Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-virus software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #26  
Old April 14th, 2012, 11:15 AM
Ranget's Avatar
Ranget Ranget is offline
Frequent Poster
 
Join Date: Mar 2011
Location: Not Really Sure :/
Posts: 832
Default Re: Anti-virus can't keep up with threat onslaught

yeah try that when you are Studying IT

but Offline Machines are the Best Peace of Mind at the Moment
__________________
Spyshelter Premuim + MBAM Pro +Avast Free + Hardend FireFox + Secunia Update Checker
"Uncommon sense will increase your privacy; common sense will just make you common."
"The Worst Thing in the World is To look and not be able to Help "
  #27  
Old April 15th, 2012, 02:08 AM
Firecat's Avatar
Firecat Firecat is offline
Incredibly Massive Poster
 
Join Date: Jan 2005
Location: The land of no identity :D
Posts: 7,676
Default Re: Anti-virus can't keep up with threat onslaught

Just discovered a brand new facebook malware dropper. At the time, only "A" had a signature out (). Now, a few others also detect it.

I guess the real problem is that malware authors have a lot more time on their hands than people working on anti-malware products (on average). Thus, new variants are released faster than signature updates can be rolled out.
__________________
Last edited by Radu : Today, at 5:32 AM. Reason: Found new malicious code

  #28  
Old April 15th, 2012, 04:44 AM
Stefan Kurtzhals's Avatar
Stefan Kurtzhals Stefan Kurtzhals is offline
AV Expert
 
Join Date: Sep 2003
Posts: 625
Default Re: Anti-virus can't keep up with threat onslaught

There are alot of malware writers, or rather, people providing crypters/droppers aka "FUD service" (= fully undetected). These droppers drop the original trojan in memory, not to hard disk - your on-access scanner sees nothing. So if your malware wrapped in such a crypter gets detected (either by detecting the crypter or managing to decrypt the protection layer), just get the next crypter from another FUD service while the author of the first crypter adapts to the detection. Alas, it seems they make enough money to afford this.

In theory, these dropping method should be easy food for behaviour blockers, so I guess they adapt against that type of detection aswell because they still manage to bypass various behaviour blockers out there.

Just google for "tejon crypter", this is just one example of such a "tool". Check out it's "feature" list... :-(
__________________
Chuck Norris does not use any antivirus software. He knows the hashes of all clean software on earth. Even those that are not compiled yet. It is not known if he got that list from dividing by zero or counting to infinity.
  #29  
Old April 15th, 2012, 09:12 AM
Baserk's Avatar
Baserk Baserk is offline
Frequent Poster
 
Join Date: Apr 2008
Location: Amstelodamum
Posts: 975
Default Re: Anti-virus can't keep up with threat onslaught

Quote:
Originally Posted by Stefan Kurtzhals
...
Just google for "tejon crypter", this is just one example of such a "tool". Check out it's "feature" list... :-(

v1.7 New Engine! 2012

+Very Stable
+Very Powerful
+Obfuscator PE
+Bypass Kaspersky Internet Security 2012 (Included) (Proactive Defense)
+Bypass OutPost Firewall
+Bypass Zemana Keylogger (HIPS)
+Bypass Comodo Internet Security (HIPS)
+Bypass AntiHook (HIPS)
+Bypass SpyShelter (HIPS)
+Bypass Avast Antivirus (Proactive)
+Bypass Norton Internet Security (Proactive)
+Bypass Avast Antivirus
+Bypass Eset Nod32
+Bypass GData Internet Security
+Bypass TrustPort Antivirus
+Bypass Panda Internet Security
+Bypass Dr Web Antivirus
+Bypass Avira Internet Security
+Bypass Avg Internet Security
+Bypass AV360
+Bypass BitDefender & 2012+Anti AV Database Update
+Remove AV From Disk
+Major Icon Quality
+Clone File Properties
+Best Binder
+Speed Increase 300%
+Add Vista Resource Manifest
+Anti Avira Heuristic Detection
+Anti Nod32 Heuristic Detection
+Fix Pe Checksum
+Fake Error Generator
+Compatible (Windows 2000 / Xp / Vista / Windows 7 / Windows 8 [32/64Bits] )
+Script Support!

