Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #26  
Old April 22nd, 2012, 11:16 PM
trismegistos's Avatar
trismegistos trismegistos is offline
Frequent Poster
 
Join Date: Jan 2009
Posts: 363
Default Re: How do Security Products protect them self

Quote:
Originally Posted by Ranget
i agree 100% but Don't forget that modern day malware it won't ask for your
premision to Run it will use some kind of UAC bypass or Browser exploit
even it can minpulate the AV
most user won't even know that the machine is infected
i think if a malware was able to run even your Antivirus is not trusted anymore
i think malware to bypass firewall it need to inject it's code in a Legit process
such as a Download manager or an Antivirus it self

so your antivirus will be the Trojan that delivering stuff to the Hacker
so for that i think anti viruses should be more powerful protecting it self


Mostly it won't kill the av for that reason
but it can minpulate it


BTW i now understand why expert users Like EPx0f,xylitol ,....etc won't use AV
That would be your common drive by malware pushed by exploits. I agree that AVs would mostly be bypassed if they don't have the signature for that malware and it escaped heuristic detection. But as for HIPS/SRP/AE/Applocker, our guru, Rmus has elucidated, that these droppers are executables, so it won't execute under those. HIPS/AE/Applocker can also prevent dll loading and therefore stop most dll injections. HIPS in addition can also be configured to be prompted for any driver loading. As I said earlier, once kernel drivers are loaded, which is what rootkits do, it's definitely game over. It can just unhook the AVs, the AV will still be up and running and won't even notice the unhooking but it's definitely useless after that. But generally, malware do code injections into trusted processes to evade detections from Avs. I am not yet aware of a malware trojanising the AV but it's quite possible. But if your firewall can catch any outbound connection and can untrust the AV, a user can have such suspicion.

The big problem for Anti-execution security layer is social engineering. The hacker can just obfuscate his malware into something a victim would likely execute or click. [HIPS can probably catch suspicious behaviours like dll injections, driver loading, keystroke logging, etc.] The hacker also can use exploit to do the job. For e.g, the Duqu malware was pushed by a zero day kernel exploit after opening a seemingly innocuous Word document. They said all security layers are bypassable by any kernel exploit but Faronics claimed they can still catch the main dll of that malware from executing, which I doubt.
__________________
-http://www.veteranstoday.com/author/henderson/
-http://www.veteranstoday.com/2013/03/04/the-911-illusion-patsies-beneficiaries/

Last edited by trismegistos : April 22nd, 2012 at 11:54 PM.
  #27  
Old April 23rd, 2012, 08:13 AM
Amit's Avatar
Amit Amit is offline
Massive Poster
 
Join Date: May 2011
Location: Parallel Universe
Posts: 4,631
Default Re: How do Security Products protect them self

interesting thread/topic .....just to input info on how Dr. protect itself:

Dr.Web is immune to any attempts by malicious programs to disrupt its operation. Dr.Web SelfPROtect is the unique anti-virus component that maintains the anti-virus’ security.

* Dr.Web SelfPROtect is implemented as a driver that operates on the lowest system level. The driver can’t be stopped or unloaded without a system reboot.
* Dr.Web SelfPROtect restricts access to a network, files and folders, certain branches of the Windows Registry and removable data-storage devices on the system driver level and protects the software from anti-antiviruses aiming to disrupt the operation of Dr.Web.
* Some anti-viruses modify the Windows kernel through intercepting interrupts, changing vector tables or using other undocumented features. This may have a negative impact on the stability of a system and pave new ways for malicious programs to get into a system. At the same time, Dr.Web SelfPROtect maintains security of the anti-virus and doesn’t interfere with routines of the Windows kernel.
* New! Automatic restoring of anti-virus modules
__________________
✓The first principle is that you must not fool yourself, and you are the easiest person to fool.
✓Science is the belief in the ignorance of experts.
✓I don't know anything, but I do know that everything is interesting if you go into it deeply enough.


-------Richard P. Feynman---------
  #28  
Old April 30th, 2012, 03:15 PM
Ranget's Avatar
Ranget Ranget is offline
Frequent Poster
 
Join Date: Mar 2011
Location: Not Really Sure :/
Posts: 832
Default Re: How do Security Products protect them self

wouldn't hurt to try Drweb protection
i will report back later

BTW extremely helpful Post trismegistos's
__________________
Spyshelter Premuim + MBAM Pro +Avast Free + Hardend FireFox + Secunia Update Checker
"Uncommon sense will increase your privacy; common sense will just make you common."
"The Worst Thing in the World is To look and not be able to Help "
  #29  
Old May 1st, 2012, 08:10 AM
DX2's Avatar
DX2 DX2 is offline
Regular Poster
 
Join Date: Aug 2010
Location: Stockton, California
Posts: 189
Default Re: How do Security Products protect them self

I know WSA is password protected to stop services or uninstall.
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:29 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums