WiseVector Stop-X

Discussion in 'other anti-malware software' started by bellgamin, Aug 10, 2020.

  1. WiseVector

    WiseVector Registered Member

    Joined:
    Aug 16, 2020
    Posts:
    543
    Location:
    China
  2. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    Oh, great! :thumb:

    Will that fix be included in the next release?

    Thank you.
     
  3. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    Robocopy.exe is a NON-system process included with Windows. I hope that WV will not henceforth be set to ignore Robocopy.exe because it has been a favorite target of malware programmers in the past. Namely, they write virus files with malicious scripts and save them as Robocopy.exe.

    From this standpoint, the paid version of WV might consider inclusion of a whitelist, including a SHA-256 fingerprint of each safe process on a user's computer.
     
    Last edited: Sep 10, 2020
  4. cruelsister

    cruelsister Registered Member

    Joined:
    Nov 6, 2007
    Posts:
    1,649
    Location:
    Paris
    I actually prefer Xcopy.
     
  5. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,296
    @WiseVector

    More curiosity, than worry. ;)
     
  6. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    :thumb: Pretty good alternative.
     
    Last edited: Sep 10, 2020
  7. WiseVector

    WiseVector Registered Member

    Joined:
    Aug 16, 2020
    Posts:
    543
    Location:
    China
    The behavior analysis module has been updated automatically and this issue has been resolved already yesterday. If you enabled the auto-update of WVSX, you will find out.:)
     
    Last edited: Sep 10, 2020
  8. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    Oh! I didn't realise modules were updated separately too.

    Very nice! :thumb:
     
    Last edited: Sep 10, 2020
  9. WiseVector

    WiseVector Registered Member

    Joined:
    Aug 16, 2020
    Posts:
    543
    Location:
    China
    Thanks for your advice.
    "Robocopy.exe" is a system file included in Windows 10. You might confuse it with some third party APP.
    Our behavior analysis module got a problem when analyze hundreds of thousands of "Robocopy.exe" launching at a very short time. We have adjusted the module, but not whitelist the process itself.
     
  10. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    PrivaZer fix confirmed! :)
     
  11. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    It is NOT a system file because it can be easily deleted with NO adverse effect on Windows OS. Of course, deletion of Robocopy.exe will adversely affect those programs (such as PrivaZer) that use it. I know of 3 large networks where Robocopy.exe has been intentionally removed from all of their serviced computers.

    As to your remark that it is included in Windows 10 -- I'm sure you know that it is also included in Vista, Win 7, Win8, & Win8.1.

    I do not get confused quite that easily. Any "third party APP" named Robocopy.exe is almost certainly malware. A SHA-256 fingerprint will distinguish the legitimate Microsoft Robocopy.exe from any counterfeit bearing that same file name.
     
    Last edited: Sep 10, 2020
  12. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    He must of only invited one friend this time, again after running PrivaZer.

    Multi bots.PNG
     
  13. WiseVector

    WiseVector Registered Member

    Joined:
    Aug 16, 2020
    Posts:
    543
    Location:
    China
    Thanks for your explaination.
    We might have different understandings of Robocopy.exe.:) Since it is made by MS and located in system directory so we think it is a system file.
     
    Last edited: Sep 11, 2020
  14. WiseVector

    WiseVector Registered Member

    Joined:
    Aug 16, 2020
    Posts:
    543
    Location:
    China
    1. You have WVSX updated to the latest V2.67, right?
    2. The way we tested PrivaZer was: click Scan-in-depth->Computer->Scan->Clean. Everything went smoothly. What's your steps?
    3. Can you please send the file named "v2-*-*-*-*.dmp" (* presents any number) in the WiseVector StopX installation folder to support@wisevector.com?
    This is the crash dump file of WVSX, thanks.
     
  15. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    Hi WiseVector,

    Email with two logs sent.
    Yes.
    I click Scan-in-depth > Scan > I have "Start cleaning" unchecked > Clean.

    Thanks.
     
  16. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    If I stand in a garage, that does not make me an automobile. Removal of a true system file will sooner or later (usually sooner) cause an operating system problem. Windows gets along just fine without Robocopy.exe.
     
  17. cruelsister

    cruelsister Registered Member

    Joined:
    Nov 6, 2007
    Posts:
    1,649
    Location:
    Paris
    One really can't just get rid of these System32 command line processes like Robocopy, certutil, attrib, etc just because they can be used for nefarious purposes (can you say LOLBin?); they are too well ingrained in the Windows OS to be trashed.

    It should be said that although LOLBin's are hot topic currently, their use has actually been occurring for a very long time (not meaning to dredge up the residua of a misspent youth, but I should note that in years past my Barbie used Xcopy to drop a Bot on Ken's computer).
     
    Last edited: Sep 11, 2020
  18. roger_m

    roger_m Registered Member

    Joined:
    Jan 25, 2009
    Posts:
    8,629
    Any file which resides in the System32 folder and is put there when Windows is installed, is classified as a system file, whether the file is actually critical to the operation of Windows or not.
     
    Last edited: Sep 11, 2020
  19. WiseVector

    WiseVector Registered Member

    Joined:
    Aug 16, 2020
    Posts:
    543
    Location:
    China
    Please try this: click Settings of WVSX->Basic->Real-Time Protection->Set Up->Uncheck "Scan on file creation" and observe whether this issue will happen again or not.
    Thanks for your help!
     
  20. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Yes but to clarify, how did you test this? I assume you disabled realtime protection and enabled only memory protection? Because in order to block code injection and process hollowing, you will need to let the malware run. That's why I asked Cruelsister how she tested NetWalker and Agent Tesla.
     
  21. WiseVector

    WiseVector Registered Member

    Joined:
    Aug 16, 2020
    Posts:
    543
    Location:
    China
    You need to disable real-time protection to run the malware if it is already detected by static scanning.
     
  22. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    Did that. Unfortunately, while running PrivaZer on that machine a second SysTray icon appeared again. For whatever reason, this machine does not show the same behaviour.

    Did the logs show anything interesting?

    Thanks.
     
  23. WiseVector

    WiseVector Registered Member

    Joined:
    Aug 16, 2020
    Posts:
    543
    Location:
    China
    Hi,
    We still need time to analyze this log and we would like to constrict the scope of analysis, that's why I asked you to uncheck "Scan on file creation" first.

    Can you please tell me what's the difference between the two computers? One of them has been installed more than two AV and the other only has WVSX?
     
  24. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    Both run the same security + mostly the same other software.
     
  25. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    I think I disabled the wrong setting last time so I ran PrivaZer again with "Scan on file creation" unchecked. This time no other icons showed up.

    Thanks.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.