Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-trojan software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #26  
Old September 27th, 2011, 10:56 AM
Baserk's Avatar
Baserk Baserk is offline
Frequent Poster
 
Join Date: Apr 2008
Location: Amstelodamum
Posts: 971
Default Re: Secure Banking 1.1

While the v1.1 changelog mentions 'Weniger "False Positives" von Anti-Viren-Programmen' / less FP's by AV progs, a hypothetical site which hypothetically tests files against 40+ hypothetical AV's, still gives a hypothetical 13/44 score.

The Secure Banking dev asks for help at protecus.de; 'Btw. ich würde mich sehr über mithilfe bei diesem Projekt freuen! (Website/Werbung/Coding)' link.
He would not only gladly receive help with his website and advertising but also coding.
And perhaps reporting FP's?
__________________
ROMANES EUNT DOMUS

Last edited by Baserk : September 27th, 2011 at 11:11 AM.
  #27  
Old September 27th, 2011, 03:53 PM
pintas pintas is offline
Regular Poster
 
Join Date: Apr 2010
Posts: 160
Default Re: Secure Banking 1.1

Unfortunately my coding is not what it used to be, but i suppose he could team up with PE Guard.
  #28  
Old September 28th, 2011, 07:51 PM
CloneRanger's Avatar
CloneRanger CloneRanger is online now
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,857
Exclamation Re: Secure Banking 1.1

Thought i'd try & see what it does Uploaded it 1st to VT

Name:  sb.gif
Views: 633
Size:  5.1 KB

SecureBanking - Installer.exe = Result: 0/43 (0.0%)

SecureBanking.exe = Result: 20/43 (46.5%)

sbservice.exe = Result: 28/43 (65.1%)

SecureBanking.dll = Result: 18/43 (41.9%)

Funny installer ?

Name:  inst.gif
Views: 637
Size:  2.4 KB

Wanted out via

Name:  za1.gif
Views: 639
Size:  7.7 KB

Also tried to connect to 178.63.25.142 = -www.securebanking.bplaced.net

Name:  za2.gif
Views: 639
Size:  7.8 KB

Had to allow several ProcessGuard prompts in German, & i also got a LOT of error messages in German, & ultimately it failed to install ?


Quote:
IP Address Inspector

ATTENTION

* This IP has not seen any suspicious activity within the last 3 months. This IP is most likely clean and trustworthy now. (This record will remain public for historical purposes, however.) https://www.projecthoneypot.org/ip_178.63.25.142

From their www via google.com/translate

Quote:
Read me first ...

Secure banking is an application that different Trojans (Zeus, SpyEye, Carberp, ...) can reliably detect on your system. This same technique is used, use the Trojans. Since the malware are often made resistant through special programs including the anti-virus programs that scan for signatures and not bring the much behavioral analysis. Secure Banking remedied by the web browser on so-called "man-in-the-middle" or "man-in-the-browser" attacks scans.

Secure Banking v1.1

Posted by Owner Posted by Owner

Here is the second release of Secure Banking.

Änderungen/Neuerungen: Changes / improvements:

Improved / New Revised recognition engine
Memory/Speicher Problem solved
CPU-friendly
Less "false positives" of anti-virus programs
I would again appreciate your feedback! Thank you!

Here's my feedback
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
  #29  
Old September 28th, 2011, 08:22 PM
Baserk's Avatar
Baserk Baserk is offline
Frequent Poster
 
Join Date: Apr 2008
Location: Amstelodamum
Posts: 971
Default Re: Secure Banking 1.1

Quote:
Originally Posted by CloneRanger
...
From their www via google.com/translate

"Secure banking is an application that different Trojans (Zeus, SpyEye, Carberp, ...) can reliably detect on your system."
Google Translate algorithm distorts the original text into something extremely fishy.
A more proper translation would be;
"Secure banking is an application that can reliably detect different Trojans (Zeus, SpyEye, Carberp, ...) on your system."
No arguments about whether the prog is valid or not but Google Translate is in this case.
__________________
ROMANES EUNT DOMUS
  #30  
Old September 28th, 2011, 08:26 PM
Page42's Avatar
Page42 Page42 is offline
Massive Poster
 
Join Date: Jun 2007
Location: Last Breath Farm
Posts: 4,580
Default Re: Secure Banking 1.1

VIPRE doesn't like securebanking...