+Process Suspended
+Process Killer
+Run Only in Admin Mode
+Cannot Run in safe Mode
+Anti-Tracing (Anti Craking)
+Set File Atributes
+Anti Kaspersky (Kaspersky Bypass Proactive Defense)
+Binder
+Activex Registration
+Anti Heuristic Detection
+Anti-Firewall (ByPass)
+Vista UAC (ByPass)
+NEW Engine
+Very Stable

+File Bundle (DLL Bundle + Register ActiveX/OLE/COM control)
+Anti-Heuristic Detection
+Obfuscation of your executable helps protect it against tampering and cracking.
*Process Killer (Multiple Process Killer)
*Cannot Run in Safe Mode
*Run Only in Admin Mode
*Set File Attributes

*Anti-Shadow User Pro
*Anti-Clean Slate
*Anti Sandbox (Fortres)
*Run as Fake Process
*Delete Me (Execute & Delete RDG Loader)
*Anti JoeBox (Enhanced)
*Anti-Anubis (Enhanced)
*Anti-CWSandbox (Enhanced)
*Sleep Sec. Run program after x Seconds. 0 to 999 (Enhanced)
*Process Ghost
*Change Process Name

*Anti-Debugger
*Anti-Sandboxie
*Anti-virtualpc
*Realig Sections
*Anti-IDA Debugger
*Anti-CWSandbox
*Anti-Norman Sandbox
*Anti-Anubis
*OEP Stolen Bytes (Enhanced)
*Checksum CRC
*Anti-OllyDbg
*Anti-ThreatExpert
*Anti-JoeBox
*Anti-VMWARE
*Anti-VirtualBOX
*Anti-Debugger2
*Overlay support (EOF Data)
*Sleep Sec. Run program after x Seconds.
*Exceptions (0 to 1000)
*Get All Privileges
*Change Icon (Enhanced)

*OEP Stolen Bytes (Enhanced)
*Anti Virtual Machine (Max) = Heuristic
*Anti-SunBelt Sandbox
*Anti Deep-Freeze
*Anti-Returnil Vistual System
*Anti-Malware Defender
*Anti-Wine(Linux)
*Anti-Xen Virtual Machine
*Password Protect
*Execute With Command Line (parameters)
*UnHook All API
*Anti-Attach Loader (Protect RDG Loder)
*Execute as NT AUTHORITY\SYSTEM
*Restore API


Bugger. Indeed (if true oc)
__________________
ROMANES EUNT DOMUS

Last edited by Baserk : April 15th, 2012 at 09:51 AM.
  #30  
Old April 15th, 2012, 09:48 AM
blasev's Avatar
blasev blasev is offline
Frequent Poster
 
Join Date: Oct 2010
Posts: 641
Default Re: Anti-virus can't keep up with threat onslaught



if all above claim are true, its very frightening fact
I hope they are only exaggerating

they even have anti-sandboxie -> what's the meaning of this?
are they bypassing sandboxie?

Last edited by blasev : April 15th, 2012 at 09:54 AM.
  #31  
Old April 15th, 2012, 09:52 AM
3x0gR13N 3x0gR13N is offline
Frequent Poster
 
Join Date: May 2008
Posts: 581
Default Re: Anti-virus can't keep up with threat onslaught

Quote:
Originally Posted by blasev
they even have anti-sandboxie -> what's the meaning of this?
are they bypassing sandboxie?
No, it means the executable will detect it's running in the sandbox and will not deliver its real/malicious payload, thus evading analysis.
  #32  
Old April 15th, 2012, 09:55 AM
blasev's Avatar
blasev blasev is offline
Frequent Poster
 
Join Date: Oct 2010
Posts: 641
Default Re: Anti-virus can't keep up with threat onslaught

Quote:
Originally Posted by 3x0gR13N
No, it means the executable will detect it's running in the sandbox and will not deliver its real/malicious payload, thus evading analysis.

thanks for the answer
it's really re-assuring
  #33  
Old April 15th, 2012, 10:01 AM
Cutting_Edgetech's Avatar
Cutting_Edgetech Cutting_Edgetech is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: USA
Posts: 1,749
Default Re: Anti-virus can't keep up with threat onslaught

