Overblog Tous les blogs Top blogs Technologie & Science Tous les blogs Technologie & Science
Suivre ce blog Administration + Créer mon blog
MENU
Publicité
WORMS, VIRUSES AND SCRIPTS  3

WORMS, VIRUSES AND SCRIPTS 3

-Worm Scanao: P1/P2 -Worm Delf.bg (also knwon as Worm Cekar by sophos): F1/P2 Kav self-defense: When the host is already infected, the PDM detects s suspicious behaviour, but it's too late (no prevention). -Worm Locksky.au: P1/P2 -Worm Jalabed.b: P1/P2...

Lire la suite

Publicité
KAV TEST Part 3 Next and end

KAV TEST Part 3 Next and end

7) Man-In-The-Middle Attack: a) Locally with SSLSpoofer (R) : P1/P2 A fake certificate is returned but kav is able to detect the connection of SSLSpoofer on 443 port, and the fake certificate. As it is displayed by the next image (referer), this communication...

Lire la suite

KAV TEST Part 3

KAV TEST Part 3

CLIENT/SERVER SIDE ATTACKS and other tests: Here we focus on attacks which occur via client applications (browser for instance) and which may represent possible attack in case of intrusion. NB. Most of these tests have been done during the summer of 2006,...

Lire la suite

KAV TEST Part 2 Next

KAV TEST Part 2 Next

3) Malwares protection: a) Trojans and backdoors: -BasicBackdoor: P1/P2 KAV warns about rundll32 integrity violation: this can't really be considered as an alert in relation to a suspect or malicious activity. But even if the backdoor is not known from...

Lire la suite

Publicité
KAV TEST PART 2

KAV TEST PART 2

PART 2: IN THE WILD WITH REAL MALWARES 1) Protection during the boot and before the shutdown a) keylogging protection with WinlogonHijack : P1/P2 P2 ("accès refusé"="access denied"): b) New program running at the boot: -keylogger: with Ardamax Keylogger....

Lire la suite

KAV TEST Part 1 Next

4) Registry protection -with Scoundrel Simulator (Run Keys): P1/P2 (4/5) -with RegTest1: P1/P2 -with RegHide (hidden key called 'can't touch me"): P1/P2 NB: Kav can prevent hidden key installation but is not able to detect already installed hidden key...

Lire la suite

Other MALWARES Part 13

Other MALWARES Part 13

Most of these malwares try to install themselves and are easily blocked by the "Trojan Generic" procative alert.Some malwares only open connections, and are not blocked by the proactive module (F1 results).Unfortunately, most .jpg has been lost for most...

Lire la suite

WORMS, VIRUS and SCRIPTS

WORMS, VIRUS and SCRIPTS

- Xorala: P1/P2 NB. Kav prevents the malware from being permanent, but not the creation of its files: - Vulcano: P1/P2 - VB Fun Love: P1/P2 - IRC VBS: P1/P2 - Autoworm: F1/P2 - "Virus": P1/P2 (not known from Kav labs, uses keyboard hooks): -Email worm...

Lire la suite

Publicité
<< < 1 2 3