Kraken botnet bypassed NG, Defence Plus

Discussion in 'other anti-malware software' started by aigle, Apr 11, 2008.

Thread Status:
Not open for further replies.
  1. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Ok, I installed OA free latest version 2.1.0.130.

    OA seems to be bypassed. Creation of executable in system32 folder not detected by OA. Can anyone confirm with free version? I am not sure about results. I tested under Sahdow mode of SS.

    Thanks
     
  2. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Don't remember if Free version has run safer option. If so try running it under that, and see if it still is bypassed.
     
  3. alex_s

    alex_s Registered Member

    Joined:
    Aug 13, 2007
    Posts:
    1,251
    127 passed it fully. 130 also passes. I just do not want to post the same pictures once again. May be she just do not like you and this is why she fails intentionally ? :)

    BTW, did you wait at least a minute after install when she exits learning mode ?
     
  4. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Sure, even rebooted.

    I will try it again. Did u try it with free version?
     
  5. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Will try. Run Safer is there in free version.
     
  6. alex_s

    alex_s Registered Member

    Joined:
    Aug 13, 2007
    Posts:
    1,251
    No, I use full version, but HIPS should be the same in full and free.
     
  7. alex_s

    alex_s Registered Member

    Joined:
    Aug 13, 2007
    Posts:
    1,251
    I think there is no need to run it safer. I tried it with admin account w/o runsafer and OA intercepted everything. I'd just like to know basing on what does he say "seems failed". It blocked autorun, memory tampering and internet access. Nothing wrong after reboot. Just retested once again (to be sure). Passed again.
     
  8. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Well, I decided to take a look myself, and I have to say that TF really needs to start giving better alerts, I mean, adding something to "Windows System Startup" is not something to get worried about.
     
  9. lucas1985

    lucas1985 Retired Moderator

    Joined:
    Nov 9, 2006
    Posts:
    4,047
    Location:
    France, May 1968
    Remember that behav. blockers don't analyze individual/isolated behaviours. They correlate the observed behaviours and then make a decision about a certain process. So, maybe, you're seeing an alert about one of the behaviours observed or the one that finally triggered the alarm.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.