I would think Appguard would block it
__________________
Netgear Prosecure UTM25 | Online Armor | NOD 32 | WSA | Appguard | VoodooShield | Shadow Defender 1.1.0.325
  #34  
Old April 15th, 2012, 11:10 AM
Arcanez's Avatar
Arcanez Arcanez is offline
Frequent Poster
 
Join Date: Oct 2011
Posts: 283
Default Re: Anti-virus can't keep up with threat onslaught

Quote:
Originally Posted by Stefan Kurtzhals
- Chrome + AdBlock(Plus) plugin (or FireFox with NoScript+AdBlock)

I see a lot recommendations for these browsers lately, can anyone explain whats so good about google chrome? I use Opera for quiet a while now without any addons and I am very pleased with it. In the settings turned off javascript and only allow it for my favorite websites so I don't need an addon for that. I also have an e-mail client integrated and mouse gestures which are very comfortable.
__________________
AppGuard - Deep Freeze - EMET - Drive SnapShot - OpenDNS - NAT Router
  #35  
Old April 15th, 2012, 01:12 PM
Stefan Kurtzhals's Avatar
Stefan Kurtzhals Stefan Kurtzhals is offline
AV Expert
 
Join Date: Sep 2003
Posts: 625
Default Re: Anti-virus can't keep up with threat onslaught

Google is very fast in updating Chrome when there is a new exploit. It also does silent auto-update. I have seen many users blocking/ignoring the Firefox updates for example. Plus it does contain it's own version of Flash, not depending on Adobe updates. Sometimes Google even updated their version of Flash before Adobe.
__________________
Chuck Norris does not use any antivirus software. He knows the hashes of all clean software on earth. Even those that are not compiled yet. It is not known if he got that list from dividing by zero or counting to infinity.
  #36  
Old April 15th, 2012, 02:43 PM
Arcanez's Avatar
Arcanez Arcanez is offline
Frequent Poster
 
Join Date: Oct 2011
Posts: 283
Default Re: Anti-virus can't keep up with threat onslaught

thanks for the info, didn't know all that. The flash thing and the updates are a good argument. Only thing is I don't like tracking of google through their browser and I find opera to be more comfortable with mouse gestures, e-mail etc. AppGuard would also block all those chrome updates when they launch from user space. I would have to drop protection pretty often I guess which might be annoying. Also my opera runs sandboxed and emet protected all the time
__________________
AppGuard - Deep Freeze - EMET - Drive SnapShot - OpenDNS - NAT Router

Last edited by Arcanez : April 15th, 2012 at 02:49 PM.
  #37  
Old April 15th, 2012, 03:46 PM
Brandonn2010's Avatar
Brandonn2010 Brandonn2010 is offline
Very Frequent Poster
 
Join Date: Jan 2011
Posts: 1,247
Default Re: Anti-virus can't keep up with threat onslaught

Scary stuff. I'd like to see if it can bypass the almighty DefenseWall, since I see it wasn't listed on there.
__________________
OS: Windows 7 Pro x64 | First-Line: Norton DNS + Google Chrome | Realtime: Bitdefender Free Antivirus | On-Demand: HitmanPro Free + Malwarebytes Free | My Computer Security Website: Link
  #38  
Old April 15th, 2012, 04:35 PM
kdcdq kdcdq is online now
Frequent Poster
 
Join Date: Apr 2002
Location: Southwestern Massachusetts
Posts: 546
Default Re: Anti-virus can't keep up with threat onslaught

I was pleased to see the "bypass" and "anti" lists that Baserk listed did NOT include Webroot SecureAnywhere and/or Prevx.....
__________________
'Peace on Earth - Purity of Essence.'
- Dr. Strangelove

Last edited by kdcdq : April 15th, 2012 at 11:57 PM.
  #39  
Old April 15th, 2012, 07:04 PM
TonyW TonyW is offline
Very Frequent Poster
 
Join Date: Oct 2005
Location: UK
Posts: 2,309
Default Re: Anti-virus can't keep up with threat onslaught

Tejon Crypter was also discussed in this old thread.
  #40  
Old April 16th, 2012, 02:05 AM
Stefan Kurtzhals's Avatar
Stefan Kurtzhals Stefan Kurtzhals is offline
AV Expert
 
Join Date: Sep 2003
Posts: 625
Default Re: Anti-virus can't keep up with threat onslaught

Quote:
I was pleased to see the the "bypass" and "anti" lists that Baserk listed did NOT include Webroot SecureAnywhere and/or Prevx.....