Name:  secure banking.jpg
Views: 642
Size:  22.9 KB
Name:  secure banking II.jpg
Views: 642
Size:  28.8 KB
__________________
To err is human; to forgive, infrequent. - Franklin P. Adams
  #31  
Old September 30th, 2011, 01:33 AM
Page42's Avatar
Page42 Page42 is offline
Massive Poster
 
Join Date: Jun 2007
Location: Last Breath Farm
Posts: 4,580
Default Re: Secure Banking 1.1

Hitman Pro context scan says sbservice.exe is malware.
Looks like WOT had this one right.
__________________
To err is human; to forgive, infrequent. - Franklin P. Adams
  #32  
Old September 30th, 2011, 04:23 AM
Jose_Lisbon's Avatar
Jose_Lisbon Jose_Lisbon is offline
Frequent Poster
 
Join Date: Feb 2010
Location: Portugal
Posts: 245
Default Re: Secure Banking 1.1

Quote:
Originally Posted by Page42
Looks like WOT had this one right.
It usually does.
  #33  
Old September 30th, 2011, 03:29 PM
J_L's Avatar
J_L J_L is offline
Massive Poster
 
Join Date: Nov 2009
Posts: 4,833
Default Re: Secure Banking 1.1

Since it's used quite a lot, there will be many false positives as well.

Also, AVs aren't perfect either. Has anyone actually analysed the behaviour of this program?
__________________
  #34  
Old September 30th, 2011, 03:45 PM
Habakuck's Avatar
Habakuck Habakuck is offline
Frequent Poster
 
Join Date: May 2009
Posts: 543
Default Re: Secure Banking 1.1

Quote:
Has anyone actually analysed the behaviour of this program?
Jep, but i wont comment it in detail as long as the analysis as protecus and TB are running... So far, nothing which was not mentioned by the builder..
__________________
"If You Run Naked Around a Tree, at about 87 km/h, there is a possibilty of f4cking your self."
Albert Einstein
  #35  
Old September 30th, 2011, 05:03 PM
Page42's Avatar
Page42 Page42 is offline
Massive Poster
 
Join Date: Jun 2007
Location: Last Breath Farm
Posts: 4,580
Default Re: Secure Banking 1.1

Quote:
Originally Posted by J_L
Since it's used quite a lot, there will be many false positives as well.

Also, AVs aren't perfect either. Has anyone actually analysed the behaviour of this program?
False positives and imperfection...
Two ever-present conditions associated with most security software.
Anyone who doesn't know this, and account for this, might as well have a blindfold on.
I view WOT and AVs as indicators.
Never do I consider either of them to be the last word.
__________________
To err is human; to forgive, infrequent. - Franklin P. Adams
  #36  
Old October 2nd, 2011, 01:19 PM
RJK3 RJK3 is offline
Frequent Poster
 
Join Date: Apr 2011
Posts: 469
Default Re: Secure Banking 1.1

Quote:
Originally Posted by Page42
I view WOT and AVs as indicators.
Never do I consider either of them to be the last word.

Exactly. There is always the possibility for false negatives and false positives.

From the WOT ratings, I feel the site should be commended for its excellent Child Safety.
  #37  
Old October 2nd, 2011, 11:14 PM
Noob's Avatar
Noob Noob is online now
Massive Poster
 
Join Date: Nov 2009
Posts: 5,249
Default Re: Secure Banking 1.1

Quote:
Originally Posted by J_L
Has anyone actually analysed the behaviour of this program?
Yeah, i would like someone to go in deep with the software, but i guess that might be too much to ask
__________________
Emsisoft Anti-Malware v7.0.0.21 - Online Armor 6.0.0.1736
SRP - UAC - EMET

Browser: Google Chrome v25.xx

Windows 7 Ultimate x64
  #38  
Old October 3rd, 2011, 06:06 PM
SUPERIOR's Avatar
SUPERIOR SUPERIOR is offline
Regular Poster
 
Join Date: Dec 2007
Location: Syria
Posts: 161
Default Re: Secure Banking 1.1

i tested version 1.0 and it failed
now tested it again with 1.1 and here what i have found :

first off, three executed files for defending and 2 files for detailed(one for the date of version)
it starts with injecting securebanking.dll into explore process and runs sbservice for monitoring when wanted processes run for detecting malicious activities
now it looks for only 2 names of processes to monitor (IE and FF) so google and other browsers are out of this game

then i had to try it in action so i run zeus bot and then run FF IE and SR and u can see the result in attachments

as long i dont understand german, i can say that it just alarms you if there is trojan but cant help you to defend or to make secure banking as its name claims

one more thing, i noticed that there was a connection to server5.bplaced.net but when i did whois i didnt find this server in the list
PS : i guess it doesnt matter since it just connects for making sure that u have latest version ^^
Attached Thumbnails
Click image for larger version

Name:	Inject.png
Views:	0
Size:	78.1 KB
ID:	229588  

Click image for larger version

Name:	in Action 2.png
Views:	1
Size:	123.5 KB
ID:	229590  

Click image for larger version

Name:	in action 3.png
Views:	0
Size:	53.9 KB
ID:	229591  

Attached Images
  
__________________
Analyzing scareware, junkware, crimeware, damnware, crapware ....... and all $h!tware

Last edited by SUPERIOR : October 3rd, 2011 at 06:26 PM.
  #39  
Old October 4th, 2011, 02:19 AM
CloneRanger's Avatar
CloneRanger CloneRanger is online now
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,857
Default Re: Secure Banking 1.1

@ Baserk

Thanks for the translation info

@ SUPERIOR

Thanks for the extra testing Well at least it alarmed you there was a Trojan, which is better than nothing Needs more work by the sound of it.
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
  #40  
Old October 4th, 2011, 04:00 AM
SUPERIOR's Avatar
SUPERIOR SUPERIOR is offline
Regular Poster
 
Join Date: Dec 2007
Location: Syria
Posts: 161
Default Re: Secure Banking 1.1

@CloneRanger
your welcome, btw the version u were testing is 1.0 maybe u could give v1.1 another try
__________________
Analyzing scareware, junkware, crimeware, damnware, crapware ....... and all $h!tware
  #41  
Old October 4th, 2011, 04:13 PM
CloneRanger's Avatar
CloneRanger CloneRanger is online now
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,857
Default Re: Secure Banking 1.1

@ SUPERIOR

Thanks for the invite, but i think i'll pass
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
  #42  
Old October 6th, 2011, 09:00 AM
Noob's Avatar
Noob Noob is online now
Massive Poster
 
Join Date: Nov 2009
Posts: 5,249
Default Re: Secure Banking 1.1

Oh well, then it's kinda crappy as of now
__________________
Emsisoft Anti-Malware v7.0.0.21 - Online Armor 6.0.0.1736
SRP - UAC - EMET

Browser: Google Chrome v25.xx

Windows 7 Ultimate x64
  #43  
Old October 7th, 2011, 02:58 PM
carat
 
Posts: n/a
Smile Re: Secure Banking 1.1

Quote:
Originally Posted by Noob
Oh well, then it's kinda crappy as of now

Why? It's designed to detect banking trojans and that's what it did
 

Wilders Security Forums > Security Products > other anti-trojan software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 10:15 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums