Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-virus software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 15th, 2002, 12:57 PM
Technodrome's Avatar
Technodrome Technodrome is offline
Global Moderator
 
Join Date: Feb 2002
Location: New York
Posts: 2,140
Default 8 Virus Scanners vs 3 infected files!

A couple nights ago I received (voluntarily) 3 files from some IRC channel! They were xxx.dll.xxx.exe (I won’t name them) for a security reasons. The length of these files was the same size (9.21 Kb). I knew they could be a potential malicious code (in fact they were)…Files were written in pure assembly language with use of slavic language. I decided to play with these files just for fun of it.

During download, my primary virus scanner didn’t pick them as infected. No surprise here, these files were fairly strange. I decided to use another virus scanner to check these file for possible infection. Better yet, to test heuristics analyzers!

Here are results:
Kaspersky AV without heuristics- Nothing
Kaspersky AV with heuristics – Nothing

DrWeb32 AV without heuristics- Nothing
DrWeb32 AV with heuristics – Nothing

Command AV with heuristics (automatically) – Nothing

F-Secure with heuristics (automatically) – Nothing

RAV 8.6 (engine 8.7) without heuristics- Nothing
RAV 8.6 (engine 8.7) with heuristics – Nothing

NOD32 1.298 without heuristics- Nothing
NOD32 1.298 with heuristics (deep) – Nothing

Sophos 3.60 without heuristics- Nothing (sophos av uses no heuristics)

F-Prot 3.12a without heuristics- Nothing
F-Prot 3.12a with heuristics – Nothing
F-Prot 3.12a with enabled neural heuristics – 3 suspicious files found

In this particular case 6 heuristics engines failed to identify infected files. F-Prot was the only one able (by using extra strength heuristics) to identified files as suspicious.


Technodrome
Attached Images
 
__________________
Classic Trance Hit: PPK - Resurrection
  #2  
Old August 15th, 2002, 02:59 PM
wizard's Avatar
wizard wizard is offline
Frequent Poster
 
Join Date: Feb 2002
Location: Europe - Germany - Duesseldorf
Posts: 818
Default Re:8 Virus Scanners vs 3 infected files!

What was the malicious activity of that file? Virus? Trojan?

wizard
__________________
wizardRESEARCH - Malware Research & Analysis since 1989
  #3  
Old August 15th, 2002, 03:54 PM
Technodrome's Avatar
Technodrome Technodrome is offline
Global Moderator
 
Join Date: Feb 2002
Location: New York
Posts: 2,140
Default Re:8 Virus Scanners vs 3 infected files!

It was a Virus. After executing, it deleted files from local drives. Similar to W97M/Melissa activities. I'd say very classic one. I believe it also damaged my system BIOS(not sure still investigating)...
Pretty powerful virus. My old computer suffered a great deal of pain.

Is there a twist between CIH and W97M? I head rumor that VXers are working on new version of CIH.



Technodrome
__________________
Classic Trance Hit: PPK - Resurrection
  #4  
Old August 15th, 2002, 06:05 PM
minacross's Avatar
minacross minacross is offline
Frequent Poster
 
Join Date: May 2002
Location: Egypt
Posts: 653
Default Re:8 Virus Scanners vs 3 infected files!

could you please check them with NAV2002 and Pc-cillin2002 and tell us the result ??
  #5  
Old August 15th, 2002, 06:33 PM
Technodrome's Avatar
Technodrome Technodrome is offline
Global Moderator
 
Join Date: Feb 2002
Location: New York
Posts: 2,140
Default Re:8 Virus Scanners vs 3 infected files!

I am sorry but I don't have those two products!


Technodrome
__________________
Classic Trance Hit: PPK - Resurrection
  #6  
Old August 15th, 2002, 07:02 PM
minacross's Avatar
minacross minacross is offline
Frequent Poster
 
Join Date: May 2002
Location: Egypt
Posts: 653
Default Re:8 Virus Scanners vs 3 infected files!

could you guide us where we can get these virus files??
i have both nav2001 and pcc2002 to check them with.
  #7  
Old August 15th, 2002, 08:02 PM
FanJ
 
Posts: n/a
Default Re:8 Virus Scanners vs 3 infected files!

Quote:
quoting: minacross link=board=24;threadid=3030;start=0#20496 date=1029452579]
could you guide us where we can get these virus files??
i have both nav2001 and pcc2002 to check them with.


Sorry Minacross,

We don't give links to those places.
  #8  
Old August 15th, 2002, 08:54 PM
Technodrome's Avatar
Technodrome Technodrome is offline
Global Moderator
 
Join Date: Feb 2002
Location: New York
Posts: 2,140
Default Re:8 Virus Scanners vs 3 infected files!

Quote:
quoting: minacross link=board=24;threadid=3030;start=0#20496 date=1029452579]
could you guide us where we can get these virus files??
i have both nav2001 and pcc2002 to check them with.


Not me! Maybe someone else.


