Overblog Tous les blogs Top blogs Technologie & Science Tous les blogs Technologie & Science
Suivre ce blog Administration + Créer mon blog
MENU
Publicité
OTHER MALWARES Part 8

OTHER MALWARES Part 8

-Backdoor VB.aw: P1/P2 -Dialer CapreDeam.p: P1/P2 -MSNIPstealer: F1/F2 (only detected by Webwasher) NB. This is here a hack tool designed to " steal" IP of MSN users."fail" results can't really be considered as important: the goal was more to demonstrate...

Lire la suite

Publicité
KAV TEST PART 2 NEXT AND END

KAV TEST PART 2 NEXT AND END

b) Worms and virus: -Feebs : P1/ P2. KAV detects the launch of IE browser, which can be blocked, and detects startup entry once mshta.exe is running. Mshta.exe is not killed, but no harmful changes are made. AV detection : - WormRays : P1/ P2. Wormray...

Lire la suite

ROOTKIT TEST B Next

ROOTKIT TEST B Next

16) Trojan Downloader Win32.Small.emg/SpamBot variant: We can't reproduce a real life situation for this test (the infection occurs via web sites), and we jus run the files locally. Detection with Helios Lite and Spyware Process Detector (a clone of Security...

Lire la suite

WORMS, VIRUSES, and SCRIPTS 2

WORMS, VIRUSES, and SCRIPTS 2

-Zhelatin worm: P1/P2 -"Kav Virus": P1/P2 Here we just create a simple malicious scripts that we call "kav virus": -P2P-WORM.Win32.Small.y: P1/P2 -Worm.Win32.Agent.ak: P1/P2 -IM Worm Win32.VB.as: P1/P2 Scan for the first test ("fresh mawlare"): Scan for...

Lire la suite

Publicité
OTHER MALWARES Part 6

OTHER MALWARES Part 6

-PoisonIvy Rat: P1/P2 In this example the server file (orishas.exe) is not detected by the scanner engine as malicious: -MiniTunnel (pure backdoor which does not install itself on the system but just acts as a server): F1/F2 False positives of 2 scanner...

Lire la suite

OTHER MALWARES Part 2

OTHER MALWARES Part 2

- Armageddon trojan: F1/P2 - IRC bot: P1/P2 - Fake codecs, zlob and variants:P1/P2 Kav prevents only the malware from being permanent, not the download of roque products. In a live system, this trojan is difficult to remove for inexperienced users ("rebirth...

Lire la suite

McAfee Rootkit Detective renamed keys

=================================================Registry Key : HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun.RENName : mssync20Type : REG_SZData : C:Documents and SettingsF.Telecom F.TelecomMes documentsRK.MSSyncmssyc20_filesmssync20.exeKey Modified...

Lire la suite

OTHER MALWARES Part 3

OTHER MALWARES Part 3

- backdoor oscar: P1/P2 - Fearless keyspy: P1/P2 - backdoor Seed: P1/P2 - Code Injection Downloader: P1/P2 - Iow A's Webdownloader: P1/P2 -Bandoork Backdoor: P1/P2: - Poly Downloader: P1/P2 (trojan generic): -Web Devil Proxy Trojan: F1/P2 Active port...

Lire la suite

Publicité
OTHER MALWARES Part 4

OTHER MALWARES Part 4

-Trojan Arduk: P1/P2: -Trojan dialer.ht: P1/P2 -Backdoor PackBot.p: P1/P2 -Bat Virus: P1/P2 -Wmf trojan downloader variant: F1/P2 -Trojan Nyxem: P1/P2 -Backdoor Win32.vb.yh: P1/P2 -Eagle Agent Trojan: P1/P2 This trojan from China is not known from AV...

Lire la suite

OTHER MALWARES Part 12

OTHER MALWARES Part 12

-Backdoor Win32.WinRC: P1/P2 -Trojan Spy Win32 vb.qq : P1/P2 "Dialer " detections are false positive: We build a server that we call Yahoo Messenger, configured to kill Windows firewall, kaspersky antivirus (avp.exe) etc. -Trojan Spy Win32.VB.dd: P1/P2...

Lire la suite

<< < 1 2 3 > >>