No more safety without AntiVir !! Is it the only one ?

Discussion in 'other anti-malware software' started by Metting, Nov 19, 2006.

Thread Status:
Not open for further replies.
  1. Metting

    Metting Registered Member

    Joined:
    Aug 3, 2006
    Posts:
    100
    Yes you are right, and I agree on that, but the problem with Themida is because it is a commercial packer and very easy to use, so any bad kid can use it to make hundreds of undetectable malwares from even commercial key loggers and remote admin progs.

    Other tools are not for any one. aslo you need to use at least two or more packers to make a hard detectable malware, even in this case you have to test your new malware with each scanner to be sure it is undetectable and the result may force you to change the way, the type, and the number of packers you used ..... then try again ... etc. i.e it is a very difficult method while on the other hand you have to use only Themida with afew mouse clicks to creat undetectable malware by the majority of scanners.
     
  2. Metting

    Metting Registered Member

    Joined:
    Aug 3, 2006
    Posts:
    100
    good for you, but hurry up


    I don't work for unknowns ,if you give a name I may rethink :isay:
     
  3. Metting

    Metting Registered Member

    Joined:
    Aug 3, 2006
    Posts:
    100
    I think not until the next version if they worked hard.
     
  4. Metting

    Metting Registered Member

    Joined:
    Aug 3, 2006
    Posts:
    100
    Themida simply protects the area in memory in which the malware or any other themida encrypted file works, so it is impossible for any program to read this memory area except if the program has a special way to pass through this protection, and this penteration of themida protection is what AntVir handled with success.

    For example : NOD32 and KAV accept Themida encrypted Biforse trojan running in the memory very happily.
     
  5. herbalist

    herbalist Guest

    Quite true. Between new methods of packing/encrypting (or unorthodox uses of older methods), keeping up is almost an excercise in futility. I gave up on signature based detections. Too many ways to avoid detection with new ones coming out, such as Themida. Now that there's one such packer/encrypter, there'll soon be more of them, and even more for the AVs to deal with.

    dah145
    I wan't trying to make something that was undetectable. That was just a quick run with an existing malware. Yes, there's a good chance that an AV would detect it when launched, assuming its first task isn't killing the AV. My point was a much simpler one. That was just to show how easy it is to get malware onto a system undetected. That's half the battle, leaving one chance for the AV to catch it, during it's launch. None of the AVs catch everything when it isn't encrypted. Encryption just makes odds worse.
    Rick
     
  6. the Tester

    the Tester Registered Member

    Joined:
    Jul 28, 2002
    Posts:
    2,854
    Location:
    The Gateway to the Blue Hills,WI.
    Metting,
    Thanks for answering my question.
     
  7. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Yes this is disturbing, the only thing you can hope is that a HIPS might be able to save your ass, but of course a HIPS relies on user input, so you need to know a bit about what´s normal behaviour and not. Sandboxing would be another solution, but often some apps won´t run if sandboxed. But signature based solutions are just not good enough nowadays, that´s a fact. :rolleyes:
     
  8. cash4questions

    cash4questions Registered Member

    Joined:
    Jun 16, 2006
    Posts:
    3
    I'm concerned about this from another angle

    i legitimately protect my software with themida. if AV products work out how to bypass themida encryption to check for viruses then the protection for my software is also breached. my code is then wide open to piracy
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.