Page 1 of 4 123 ... LastLast
Results 1 to 10 of 31
  1. #1
    Experienced User
    Overall activity: 0%

    Join Date
    Feb 2008
    Location
    Socket LGA 771
    Posts
    1,785
    Liked
    3 times
    Points
    14,465

    Cool Do you trust your AV ?

    I recently got a common virus.
    It creates a folder "resycled" with a file boot.com inside it. It also adds an autorun.inf file to the root of the drive. On execution it injects dll.dll into 2 system processes.

    Neither my Norton 2009 nor the Kaspersky AVP Tool could detect it. I had to remove it manually by unloading the dll.dll from the processes and then manually deleting the virus files. I had turned off automatic loading of autorun.inf.

    I then uploaded the resycled folder having boot.com along with autorun file to VirusTotal and most of the AV detected it.
    Then I uploaded only the resycled having the boot.com file inside it. To my surprise, neither Norton nor Kapersky detected it.

    With Autorun file :
    http://www.virustotal.com/analisis/6...49b6e2adf6f862

    Without Autorun File :
    http://www.virustotal.com/analisis/0...5fcd6e25b4dee1

    and here's a sample of the boot.com file :
    http://rapidshare.com/files/155514118/resycle.zip.html

    The virus is relatively less harmful. Norton was able to detect the temp files from where the virus originated and was able to remove registry entries made by it and also some of the folders and files created by it but it failed to detect boot.com

    ThreatExpert reports:
    http://www.google.co.in/search?hl=en&q=site%3Athreatexpert.com%2Freport.aspx+resycled&btnG=Search&meta=

    So I don't trust my AV Norton or Kaspersky. Both failed to detect it. Even Microsoft (Onecare) was able to detect it. My question is do you trust your AV ?
    Last edited by prashanthpai; 10-20-2008 at 02:45 PM.
    Happy To Help

  2. #2
    Senior Techie
    Overall activity: 0%

    Join Date
    Sep 2008
    Location
    UK/ Midlands
    Posts
    207
    Liked
    0 times
    Points
    3,649
    No I don;t trust my AV but that is why its best to scan with stand alone antimalware programs as well,

    Makes you wonder what else they miss that goes undetected

  3. #3
    Guest
    Overall activity: 30.0%

    Join Date
    May 2007
    Location
    Philippines
    Posts
    4,001
    Liked
    709 times
    Points
    47,592
    My answer is simple - Like human beings software have flaws too

    FBI said that there's no 100% computer security - ur PC is 100% safe when its turn off

    Apart from the sayings imagine there are 3-4 million malwares across the cyberworld and living inside physical boxes and Antivirus vendors cant filter all of those,despite the fact that addition of new tech innovations like Proactive features/HIPS/Heuristic tech...still not able to guarantee.

    If I were u just sent the sample to the AV vendors - It's a good initiative

  4. #4
    Experienced User
    Overall activity: 0%

    Join Date
    Feb 2008
    Location
    Socket LGA 771
    Posts
    1,785
    Liked
    3 times
    Points
    14,465
    I've already sent it.
    FBI said that there's no 100% computer security - ur PC is 100% safe when its turn off
    ^ True Indeed
    Last edited by prashanthpai; 10-19-2008 at 11:00 PM.

  5. #5
    The Fun Stuff Owner
    Overall activity: 0%

    Join Date
    Jun 2008
    Location
    UK
    Posts
    2,883
    Liked
    7 times
    Points
    28,077
    yes true..

    I trust my Anti Virus.. dunno why.. I just do..

  6. #6
    Administrator
    Overall activity: 46.0%

    Join Date
    Nov 2006
    Location
    Malaysia
    Posts
    9,802
    Liked
    1656 times
    Points
    48,740
    Nope, a turned off computer is not even considered safe. I once a read that FBI said that the "safest computer will be the one that is turned off, buried 6 feed underground".... wait a minute, and he's even sure that's safe enough.

    In short, there's no safe computer. And I do not trust antivirus. To me, it's just an alert tool rather than total protection.

  7. #7
    Experienced User
    Overall activity: 0%

    Join Date
    Aug 2008
    Posts
    157
    Liked
    0 times
    Points
    10,055

    Cool

    I have a clean file. When I scan with Norton 2009, it doesnt detect any malware threats. Yesterday, when I uploaded to VirusTotal.com ~ two scan engines said that the file contains malware [aka~suspicious file]. Does it mean that two scan engines have positive test or the others fail to detect the file.

    http://www.virustotal.com/analisis/2...e22a6ba74909df

    Thanks,

    diddo09

  8. #8
    Experienced User
    Overall activity: 0%

    Join Date
    Feb 2008
    Location
    Socket LGA 771
    Posts
    1,785
    Liked
    3 times
    Points
    14,465
    That file is safe

  9. #9
    Administrator
    Overall activity: 46.0%

    Join Date
    Nov 2006
    Location
    Malaysia
    Posts
    9,802
    Liked
    1656 times
    Points
    48,740
    Quote Originally Posted by diddo09 View Post
    I have a clean file. When I scan with Norton 2009, it doesnt detect any malware threats. Yesterday, when I uploaded to VirusTotal.com ~ two scan engines said that the file contains malware [aka~suspicious file]. Does it mean that two scan engines have positive test or the others fail to detect the file.

    http://www.virustotal.com/analisis/2...e22a6ba74909df

    Thanks,

    diddo09
    If you're unsure, it's time to analyze the file with ThreatExpert.
    http://www.raymond.cc/blog/archives/2008/10/05/faster-and-easily-upload-suspicious-files-to-threatexpert-for-analyzing/
    http://www.raymond.cc/blog/archives/2008/03/03/how-to-easily-analyze-and-get-detailed-report-of-suspicious-files/

  10. #10
    Experienced User
    Overall activity: 19.0%

    Join Date
    Jun 2008
    Location
    Sri Lanka
    Posts
    1,909
    Liked
    1 times
    Points
    15,911
    just like raymond i dont trust my av. thats one reason why i use mcafee its alerts are simple than kaspersky

 

 
Page 1 of 4 123 ... LastLast

Similar Threads

  1. Why do you trust WOT?
    By weylin in forum General Forum
    Replies: 11
    Last Post: 10-15-2010, 02:18 AM
  2. Is WOT (web of trust) reliable
    By ted in forum General Forum
    Replies: 15
    Last Post: 10-06-2010, 10:25 PM
  3. Why you should never trust your antivirus 100%
    By LunarWolf in forum Spyware/Viruses
    Replies: 13
    Last Post: 09-03-2010, 01:54 PM
  4. Web Of Trust
    By JayCub in forum General Forum
    Replies: 32
    Last Post: 07-07-2010, 02:15 AM
  5. can we trust these websites ?
    By witchball in forum General Forum
    Replies: 8
    Last Post: 08-12-2008, 12:49 AM
All times are GMT +8. The time now is 10:08 PM.