Interesting malware/ DDOS worm testing?

Discussion in 'other anti-malware software' started by aigle, Jul 20, 2009.

Thread Status:
Not open for further replies.
  1. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    wooo but threatfire has outbound like protection for protecting network and maybe file theft isn't?
     
  2. mvdu

    mvdu Registered Member

    Joined:
    Oct 14, 2003
    Posts:
    1,166
    Location:
    PA
    Can Online Armor (without AV part) stop it without Run Safer?
     
  3. danny9

    danny9 Departed Friend

    Joined:
    Feb 18, 2004
    Posts:
    678
    Location:
    Clinton Twp. Mi
    Thanks for what you do here Pete, as well as the other posters here who test these nasties.
    It's terrific that we have people like you that will do this.

    To all testers-- Thank You! :D :thumb:
     
  4. CogitoErgoSum

    CogitoErgoSum Registered Member

    Joined:
    Aug 22, 2005
    Posts:
    641
    Location:
    Cerritos, California
    For those who are interested,

    I can personally confirm that DefenseWall v2.56 successfully contains the malware sample in question under Vista 32 SP2.


    Peace & Gratitude,

    CogitoErgoSum
     

    Attached Files:

    Last edited: Jul 21, 2009
  5. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    6,941
    Location:
    USA
    I agree and extend my appreciation as well! :)
     
  6. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Thanks. Was expecting so.
     
  7. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    Kudos Prevx:thumb:
     
  8. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Absolutely, assuming you answer the pop ups correctly. If you deny direct disk access, shows over for malware.

    Pete
     
  9. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Hi sorry for the same question. Does this worm works under vista?
     
  10. CogitoErgoSum

    CogitoErgoSum Registered Member

    Joined:
    Aug 22, 2005
    Posts:
    641
    Location:
    Cerritos, California
    Yes.


    Peace & Gratitude,

    CogitoErgoSum
     
  11. Toby75

    Toby75 Registered Member

    Joined:
    Mar 10, 2006
    Posts:
    480
    Hesitant to test Outpost because I don't think it offers file protection. Maybe someone can tell me otherwise? I know it will protect MBR via direct disk access.
     
    Last edited: Jul 21, 2009
  12. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    BTW I must say thanks to Rmus for poiting out this malware for testing and also to Stefan( from Avira) for providing me with the sample. So many thanks to both of them.

    For the users who requested for testing I will apologize. I have no VM and have loaded a fresh complete system image just now. I will not be able to test on wish as it needs a lot of time that i don,t have at the moment.
     
  13. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    thanks cogito very nice some one tested my beloved defensewall
     
  14. Retadpuss

    Retadpuss Suspended Member

    Joined:
    Apr 4, 2009
    Posts:
    226
    I would advise everyone to be very careful playing about with this and any other malware.

    Worms are a nightmare. Running tests under Returnil and similar light virtualisation is not advised as they wont prevent it working and many worms are VM aware and / or wont yeild realistic results in full virtual environments.

    You have been warned.

    Puss
     
  15. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    very good point puss, very good point.
     
  16. raven211

    raven211 Registered Member

    Joined:
    May 4, 2005
    Posts:
    2,567
    What would happen if a user downloaded this kind of virus through their web-browser while running software like SBIE, DW or GeSWall in their respective default settings? Penetrated or not?
     
  17. Retadpuss

    Retadpuss Suspended Member

    Joined:
    Apr 4, 2009
    Posts:
    226
    I use Sandboxie usually and have found it to be very rubust and secure with IE for normal browsing - cant think of any times when its been compromised.

    This is not to say it is safe to purposefully experement with sandboxed malware. I guess most members here have their home PC with all their security apps on, along with all their personal files, photos, work etc - it is not wise to play with malware under any circumstances on your home PC - not worth the risk, its all too easy to get infected / lose your data / spread malware.

    As for DW / GESWall - I have not used them so cant comment.

    Puss
     
    Last edited: Jul 22, 2009
  18. raven211

    raven211 Registered Member

    Joined:
    May 4, 2005
    Posts:
    2,567
    Hi, aigle! Was wondering if you're running GeSWall with any modifications to its defaults, e.g. new/modified/deleted rules and such - when it successfully blocked this malware's actions? Thanks! :)
     
  19. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    There are some additional rules but default settings will stop the worm without any issues.
     
  20. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Ofcourse not.
     
  21. Toby75

    Toby75 Registered Member

    Joined:
    Mar 10, 2006
    Posts:
    480
    No need to be warned. I'm on a test machine...could care less what happens to it...just don't want to go through the trouble of recovering from this and having to install a fresh copy of Win.

    I remember when Gromozon first came out and I purposely ran it. What a nightmare.

    Wait a minute...that wasn't a nightmare...that was damn fun. :p
     
  22. raven211

    raven211 Registered Member

    Joined:
    May 4, 2005
    Posts:
    2,567
    Aha! Now you made me curious. :D - What rules? :D Don't worry, I simply just wanna learn more - that's what I always do in this hobby. :D
     
  23. raven211

    raven211 Registered Member

    Joined:
    May 4, 2005
    Posts:
    2,567
    Haha, that comment made me laugh. :D
     
  24. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    The warning posted should really be heeded. Don't play with this stuff unless you fully understand what you are doing.

    Some of these worms, when the do the number on your hard drive, even make restoring an image impossible unless you know what to do.

    So if you are reading this thread, and think it would be cool to try, DON'T.

    Pete
     
  25. raven211

    raven211 Registered Member

    Joined:
    May 4, 2005
    Posts:
    2,567
    Thanks Pete - I respect your warning and obviously the original one from Puss as well. On another note I never do this kind of dangerous testing. I only try to stay secure. ;)
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.