Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-virus software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 4th, 2010, 02:28 PM
Gasp Gasp is offline
Regular Poster
 
Join Date: Jan 2010
Posts: 82
Default Panda Failure

I've just been round to fix my friends computer after he reported it was playing up. When checking it, it was pretty obvious why he was experiencing so many problems. The computer was rammed with Malware, ss you'll see from the MBAM Log.

Interestingly the computer was running Panda Cloud AntiVirus & ThreatFire. After checking the ThreatFire log, it did pickup some suspicious files but they were allowed by the user. However Panda didn't detect anything. I even scanned some of the trojans directly with Panda and no results. And yes, the computer was online.

Some of the nasties:
Trojan.Vundo
Trojan.Hiloti
Trojan.Fraudpack
Trojan.Dropper
Worm.Allaple
Backdoor.Bot
Rootkit.Agent
Rootkit.TDSS
Malware.Trace
Spyware.Zbot
Rogue.YourProtection
Rogue.SpywareBot
Rogue.PrivacyConductor
Rogue.SecurePCCleaner
Rogue.RegistrySmart
Rogue.Multiple
Adware.MyWebSearch
Adware.180Solutions
Adware.Seekmo
Adware.ShopperReports
Adware.Zango

All the above were removed with MBAM and the computer booted fine.
When later uninstalled Panda only to find after rebooting a wall of BSODs.

I think a format / reinstall is going to be the fatest solution here now.
  #2  
Old April 4th, 2010, 03:14 PM
dw426 dw426 is offline
Massive Poster
 
Join Date: Jan 2007
Posts: 5,543
Default Re: Panda Failure

There may be more to this than is posted here, so I can't say much about Panda, but ouch. TDSS I can understand, as the last I checked VERY few apps caught this. 180Solutions, Zango, Vundo, these should be detected by a lot of apps by now. 180Solutions was being detected by Spybot when people still loved that app, so I don't know what to think of that.
  #3  
Old April 4th, 2010, 03:42 PM
Brocke's Avatar
Brocke Brocke is offline
Updates Team
 
Join Date: Mar 2008
Location: USA,IA
Posts: 1,644
Default Re: Panda Failure

PCA is still young, version 1.1 soon will be beta will ofter alot more protection.

a BB, self protection, auto updates, etc.
  #4  
Old April 4th, 2010, 03:51 PM
Gasp Gasp is offline
Regular Poster
 
Join Date: Jan 2010
Posts: 82
Default Re: Panda Failure

Yes but it should have got something surely? Plus, when I uninstalled it, it ~Snip~ the system up totally so a format is necessary anyway now.

Last edited by ronjor : April 4th, 2010 at 04:25 PM. Reason: Possibly offensive phrase removed
  #5  
Old April 4th, 2010, 04:03 PM
vojta vojta is offline
Frequent Poster
 
Join Date: Feb 2010
Posts: 464
Default Re: Panda Failure

Quote:
Originally Posted by Gasp
Yes but it should have got something surely? Plus, when I uninstalled it, it ~Snip~ the system up totally so a format is necessary anyway now.

Honestly, the system seemed to be quite ~Snip~ by the user:

Quote:
Originally Posted by Gasp

Some of the nasties:
Trojan.Vundo
Trojan.Hiloti
Trojan.Fraudpack
Trojan.Dropper
Worm.Allaple
Backdoor.Bot
Rootkit.Agent
Rootkit.TDSS
Malware.Trace
Spyware.Zbot
Rogue.YourProtection
Rogue.SpywareBot
Rogue.PrivacyConductor
Rogue.SecurePCCleaner
Rogue.RegistrySmart
Rogue.Multiple
Adware.MyWebSearch
Adware.180Solutions
Adware.Seekmo
Adware.ShopperReports
Adware.Zango

You don't catch all this at Wikipedia.

Last edited by ronjor : April 4th, 2010 at 04:27 PM. Reason: Possibly offensive phrase removed
  #6  
Old April 4th, 2010, 04:10 PM
PC__Gamer's Avatar
PC__Gamer PC__Gamer is offline
Frequent Poster
 
Join Date: Dec 2009
Posts: 526
Default Re: Panda Failure

well, forgive me if im wrong, but this all seems a little theatre-like,

like its been acted out to show Panda's failings in these particular infections.

__________________
Webroot SecureAnywhere Complete
  #7  
Old April 4th, 2010, 04:11 PM
Brocke's Avatar
Brocke Brocke is offline
Updates Team
 
Join Date: Mar 2008
Location: USA,IA
Posts: 1,644
Default Re: Panda Failure

Quote:
Originally Posted by PC__Gamer
well, forgive me if im wrong, but this all seems a little theatre-like,

like its been acted out to show Panda's failings in these particular infections.



i agree, all those infections, i mean they must be going to some shady sites.
  #8  
Old April 4th, 2010, 04:13 PM
pbust's Avatar
pbust pbust is offline
AV Expert
 
Join Date: Apr 2009
Location: Spain
Posts: 1,173
Default Re: Panda Failure

I'm sorry but I find this a little hard to believe. Please send me the samples that were not detected by Panda in order to verify this claim.
  #9  
Old April 4th, 2010, 04:23 PM
Brocke's Avatar
Brocke Brocke is offline
Updates Team
 
Join Date: Mar 2008
Location: USA,IA
Posts: 1,644
Default Re: Panda Failure

Quote:
Originally Posted by pbust
I'm sorry but I find this a little hard to believe. Please send me the samples that were not detected by Panda in order to verify this claim.


if he does post the results here please for all of to see.

thanks
Pbust
  #10  
Old April 4th, 2010, 04:40 PM
Cudni's Avatar
Cudni Cudni is offline
Global Moderator
 
Join Date: May 2009
Location: Somethingshire
Posts: 6,944
Default Re: Panda Failure

Quote:
Originally Posted by Brocke
if he does post the results here please for all of to see.

thanks
Pbust

it would be interesting but somehow doubtful they will be forthcoming
Quote:
Originally Posted by Gasp
I think a format / reinstall is going to be the fatest solution here now.
__________________
once we only had ideals, today they are the only things we are missing
Microsoft MVP, 2006 - 2013/14
  #11  
Old April 4th, 2010, 04:53 PM
Noob's Avatar
Noob Noob is offline
Massive Poster
 
Join Date: Nov 2009
Posts: 5,330
Default Re: Panda Failure

Quote:
Originally Posted by Cudni
it would be interesting but somehow doubtful they will be forthcoming
Yeah, he already stated he deleted them with MBAM xD
__________________
Emsisoft Anti-Malware v7.0.0.21 - Online Armor 6.0.0.1736
SRP - UAC - EMET

Browser: Google Chrome v25.xx

Windows 7 Ultimate x64
  #12  
Old April 4th, 2010, 04:53 PM
Gasp Gasp is offline
Regular Poster
 
Join Date: Jan 2010
Posts: 82
Default Re: Panda Failure

@PC__Gamer
theatre-like sites lol! He did say that he'd been looking at those "theatre-like" sites prior to the issues. Although I'd be suprised if they were all from pr0n sites.

@pbust
All the malware has been Quarantined and deleted successfully by MBAM so I don't think I am able to send this now. For future reference, how do you want me to submit the malware to you?

I un-installed Panda hoping to download and re-install a newer version but after doing the uninstall the computer BSODs at boot. Any ideas what caused this?
  #13  
Old April 4th, 2010, 05:07 PM
zfactor's Avatar
zfactor zfactor is offline
Massive Poster
 
Join Date: Mar 2005
Location: on my zx10-r
Posts: 4,301
Default Re: Panda Failure

i have been testing panda cloud and to be honest its not that bad. if it really did miss all of those imo there may have been a more underlying cause for it. yes panda cloud does miss some things but no way is it that bad.
__________________
Meatwad you're up next, with your knock-knock.
Meatwad make the money see. Meatwad get the honeys G. Drivin in my car, living like a star ice on my fingers and my toes, and im a taurus

"Some days your the windshield. Some days your the bug"
Eset ESS V6 / Webroot WSA / Avast! IS V8
  #14  
Old April 4th, 2010, 05:19 PM
Gasp Gasp is offline
Regular Poster
 
Join Date: Jan 2010
Posts: 82
Default Re: Panda Failure

Quote:
Originally Posted by zfactor
i have been testing panda cloud and to be honest its not that bad. if it really did miss all of those imo there may have been a more underlying cause for it. yes panda cloud does miss some things but no way is it that bad.

If we assume something was blocking the internet connection that might explain part of it??
  #15  
Old April 4th, 2010, 05:35 PM
Brocke's Avatar
Brocke Brocke is offline
Updates Team
 
Join Date: Mar 2008
Location: USA,IA
Posts: 1,644
Default Re: Panda Failure

Quote:
Originally Posted by Gasp
If we assume something was blocking the internet connection that might explain part of it??


well PCA does use a offline cache, but still all of those not even been seen by PCA its hard to believe.
  #16  
Old April 4th, 2010, 05:44 PM
Gasp Gasp is offline
Regular Poster
 
Join Date: Jan 2010
Posts: 82
Default Re: Panda Failure

If the computer is offline and one of the trojans corrupted the signature files, would that knock off the panda protection?
  #17  
Old April 4th, 2010, 06:02 PM
Ibrad's Avatar
Ibrad Ibrad is offline
Very Frequent Poster
 
Join Date: Dec 2009
Posts: 1,887
Default Re: Panda Failure

Are you 100% sure Panda Cloud was running? Maybe some of the malware killed the protection service.
__________________
Panda Security TRUSTED MOD


Panda Cloud Antivirus + Rising PC Doctor + Common Sense

My Security Blog: http://igl-security.blogspot.com/
  #18  
Old April 4th, 2010, 06:04 PM
pbust's Avatar
pbust pbust is offline
AV Expert
 
Join Date: Apr 2009
Location: Spain
Posts: 1,173
Default Re: Panda Failure

Gasp, do you know if the malware was on the system *before* Panda Cloud AV was installed? It could be any one of those you mentioned crippled the connection and/or prevented PCA from accessing its scanning servers. Did you run a full scan with PCA? If so, can you post the results? Also you mentioned the malware was quarantined by MBAM. Can you restore it and send it to me?
  #19  
Old April 4th, 2010, 06:34 PM
Gasp Gasp is offline
Regular Poster
 
Join Date: Jan 2010
Posts: 82
Default Re: Panda Failure

Panda Cloud was installed on a new clean build of XP so no malware then. I am very sure Panda was running when I last checked. The system was running on spoof name servers which could explain a loss in connection to Panda Cloud.

The system isn't bootable or restorable its completely wrecked now with the BSODs.
  #20  
Old April 4th, 2010, 06:49 PM
Gasp Gasp is offline
Regular Poster
 
Join Date: Jan 2010
Posts: 82
Default Re: Panda Failure

My friend (or maybe its his kids) has a history of opening unknown files on the internet and infecting his PC with all sorts of crap. Like I said the ThreatFire log confirmed that he had allowed some of the malware. I think what happened here is he's had a 0day drive-by download on a "theatre-like" site which he has allowed and run. This has either blocked his internet and corrupt the Panda signatures, or downloaded another app which has done this.

I am upgrading him to Windows 7 tomorrow so we can review his security. What would you recommend for someone which opens everything? I am tempted to use something like Returnil to return his system back to normal after every reboot. Or should I go for a free HIPs instead?

Limited User Account - This will stop him or his kids installing new apps/files.
Microsoft Security Essentials - Its free and very easy to use.
Malware Bytes - On-demand malware scanning.
SAS - On-demand malware scanning.
Comodo Time Machine - For when it all goes wrong again.

Last edited by Gasp : April 4th, 2010 at 06:57 PM.
  #21  
Old April 4th, 2010, 07:09 PM
andyman35 andyman35 is offline
Very Frequent Poster
 
Join Date: Nov 2007
Posts: 2,288
Default Re: Panda Failure

Gasp.
I'd go with Returnil to save your friend from himself.It does seem that he managed to get an extraordinary amount of malware onto his system.It's no mean feat to get yourself that infected as I found out when running a VM without any security software to test CTM a while ago.

It seems unlikely that Panda (and Threatfire too) would fail so dramatically during normal usage,there must be more to it.
  #22  
Old April 4th, 2010, 07:17 PM
dw426 dw426 is offline
Massive Poster
 
Join Date: Jan 2007
Posts: 5,543
Default Re: Panda Failure

If you HAVE to go to a deny/allow approach, do it through LUA. HIPs in the hands of the less knowledgeable and/or uncaring is just as dangerous as malware itself.
  #23  
Old April 4th, 2010, 07:36 PM
Konata Izumi's Avatar
Konata Izumi Konata Izumi is offline
Very Frequent Poster
 
Join Date: Nov 2008
Posts: 1,521
Default Re: Panda Failure

no conficker?
  #24  
Old April 4th, 2010, 07:38 PM
Gasp Gasp is offline
Regular Poster
 
Join Date: Jan 2010
Posts: 82
Default Re: Panda Failure

No why ?
  #25  
Old April 4th, 2010, 07:40 PM
Gasp Gasp is offline
Regular Poster
 
Join Date: Jan 2010
Posts: 82
Default Re: Panda Failure

Quote:
Originally Posted by dw426
If you HAVE to go to a deny/allow approach, do it through LUA. HIPs in the hands of the less knowledgeable and/or uncaring is just as dangerous as malware itself.

How about if we went with Sandboxie or Geswall instead of the strong hips?
 

Wilders Security Forums > Security Products > other anti-virus software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:28 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums