we trust these websites ? witchball General Forum 8 08-12-2008 12:49 AM


All times are GMT +8. The time now is 05:13 PM.