Technodrome
__________________
Classic Trance Hit: PPK - Resurrection
  #9  
Old August 15th, 2002, 09:48 PM
kdcdq kdcdq is offline
Frequent Poster
 
Join Date: Apr 2002
Location: Southwestern Massachusetts
Posts: 546
Default Re:8 Virus Scanners vs 3 infected files!

Hello Technodrome and all,

I am willing to run/test the same virus-infected files that Technodrome used with the following products (all legally licensed to me) to see if any of them can detect the "stealth" virus that Technodrome found:

. Computer Associates eTrust EZ Antivirus
. McAfee VirusScan v6
. NAV 2001 and/or NAV2002
. Panda AntiVirus Platinum
. PCC2000
. PCC2002
. VirusBuster

Thats why they call me:
KDCDQ, Security Freak
__________________
'Peace on Earth - Purity of Essence.'
- Dr. Strangelove
  #10  
Old August 16th, 2002, 12:04 AM
grey_ghost's Avatar
grey_ghost grey_ghost is offline
Regular Poster
 
Join Date: Apr 2002
Posts: 60
Default Re:8 Virus Scanners vs 3 infected files!

Hi,

I was wondering if you could check those files with the DrWeb and Kaspersky online tests?

I had a suspicious file a couple of days ago and my Kav4 missed it.
When I checked with DrWeb online it identified it.

Regards
__________________
Gerry
  #11  
Old August 16th, 2002, 12:11 AM
Technodrome's Avatar
Technodrome Technodrome is offline
Global Moderator
 
Join Date: Feb 2002
Location: New York
Posts: 2,140
Default Re:8 Virus Scanners vs 3 infected files!

I am sorry kdcdq but I won't provide these files to anyone! I did this test for myself and decided to share only text version with you! There is no need to get curios over this. I just wanted to point out that sometimes, use of strong heuristics can be useful (if you know what you're doing).

This test result is not suitable to measure anti-virus product because, on the one hand I am not professional and on the other hand only 3 samples were used.


Technodrome
__________________
Classic Trance Hit: PPK - Resurrection
  #12  
Old August 16th, 2002, 12:15 AM
Technodrome's Avatar
Technodrome Technodrome is offline
Global Moderator
 
Join Date: Feb 2002
Location: New York
Posts: 2,140
Default Re:8 Virus Scanners vs 3 infected files!

Quote:
quoting: grey_ghost link=board=24;threadid=3030;start=0#20513 date=1029470681]
Hi,

I was wondering if you could check those files with the DrWeb and Kaspersky online tests?

I had a suspicious file a couple of days ago and my Kav4 missed it.
When I checked with DrWeb online it identified it.

Regards

Missed by both products.


Technodrome
__________________
Classic Trance Hit: PPK - Resurrection
  #13  
Old August 16th, 2002, 12:34 AM
Mr.Blaze's Avatar
Mr.Blaze Mr.Blaze is offline
The Newbie Welcome Wagon
 
Join Date: Feb 2003
Location: on the sofa
Posts: 2,842
Default Re:8 Virus Scanners vs 3 infected files!

what the mo jo all that does is scare me arnt you supose to supply us with a since of security what do you plan to do with those nastys i can get nastys to lol i use to go to places you aint even seen till i made wilders my home.

i think you should give them to the major tech guys here at wilders to test it out so us newbys can get the right software to fight these guys or if are current software will protect us.

i think thats fair not saying hand it to a newby bad cyber candy =)
__________________
i am blazes rageing fur ball of fury dont let the small paws fool you my claws retract like wolverin, err when I'm not babysitting Jooskes mouse
  #14  
Old August 16th, 2002, 12:44 AM
Technodrome's Avatar
Technodrome Technodrome is offline
Global Moderator
 
Join Date: Feb 2002
Location: New York
Posts: 2,140
Default Re:8 Virus Scanners vs 3 infected files!

Quote:
quoting: MRBLAZE link=board=24;threadid=3030;start=0#20524 date=1029472441]
i think you should give them to the major tech guys here at wilders to test it out so us newbys can get the right software to fight these guys or if are current software will protect us.


These file will be shredded by using DoD 5220.22-M, NISPOM 8 - 306 standard!

Ever heard about Guillotin MR Blaze? This is even worse!


Technodrome
__________________
Classic Trance Hit: PPK - Resurrection
  #15  
Old August 16th, 2002, 03:48 AM
zappa zappa is offline
Regular Poster
 
Join Date: Feb 2002
Location: Los Angeles, Ca.
Posts: 176
Default Re:8 Virus Scanners vs 3 infected files!

LOL. The net paranoia is alive and well. Me included. I know the answer but I'm going to chime in too before the Swing Low Sweet Chariot song plays at your place?

Can you send them to Paul W. so he can send them to Eset? LOL. Please?
  #16  
Old August 16th, 2002, 04:20 AM
SKA SKA is offline
Regular Poster
 
Join Date: Aug 2002
Posts: 151
Default Re:8 Virus Scanners vs 3 infected files!

Technodrome,

1. What OS were you using F-Prot on please ?

2. Would you say heuristics of F-Prot 3.12a Win version proves more aggressive than Nod32/DrWeb/KAV4 or would you say this is just one test case that's lucky for F-Prot and unlucky for others ?