Uhm, they bypass the regular detection of every AV scanner anyway, they don't even mention that "feature" anymore.
__________________
Chuck Norris does not use any antivirus software. He knows the hashes of all clean software on earth. Even those that are not compiled yet. It is not known if he got that list from dividing by zero or counting to infinity.
  #41  
Old April 16th, 2012, 11:49 AM
blasev's Avatar
blasev blasev is offline
Frequent Poster
 
Join Date: Oct 2010
Posts: 641
Default Re: Anti-virus can't keep up with threat onslaught

Now I'm confused, it can bypass Avira Internet Security, but it also has anti-Avira Heuristic Detection. So it means that if one person use avira standard setting which use heuristic detection , the malware wont run
  #42  
Old April 16th, 2012, 01:48 PM
Ilya Rabinovich Ilya Rabinovich is offline
Developer
 
Join Date: Sep 2005
Posts: 1,516
Default Re: Anti-virus can't keep up with threat onslaught

Quote:
Originally Posted by Brandonn2010
Scary stuff. I'd like to see if it can bypass the almighty DefenseWall, since I see it wasn't listed on there.
Yep, I'm really interested in it too. May I have a sample of it?
__________________
DefenseWall HIPS developer. www.softsphere.com
  #43  
Old April 16th, 2012, 02:12 PM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,551
Default Re: Anti-virus can't keep up with threat onslaught

Got the pocorn and cola ready. I am also Interested to see how Defensewall handles it and Appguard if any one tested it.
__________________
OS X 10.8.4 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
http://www.flickr.com/photos/darkshadow1911/
  #44  
Old April 16th, 2012, 02:59 PM
Stefan Kurtzhals's Avatar
Stefan Kurtzhals Stefan Kurtzhals is offline
AV Expert
 
Join Date: Sep 2003
Posts: 625
Default Re: Anti-virus can't keep up with threat onslaught

Actually I am looking for samples too. I am not going to buy that crypter just to test it.
__________________
Chuck Norris does not use any antivirus software. He knows the hashes of all clean software on earth. Even those that are not compiled yet. It is not known if he got that list from dividing by zero or counting to infinity.
  #45  
Old April 16th, 2012, 03:14 PM
3x0gR13N 3x0gR13N is offline
Frequent Poster
 
Join Date: May 2008
Posts: 581
Default Re: Anti-virus can't keep up with threat onslaught

I'm fairly certain that good* HIPSes, sandboxes and policy restriction sandboxes are immune to these kind of crypters. For example, malware x uses SeDebugPrivileges to elevate itself, HIPS like applications will notice the action because they monitor the API. When malware x is crypted via said crypter it won't change the fact that malware x uses SeDebugPrivileges, it's not changing the code itself, just cloaking it.

It's a bit of a different story with behavior blockers because of the way some are implementing protection. Some BBs are made so that if a certain set of actions are performed by malware x then a detection is triggered, opposed to a specific API in case of HIPS etc. Depending on how the detection ruleset is created it may give leeway to some evasion techniques employed by crypters.

I could be wrong though.

(by good I mean having system hooks that are not easily unhooked from usermode)
  #46  
Old April 16th, 2012, 03:27 PM
Stefan Kurtzhals's Avatar
Stefan Kurtzhals Stefan Kurtzhals is offline
AV Expert
 
Join Date: Sep 2003
Posts: 625
Default Re: Anti-virus can't keep up with threat onslaught

You would be surprised how many normal programs show "ugly" behaviour, causing false positives for behaviour blockers. So it is getting more difficult to find the balance between catching typical malware behaviour and false positives.

The malware writers are attacking behaviour blockers like normal scan engine detection, it just takes more work. But it also more difficult to update and QA new behaviour blocker rules.

And 64 bit did not make things easier for the AV programs. Actually, we lost of hooking abilities. You could say, 64 bit worked in favour of the malware writers. They still can do the things they want.
__________________
Chuck Norris does not use any antivirus software. He knows the hashes of all clean software on earth. Even those that are not compiled yet. It is not known if he got that list from dividing by zero or counting to infinity.
  #47  
Old April 16th, 2012, 04:18 PM
EASTER's Avatar
EASTER EASTER is offline
Massive Poster
 
Join Date: Jul 2007
Location: U.S.A. (South)
Posts: 4,601
Default Re: Anti-virus can't keep up with threat onslaught

And the trend is toward even more rapid migration over to 64 bit units for them to become the norm i guess.
I didn't see ThreatFire or Mamutu on the list of the anti's but then thats a very exhaustive list indeed. Anti-Deepfreeze, Returnil types apps are sure to be a good plug for some attention.

Noticed on their website in the lite version they mention the likes of Clam, ad-aware? etc. I surely would like to have a crack at a sample of it. We'll see who fishes this one up first. LoL

I never did fully understand why more attention wasn't given to pursuing more developments of (rule-based)? Behavioral Blockers then it was. They always had a particularly useful place IMO as an in-between for AS & AV's against the unknowns not yet detectable by the usual conventional security apps.
__________________
★AX64 Time Machine★
★Shadow Defender★| EQSecure v4.0 |Qihoo 360 Security Triple AV |FirstDefense-ISR|★FileChangeAlarm★ |Registry Backup VSS|
Maxthon 4 | X Iron 17.0 | Chromium 19.0 | Pale Moon 20.1

Microsoft Windows 8 64bit (UEFI/GPT) Secure Boot¶
¶Linux Mint 14 MATE¶
  #48  
Old April 18th, 2012, 10:01 AM
Escalader's Avatar
Escalader Escalader is offline
Massive Poster
 
Join Date: Dec 2005
Location: Land of the Mooses
Posts: 3,661
Default Re: Anti-virus can't keep up with threat onslaught

I think now after 40 years in the business I'll divide my own PC's into 2.

One with the best layered security I can muster that does 2 things only banking and private email. All connects to https only. ONLY MY WHITE LIST OF SITES VISITED.

The second machine (an iPAD?) does the risky stuff surfing, forum posts amazon book buying, movie watching, games etc etc


That's it using the old KISS concept.
__________________
Escalader
i7 8 GB RAM Notebook, 1TB External Drive
Sandboxie, Nod32, OP FW Pro, KeyScrambler, MVPS HOSTS File
IE 9 Hardened Active X,SmartScreen,Tracking Protection
Paragon Backup and Imaging
  #49  
Old April 19th, 2012, 03:46 AM
Noob's Avatar
Noob Noob is offline
Massive Poster
 
Join Date: Nov 2009
Posts: 5,330
Default Re: Anti-virus can't keep up with threat onslaught

Well, it's been fine for me and i hope it continues like that
__________________
Emsisoft Anti-Malware v7.0.0.21 - Online Armor 6.0.0.1736
SRP - UAC - EMET

Browser: Google Chrome v25.xx

Windows 7 Ultimate x64
  #50  
Old April 20th, 2012, 09:33 AM
Escalader's Avatar
Escalader Escalader is offline
Massive Poster
 
Join Date: Dec 2005
Location: Land of the Mooses
Posts: 3,661
Default Re: Anti-virus can't keep up with threat onslaught

Quote:
Originally Posted by Stefan Kurtzhals
Google is very fast in updating Chrome when there is a new exploit. It also does silent auto-update. I have seen many users blocking/ignoring the Firefox updates for example. Plus it does contain it's own version of Flash, not depending on Adobe updates. Sometimes Google even updated their version of Flash before Adobe.

Ever since Google went over the top on their new privacy policy I have avoided them and their products like the plague. Found I really don't need them.
__________________
Escalader
i7 8 GB RAM Notebook, 1TB External Drive
Sandboxie, Nod32, OP FW Pro, KeyScrambler, MVPS HOSTS File
IE 9 Hardened Active X,SmartScreen,Tracking Protection
Paragon Backup and Imaging
 

Wilders Security Forums > Security Products > other anti-virus software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 09:22 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums