Entries tagged as virus

Anti-virus applications and the Bundestrojaner

Monday, October 10. 2011, 20:05
BundestrojanerTwo days ago, the german Chaos Computer Club (CCC) published a sample that's supposedly a variant of a german state spy software (the so-called "Bundestrojaner").

You might wonder if your anti virus software is protecting you. The webpage Virus Total lets you upload suspicious files, scans them with 43 different anti virus applications and presents you the result. Currently, 24 of 43 scanners detect the Bundestrojaner.

The CCC provides some further information where they state that the file they released is not the original one - they had several samples that differed and to avoid detection of the potential source, they changed the differing parts to something completely else. You might wonder if your anti virus app also detects the "original" Bundestrojaner and not just the modified file the CCC released.

We can easily check this if we change the modified pieces again to something else. A modified variant lowered the detection rate to 14 of 43 - amongst them the popular McAffee software. Now, it's pretty useless to only detect the exact published sample of a malware if we know that the original malware is different.

ApplicationVersionSig dateModified sampleOriginal CCC sample
AhnLab-V32011.10.08.012011-Okt-09Trojan/Win32.R2d2Trojan/Win32.R2d2
AntiVir7.11.15.1752011-Okt-09TR/GruenFink.1TR/GruenFink.1
Antiy-AVL2.0.3.72011-Okt-09--
Avast6.0.1289.02011-Okt-09Win32:Trojan-genWin32:Trojan-gen
AVG10.0.0.11902011-Okt-07--
BitDefender7.22011-Okt-10Backdoor.R2D2.ABackdoor.R2D2.A
ByteHero1.0.0.12011-Sep-23--
CAT-QuickHeal11.002011-Okt-07--
ClamAV0.97.0.02011-Okt-10Trojan.BTroj-1Trojan.BTroj-1
Commtouch5.3.2.62011-Okt-10-W32/R2D2.A
Comodo104072011-Okt-10-Backdoor.Win32.R2D2.A
DrWeb5.0.2.033002011-Okt-10--
Emsisoft5.1.0.112011-Okt-10Trojan.Win32.Bundestrojaner!A2Backdoor.Win32.R2D2!IK
eSafe7.0.17.02011-Okt-06--
eTrust-Vet36.1.86052011-Okt-07--
F-Prot4.6.2.1172011-Okt-09-W32/R2D2.A
F-Secure9.0.16440.02011-Okt-10Backdoor:W32/R2D2.ABackdoor:W32/R2D2.A
Fortinet4.3.370.02011-Okt-10-W32/R2D2.A!tr.bdr
GData222011-Okt-10Backdoor.R2D2.ABackdoor.R2D2.A
IkarusT3.1.1.107.02011-Okt-10-Backdoor.Win32.R2D2
Jiangmin13.0.9002011-Okt-09--
K7AntiVirus911552582011-Okt-08--
Kaspersky9.0.0.8372011-Okt-09Backdoor.Win32.R2D2.aBackdoor.Win32.R2D2.a
McAfee5.400.0.11582011-Okt-10-Artemis!930712416770
McAfee-GW-Edition2010.1D2011-Okt-09-Artemis!930712416770
Microsoft177022011-Okt-10Backdoor:Win32/R2d2.ABackdoor:Win32/R2d2.A
NOD3265292011-Okt-10Win32/R2D2.AWin32/R2D2.A
Norman6.7.20112011-Okt-09--
nProtect2011-10-10.012011-Okt-10--
Panda10.0.3.52011-Okt-09-Suspiciousfile
PCTools8.0.0.52011-Okt-10Backdoor.R2D2Backdoor.R2D2
Prevx3.02011-Okt-10--
Rising23.78.06.022011-Okt-09--
Sophos4.70.02011-Okt-10Troj/BckR2D2-ATroj/BckR2D2-A
SUPERAntiSpyware4.40.0.10062011-Okt-08--
Symantec20111.2.0.822011-Okt-10Backdoor.R2D2Backdoor.R2D2
TheHacker6.7.0.1.3182011-Okt-09--
TrendMicro9.500.0.10082011-Okt-09--
TrendMicro-HouseCall9.500.0.10082011-Okt-10-BKDR_R2D2.A
VBA323.12.16.42011-Okt-07--
VIPRE107182011-Okt-10-Trojan.Win32.Generic!BT
ViRobot2011.10.10.47102011-Okt-10--
VirusBuster14.1.3.02011-Okt-09--

Scans done Monday morning around 8:00.

Dangerous for their business model

Wednesday, August 9. 2006, 14:37
A while back, some people from the chaos computer club created a small tool called dingens (yeah, the name sucks) to disable windows services that open ports to the network.
The idea is simple, a common windows installation (esp. before sp2) opens various ports to the network by default, even if they aren't used for anything. This led to a couple of security threats in the past, many viruses used buggy services to attack remote computers.

Now, while it's probably in general not a good idea to use an operating system so poorly designed that it opens ports by default without needing them, if you're forced to use windows, dingens is probably a much better idea than most other »security solutions«. Why? Because it closes security holes instead of working around them and introducing new problems, like antivirus-apps or personal firewalls do.

Now, recently Antivir reported win32sec.exe (the dingens-tool) as
SecurityPrivacyRisk/Tool.KillService riskware

And Panda Antivirus says:
Hacktool/Servicekiller.A

Probably someone should tell the people at Panda about the different meanings of »Hacker«. Just because something was done by »Hackers« doesn't mean it's a hacktool. In fact, detecting dingens as something dangerous is trying to get rid of competitors in terms of security solutions. The only thing dingens endangers is the business model of so-called security companies.
After some people intervened, Antivir has removed the signature now. Panda still thinks it's a »hacktool«.

The complete idea of AV apps is wrong. The purpose of a virus is to use security holes to spread itself. AVs can only detect already known viruses. That also means the security hole is known and thus should be fixed, not worked around by some crappy software that can have security problems itself. The only valid usage of an AV I can think of is to scan email to reduce crap in your inbox. But, not to secure you (that should be done by a well-designed mail client), just to save you time from deleting the mails, the same thing spamfilters do. A command-line scanner like clamav (the only free one) is just fine for this. Everyone telling you that you need to install a »allround security solution« on your PC is lying.

This Virus made my day

Tuesday, July 18. 2006, 18:28
Kam gerade rein, alle Fehler im Original, vielleicht passend zu meinem kürzlichen Etymologie-Artikel:

Guten Tag,

Den Montag, der 17. Juli 2006, 3:17:44 PM, schrieben Sie:

>Ich denke dass du impulsiv in seiner Manier wieder giltst beruhige
>sich und sage obwohl dass irgendwelcher dass einfach grosser einfacher
>Anschuldigungen deine Eifersucht die Grenze nicht kennt!!!!!

Ich verstehe warum du sie alle noch schirmen Sie seinen alle nicht.
Ich habe schon soviel der Beweise gesammelt,
dass deine Bemerkungen horend ist gesenkt,
dass auch bei dir mit sie etwas auch zu denken war.
Jetzt ich die Unausgesprochenen schon vermeide schicke ich die Fotografie
ab wo sie gesaugt meinem Boss macht!

Also, eben was du mir darauf sagen wirst?

P.S. Niemandem es zeige auf.
Wenn ich von deinem Nachbarn erkenne dass auch du es im Wanderzirkus
umgewandelt hast, ich garantiere die Unannehmlichkeit dir.
In die nachsten Tage schreibe nicht, ich habe in das buro schon
ausgetrunken und ich denke, fur die Stadt zu fahren,
was ich und dir wunsche.


Achja, der Virus wird von den bei mir installierten AV-Progs gerade nicht erkannt (PANIK!) und scheint sich gut zu verbreiten, Antivirenprogrammierer mit begründetem Interesse dürfen sich melden. ClamAV, VirusTotal und Jotti sind bereits versorgt.
(Page 1 of 1, totaling 3 entries)