Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-virus software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #176  
Old April 19th, 2009, 09:37 AM
Bob Bob is offline
Infrequent Poster
 
Join Date: Apr 2002
Posts: 49
Default Re: New MBR rootkit goes undetected

Are these rootkits only a problem for 32-bit systems
or can they now also infect vista 64-bit?
  #177  
Old April 19th, 2009, 03:04 PM
vijayind vijayind is offline
Very Frequent Poster
 
Join Date: Aug 2008
Posts: 1,413
Default Re: New MBR rootkit goes undetected

BluePill rootkit was developed on x64 systems only. So yes, x64 rootkits do exist (I guess)

http://northsecuritylabs.blogspot.co...blue-pill.html

also: http://bluepillproject.org/
  #178  
Old April 19th, 2009, 04:46 PM
steve1955's Avatar
steve1955 steve1955 is offline
Very Frequent Poster
 
Join Date: Feb 2004
Location: Sunny(in my dreams)Manchester,England
Posts: 1,237
Default Re: New MBR rootkit goes undetected

Quote:
Originally Posted by ffreedom01
Wow...with all the security you are running, I am surprised it wasn't picked up!
Perhaps the best idea is fill your HD with security apps so there's no room for any malware!
__________________
The part of a computer that causes most problems is the bit that holds the mouse!
  #179  
Old May 29th, 2009, 05:01 AM
MAOS MAOS is offline
Infrequent Poster
 
Join Date: Apr 2009
Posts: 15
Default Re: New MBR rootkit goes undetected

I just got the RSS feed report

http://www.prevx.com/blog/131/MBR-Rootkit-reloaded.html

Quote:
We have checked how many antirootkits are already able to detect the new version of MBR rootkit we've isolated two months ago. Result is that only five applications are able to fully detect this threat
  #180  
Old May 29th, 2009, 06:05 AM
Baz_kasp's Avatar
Baz_kasp Baz_kasp is offline
Frequent Poster
 
Join Date: May 2008
Location: London
Posts: 593
Default Re: New MBR rootkit goes undetected

Quote:
Originally Posted by MAOS


I assume if prevx is so worried about the lack of detection by other security vendors they have shared samples with the security community to combat such a "dangerous" threat....unless they are going to pull a "Dr.Web"

Last edited by Baz_kasp : May 29th, 2009 at 06:18 AM.
  #181  
Old May 29th, 2009, 06:18 AM
EraserHW's Avatar
EraserHW EraserHW is offline
Prevx Moderator
 
Join Date: Oct 2005
Location: Italy / UK
Posts: 584
Default Re: New MBR rootkit goes undetected

Quote:
Originally Posted by Baz_kasp
I assume if prevx is so worried about the lack of detection by other security vendors they have shared samples with the security community to combat such a "dangerous" threat....

Right I can assure you I personally shared all the samples I have with all companies that asked me for them. Sure, I'm not going to hunt for every single e-mail contact inside every single company and send samples in a spam-like way If anyone from security vendors want them, just ask for them I think it's the best way for everyone
__________________
Before you criticize someone, you should walk a mile in their shoes. That way when you criticize them, you are a mile away from them and you have their shoes
Check your PC in about a minute

Last edited by EraserHW : May 29th, 2009 at 06:30 AM.
  #182  
Old May 29th, 2009, 06:32 AM
Baz_kasp's Avatar
Baz_kasp Baz_kasp is offline
Frequent Poster
 
Join Date: May 2008
Location: London
Posts: 593
Default Re: New MBR rootkit goes undetected

Quote:
Originally Posted by EraserHW
Right I can assure you I personally shared all the samples I have with all companies that asked me for them. Sure, I'm not going to hunt every single e-mail contact inside every single company and send samples in a spam-like way If anyone from security vendors want them, just ask for them I think it's the best way for everyone

I think we both know about a certain place(s) where vendors meet for malware researching, makes sense to lay them out in there perhaps....I mean of course this is great that you found it and congratulations on the technical knowledge, props for being the first.... but if its something revolutionary collective intelligence is better than none.
  #183  
Old May 29th, 2009, 06:35 AM
EraserHW's Avatar
EraserHW EraserHW is offline
Prevx Moderator
 
Join Date: Oct 2005
Location: Italy / UK
Posts: 584
Default Re: New MBR rootkit goes undetected

Quote:
Originally Posted by Baz_kasp
I think we both know about a certain place(s) where vendors meet for malware researching, makes sense to lay them out in there perhaps....I mean of course this is great that you found it and congratulations on the technical knowledge, props for being the first.... but if its something revolutionary collective intelligence is better than none.

As you may know, inside certain places samples are available since April So they have been always available to everyone
__________________
Before you criticize someone, you should walk a mile in their shoes. That way when you criticize them, you are a mile away from them and you have their shoes
Check your PC in about a minute
  #184  
Old May 29th, 2009, 06:53 AM
Baz_kasp's Avatar
Baz_kasp Baz_kasp is offline
Frequent Poster
 
Join Date: May 2008
Location: London
Posts: 593
Default Re: New MBR rootkit goes undetected

Quote:
Originally Posted by EraserHW
As you may know, inside certain places samples are available since April So they have been always available to everyone


In which case I apologise since I missed that.
  #185  
Old May 29th, 2009, 06:54 AM
EraserHW's Avatar
EraserHW EraserHW is offline
Prevx Moderator
 
Join Date: Oct 2005
Location: Italy / UK
Posts: 584
Default Re: New MBR rootkit goes undetected

Quote:
Originally Posted by Baz_kasp
In which case I apologise since I missed that.

No problem at all You're more than welcome
__________________
Before you criticize someone, you should walk a mile in their shoes. That way when you criticize them, you are a mile away from them and you have their shoes
Check your PC in about a minute
  #186  
Old May 30th, 2009, 05:46 PM
developers developers is offline
Regular Poster
 
Join Date: Apr 2009
Posts: 62
Default Re: New MBR rootkit goes undetected

Quote:
Originally Posted by Saraceno
It's good seeing people test their security programs against this variation.

Maybe someone can test Shadow Defender? Would be interested to find out if a reboot removes the infection.

No, it's vulnerable.
  #187  
Old June 4th, 2009, 09:26 PM
MAOS MAOS is offline
Infrequent Poster
 
Join Date: Apr 2009
Posts: 15
Default Re: New MBR rootkit goes undetected

New variant of mebroot detected as vendors criticised for failing to react to threat
  #188  
Old June 5th, 2009, 03:09 AM
format_c's Avatar
format_c format_c is offline
Regular Poster
 
Join Date: May 2008
Posts: 116
Default Re: New MBR rootkit goes undetected

Dr.Web can neutralize all known modifications of the Backdoor.Maosboot including its latest variation discovered in May and still undefeated by any other anti-virus.
__________________
Using:
brains and hands
  #189  
Old June 10th, 2009, 10:48 AM
TonyW TonyW is offline
Very Frequent Poster
 
Join Date: Oct 2005
Location: UK
Posts: 2,301
Default Re: New MBR rootkit goes undetected

Interesting analysis by Sergey Golovanov at KL here.
  #190  
Old June 10th, 2009, 10:59 AM
raven211's Avatar
raven211 raven211 is offline
Very Frequent Poster
 
Join Date: May 2005
Posts: 2,552
Default Re: New MBR rootkit goes undetected


... and it says so on their own website - *applause*.

Last edited by raven211 : June 11th, 2009 at 07:53 AM.
 

Wilders Security Forums > Security Products > other anti-virus software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:05 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums