Results 1 to 10 of 31
Thread: Do you trust your AV ?
- 10-19-2008 #1
Do you trust your AV ?
I recently got a common virus.
It creates a folder "resycled" with a file boot.com inside it. It also adds an autorun.inf file to the root of the drive. On execution it injects dll.dll into 2 system processes.
Neither my Norton 2009 nor the Kaspersky AVP Tool could detect it. I had to remove it manually by unloading the dll.dll from the processes and then manually deleting the virus files. I had turned off automatic loading of autorun.inf.
I then uploaded the resycled folder having boot.com along with autorun file to VirusTotal and most of the AV detected it.
Then I uploaded only the resycled having the boot.com file inside it. To my surprise, neither Norton nor Kapersky detected it.
With Autorun file :
http://www.virustotal.com/analisis/6...49b6e2adf6f862
Without Autorun File :
http://www.virustotal.com/analisis/0...5fcd6e25b4dee1
and here's a sample of the boot.com file :
http://rapidshare.com/files/155514118/resycle.zip.html
The virus is relatively less harmful. Norton was able to detect the temp files from where the virus originated and was able to remove registry entries made by it and also some of the folders and files created by it but it failed to detect boot.com
ThreatExpert reports:
http://www.google.co.in/search?hl=en...G=Search&meta=
So I don't trust my AV Norton or Kaspersky. Both failed to detect it. Even Microsoft (Onecare) was able to detect it. My question is do you trust your AV ?Last edited by prashanthpai; 10-20-2008 at 03:45 PM.
Happy To Help
- 10-19-2008 #2
No I don;t trust my AV but that is why its best to scan with stand alone antimalware programs as well,
Makes you wonder what else they miss that goes undetected
- 10-19-2008 #3
My answer is simple - Like human beings software have flaws too
FBI said that there's no 100% computer security - ur PC is 100% safe when its turn off
Apart from the sayings imagine there are 3-4 million malwares across the cyberworld and living inside physical boxes and Antivirus vendors cant filter all of those,despite the fact that addition of new tech innovations like Proactive features/HIPS/Heuristic tech...still not able to guarantee.
If I were u just sent the sample to the AV vendors - It's a good initiative
- 10-19-2008 #4
I've already sent it.
^ True IndeedFBI said that there's no 100% computer security - ur PC is 100% safe when its turn offLast edited by prashanthpai; 10-20-2008 at 12:00 AM.
- 10-20-2008 #5
yes true..
I trust my Anti Virus.. dunno why.. I just do..
- 10-20-2008 #6
Nope, a turned off computer is not even considered safe. I once a read that FBI said that the "safest computer will be the one that is turned off, buried 6 feed underground".... wait a minute, and he's even sure that's safe enough.
In short, there's no safe computer. And I do not trust antivirus. To me, it's just an alert tool rather than total protection.
- 10-20-2008 #7
I have a clean file. When I scan with Norton 2009, it doesnt detect any malware threats. Yesterday, when I uploaded to VirusTotal.com ~ two scan engines said that the file contains malware [aka~suspicious file]. Does it mean that two scan engines have positive test or the others fail to detect the file.

http://www.virustotal.com/analisis/2...e22a6ba74909df
Thanks,
diddo09
- 10-20-2008 #8
That file is safe
- 10-20-2008 #9
If you're unsure, it's time to analyze the file with ThreatExpert.
http://www.raymond.cc/blog/archives/...for-analyzing/
http://www.raymond.cc/blog/archives/...picious-files/
- 10-20-2008 #10
just like raymond i dont trust my av. thats one reason why i use mcafee its alerts are simple than kaspersky
Similar Threads
-
Why do you trust WOT?
By weylin in forum General ForumReplies: 11Last Post: 10-15-2010, 03:18 AM -
Is WOT (web of trust) reliable
By ted in forum General ForumReplies: 15Last Post: 10-06-2010, 11:25 PM -
Why you should never trust your antivirus 100%
By LunarWolf in forum Spyware/VirusesReplies: 13Last Post: 09-03-2010, 02:54 PM -
Web Of Trust
By JayCub in forum General ForumReplies: 32Last Post: 07-07-2010, 03:15 AM -
can we trust these websites ?
By witchball in forum General ForumReplies: 8Last Post: 08-12-2008, 01:49 AM


LinkBack URL
About LinkBacks





Reply With Quote