SKA
  #17  
Old August 16th, 2002, 07:50 AM
Technodrome's Avatar
Technodrome Technodrome is offline
Global Moderator
 
Join Date: Feb 2002
Location: New York
Posts: 2,140
Default Re:8 Virus Scanners vs 3 infected files!

Quote:
quoting: SKA link=board=24;threadid=3030;start=15#20560 date=1029486046]
Technodrome,

1. What OS were you using F-Prot on please ?

2. Would you say heuristics of F-Prot 3.12a Win version proves more aggressive than Nod32/DrWeb/KAV4 or would you say this is just one test case that's lucky for F-Prot and unlucky for others ?

SKA

Hi SKA

1.Windows XP & 98

2. F-Prot has pretty aggressive neural heuristics, but this doesn't prove anything! More testing must be done to clearly answer your 2nd question!


Technodrome
__________________
Classic Trance Hit: PPK - Resurrection
  #18  
Old August 16th, 2002, 09:29 AM
Mr.Blaze's Avatar
Mr.Blaze Mr.Blaze is offline
The Newbie Welcome Wagon
 
Join Date: Feb 2003
Location: on the sofa
Posts: 2,842
Default Re:8 Virus Scanners vs 3 infected files!

yeah that way we know what program is up to date.

i mean if you got ahold of these how long till it comes for us in the wild have you notified some one?

it like saying theres this horriable thing out there and its comeing for you cheers have fun lol.

panic panic=)
__________________
i am blazes rageing fur ball of fury dont let the small paws fool you my claws retract like wolverin, err when I'm not babysitting Jooskes mouse
  #19  
Old August 16th, 2002, 09:39 AM
MyNethingyman
 
Posts: n/a
Default Re:8 Virus Scanners vs 3 infected files!

Something just is not making sense here...but it was an interesting post. I will just leave it at that.
  #20  
Old August 16th, 2002, 10:35 AM
controler's Avatar
controler controler is offline
Massive Poster
 
Join Date: Jun 2002
Posts: 3,268
Default Re:8 Virus Scanners vs 3 infected files!

Try NAV 2003 please ?
  #21  
Old August 16th, 2002, 10:49 AM
Technodrome's Avatar
Technodrome Technodrome is offline
Global Moderator
 
Join Date: Feb 2002
Location: New York
Posts: 2,140
Default Re:8 Virus Scanners vs 3 infected files!

Quote:
quoting: MyNethingyman link=board=24;threadid=3030;start=15#20591 date=1029505162]
Something just is not making sense here...but it was an interesting post. I will just leave it at that.

Life doesn't make sense sometimes....But we live!


Technodrome
__________________
Classic Trance Hit: PPK - Resurrection
  #22  
Old August 16th, 2002, 11:02 AM
kdcdq kdcdq is offline
Frequent Poster
 
Join Date: Apr 2002
Location: Southwestern Massachusetts
Posts: 546
Default Re:8 Virus Scanners vs 3 infected files!

Hey Technodrome,

If you ever run any more "Virus Scanners vs infected files" tests and need/want to test them against the AV products in my previous posting, I would be more than willing to assist in any way possible.

Good luck in the future,
KDCDQ, Security Freak
__________________
'Peace on Earth - Purity of Essence.'
- Dr. Strangelove
  #23  
Old August 16th, 2002, 11:13 AM
Technodrome's Avatar
Technodrome Technodrome is offline
Global Moderator
 
Join Date: Feb 2002
Location: New York
Posts: 2,140
Default Re:8 Virus Scanners vs 3 infected files!

KDCDQ,you are a real Security Freak!!!

I'll let you know!


Technodrome
__________________
Classic Trance Hit: PPK - Resurrection
  #24  
Old August 16th, 2002, 12:14 PM
wizard's Avatar
wizard wizard is offline
Frequent Poster
 
Join Date: Feb 2002
Location: Europe - Germany - Duesseldorf
Posts: 818
Default Re:8 Virus Scanners vs 3 infected files!

Quote:
quoting: SKA link=board=24;threadid=3030;start=15#20560 date=1029486046]
2. Would you say heuristics of F-Prot 3.12a Win version proves more aggressive than Nod32/DrWeb/KAV4 or would you say this is just one test case that's lucky for F-Prot and unlucky for others ?

IMHO the heuristic of F-Prot is better than KAV but not as good as NOD32/DrWeb.

wizard
__________________
wizardRESEARCH - Malware Research & Analysis since 1989
  #25  
Old August 16th, 2002, 12:33 PM
Technodrome's Avatar
Technodrome Technodrome is offline
Global Moderator
 
Join Date: Feb 2002
Location: New York
Posts: 2,140
Default Re:8 Virus Scanners vs 3 infected files!

Earlier versions of DrWeb32, say 4.25 and down had more aggressive heuristic analyzer. But more false positives were produced.


Technodrome
__________________
Classic Trance Hit: PPK - Resurrection
 

Wilders Security Forums > Security Products > other anti-virus software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 04:07 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums