![]() |
|
#51
|
|||
|
|||
|
Quote:
i's like to know aboit latest CIS...please. |
|
#52
|
|||
|
|||
|
Quote:
|
|
#53
|
|||
|
|||
|
Quote:
That´s eufemistic, man! They are not bullet proof as advertised. Just look at Faronics or Returnil publicity and then look how they fail to restore a system where SafeSys or TDSS was executed. And do you know the best? They knew the publicity was wrong so they fooled customers on purpose. Faronics received reports about SafeSys bypassing their software 1 year ago. All this time they have been telling they were unable to reproduce or that they developers were investigating the issue. It´s incredible. In fact I consider this to be the biggest scandal in the security industry since some years ago some av vendors were announcing their products to have "100% virus detection".
__________________
http://bsa.isoftware.nl |
|
#54
|
|||
|
|||
|
Ok I resolved the issue with Shadow Defender. It was the OS difference on which the samples has been tested. I used Windows XP for windows 7, while Buster_BSA was using original XP as a host system and original XP as a guest system. Hence here's the difference in virus behaviour - the real XP system will not be infected after a malware execution in shadow mode and thus goes into reboot clean. That's what happened in Buster's case and mine after I installed VirtualBox with a real Windows XP. The Win7's version of Windows XP was infected and went onto reboot infected too. So to decide if Shadow Defender is bypassed or not is up to you
![]() I made a test on a real Windows 7 system which I'm using now (a clone of course) and here's what I got: Last edited by Leach : July 2nd, 2010 at 05:45 PM. |
|
#55
|
|||
|
|||
|
Quote:
If I missed this I apologize. Is anybody testing this on Windows 7 x64? Thanks. Hugger |
|
#56
|
||||
|
||||
|
curious to know i run returnil2008 and then open browser in sanboxie within returnil
can this be tested thanks |
|
#57
|
|||
|
|||
|
Quote:
Quote:
|
|
#58
|
||||
|
||||
|
You guys doing great... SandboxIE is really a nice and trusted application. Anyways i have tested Safe n Sec 2009 (ver. 3.5.1.865)... As per the vendor it provides proactive protection from known and unknown malicious software and Internet threats due to advanced technology of behavioral analysis and up-to-the-minute V.I.P.O (Valid Inside Permitted Operations) solution... V.I.P.O. (Valid Inside Permitted Operations) prevents malicious actions of any unknown and potentially dangerous application... So i have tested some Zero Day nasties and latest TDSS aka TDL3 .. I have executed all the threats, and allowed them to run on my system...and to be very honest TDL3 unable to infect my system. It kept under the VIPO user account of Safe n Sec but didn't able to infect me. I am unable to provide you the screen-shots because by tomorrow i'll show you the video of the same...so i thought why screen-shot.. Anyways even i really don't how to take screen-shots... ![]() Last but not least this application "Safe n Sec" deserves my two
__________________
∆√♪ηάکђ ℓєтک υηcσммpℓιcαтє http://www.adminus.net http://technonxt.wordpress.com |
|
#59
|
|||
|
|||
|
__________________
Enomis erzeugt passwortgeschützte 7-Zip/ZIP/RAR/SFX Archive von Dateien oder Ordnern durch einfaches Ziehen auf ein Desktopsymbol. Die Archive lassen sich mit Mustern wie Zeitstempel oder Version im Dateinamen und auch direkt bei Cloud-Speicherdiensten wie Dropbox ablegen. |
|
#60
|
||||
|
||||
|
Safe n Sec contains the rktrap antirootkit engine, can one scan for tdss on an already infected system with SnS and do you have any results
?
__________________
Who controls the past controls the future Who controls the present controls the past vmworld |
|
#61
|
|||
|
|||
|
Quote:
__________________
Enomis erzeugt passwortgeschützte 7-Zip/ZIP/RAR/SFX Archive von Dateien oder Ordnern durch einfaches Ziehen auf ein Desktopsymbol. Die Archive lassen sich mit Mustern wie Zeitstempel oder Version im Dateinamen und auch direkt bei Cloud-Speicherdiensten wie Dropbox ablegen. |
|
#62
|
||||
|
||||
|
Quote:
Roger that !! I'll try to test it against pre-infected system..But it will spoil my 1 and half hour.. Its really slow while updating and making system profile... ![]()
__________________
∆√♪ηάکђ ℓєтک υηcσммpℓιcαтє http://www.adminus.net http://technonxt.wordpress.com |
|
#63
|
|||
|
|||
|
Hi:
The tdss/tdl rootkit that originaly infected my pc even with CIS set to highrest setting and even scanning with comodo and a-squares, malwarebyte, superantispyware all did not detect and time freeze failed and it infected the atapi.sys driver (hitman identified it as atapi.sys rootkit) that was very new. Perhapse can anyone test this particular rootkit against these security softwares? I think I may have gotten it through malwaredomainlist site link testing. So I think the atapi rootkit is a badass one. SO if you guys can test this rootkit as well would be great. |
|
#64
|
||||
|
||||
|
Quote:
Yeah, SafeSys would require the load driver privilege, and limited users don't have that, so SafeSys would do nothing. TDSSKiller also requires that privilege, so it can only run as admin. So to test whether one managed to get the entire system infected from a limited user account, one would have to log in as admin to run tests like TDSSKiller. MBAM always acted weird under LUA, but then, stuff like that should be run with admin privileges, so it can look as deep in the system as possible. ![]()
__________________
Save your tears, for your tears will not save you :: Shameless LUA troll |
|
#65
|
||||
|
||||
|
Quote:
__________________
Who controls the past controls the future Who controls the present controls the past vmworld |
|
#66
|
|||
|
|||
|
Shadow Defender 1.1.0.326 is infected in VBOX unlike 325. And TDSS keeps behaving strangely in VBOX - kills himself after detecting with TDSSKiller so there's no need in TDSSKiller any more to cure the system. Don't think behaviour should be investigated in VBOX but rather in VPC, VPC with W7's XP system seems frightens the virus much less and results are more stable. What do you think?
Correction: 1. TDSS kills itself after being detected with TDSSKiller in VPC too. 2. TDSSKiller seems trying to restore the normal state of the infected DLL after restart. 3. Windows Defender detects now that critter. Last edited by Leach : July 3rd, 2010 at 05:18 PM. |
|
#67
|
|||
|
|||
|
Power Shadow v2.6 is bypassed time to time by TDSS TDL.
|
|
#68
|
||||
|
||||
|
XP VM.
Testing safesys.exe and beta Returnil Virtual System Lite 2011 using the memory cache. On the first run of safesys.exe and rebooting out of Returnil mode Malwarebytes finds one suss reg key: Quote:
Reboot again out of Returnil mode and a scan with MBAM shows all clear?
__________________
Lean, Mean and Clean! Sandboxie, Buster Sandbox Analyser, Returnil 2008, Microsoft Virtual PC 2007 SP1, Drive Snapshot
|
|
#69
|
||||
|
||||
|
Originally Posted by Franklin
Quote:
I like the memory cache approach Quote:
I have spooler disabled as i use another comp for printing. I wonder if some of these RK's would be fooled etc if tested in this way ?Quote:
Not being funny, but can you be sure MBAM caught everything. What if you used the available removal tools to also check for remnants, or worse ? And for eg Gmer/Rku ? Also as you tested in VM, maybe you would get different results without ? Plus what would happen if you didn't use MBAM after RVS reboot ? TIA
__________________
. Malware = You don't scare me A different perspective https://rt.com - https://rt.com/on-air |
|
#70
|
|||
|
|||
|
Quote:
Quote:
Sandboxed TDSS did nothing, the system is not affected. Normally launched TDSS gave the same warning and infected the system, as it should ![]() Last edited by Leach : July 4th, 2010 at 02:56 AM. |
|
#71
|
||||
|
||||
|
Quote:
MBAM seems to cleanup all dregs of the infection finding around 130 entries after safesys.exe is installed with most being the image execution reg hijacks. Will test further a bit later.
__________________
Lean, Mean and Clean! Sandboxie, Buster Sandbox Analyser, Returnil 2008, Microsoft Virtual PC 2007 SP1, Drive Snapshot
|
|
#72
|
||||
|
||||
|
Quote:
__________________
|
|
#73
|
|||
|
|||
|
Leach thanks for the report,very informative.
|
|
#74
|
||||
|
||||
|
Quote:
not yet they don't, but they do detect it's injected modules even in the latest release and hold their payloads, like most updated malwares do against sandboxie. If there is a memory corruption or a way to use native API to detach sandboxie you'll see it in one of these industrial rootkits first. EDIT: Some variants in the 7.10.09.10 Avira DB now defeat NIS 2011 and some other solutions btw..
__________________
Having the audacity to be honest about security products for fun and profit. |
|
#75
|
|||
|
|||
|
Quote:
![]()
__________________
Windows 95, no security updates, no AV, no firewall. works just as i expected. Light virtualization software / Partial sandbox test : the truth about rollback software |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|