MSE fails these SIMPLE programs

jimbo45

New member
Guru
Gold Member
VIP
Local time
8:30 AM
Messages
5,941
Location
Hafnarfjörður IS
Hi all
Whilst I'm not usually keen on most av software it should actually do "what it says on the tin".

I thought I'd test MSE on a VM with a deliberately infected popup hijacker.

MSE gave it a clean bill of health.

The free version of Malwarebytes Anti malware (we call it "Animalware") correctly identified the offending software and registry keys

here's the log (MSE failed to find anything).

Malwarebytes' Anti-Malware 1.41
Database version: 3065
Windows 6.1.7600
31/10/2009 10:21:40
mbam-log-2009-10-31 (10-21-40).txt
Scan type: Quick Scan
Objects scanned: 93221
Time elapsed: 2 minute(s), 45 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Windows\Tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job (Trojan.Downloader) -> Quarantined and deleted successfully.


So OK this test is not exhaustive but it looks like MSE needs a bit more work on it.

I've totally wiped the infected VM -- VM's are great for this type of testing - I would recommend DO NOT install VIRUSES for testing purposes on ANY machine connected to your LAN -- use a STAND ALONE machine with no Internet access then you should be quite safe testing these things.

Also use a dedicated CD/DVD RW for installing the software so you can completely wipe it with a COMPLETE ERASE (write binary zeros to every track) before loading new "malicious" software for testing. -- sometime USB sticks get infected and can load viruses on to CLEAN machines if you play around with this type of stuff.

Cheers
jimbo
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom built, several laptops HP/ASUS
OS
Linux CENTOS 7 / various Windows OS'es and servers
CPU
Intel i7 Intel i5
Memory
8GB, 16GB
Graphics Card(s)
On Motherboard
Sound Card
Realtek HD audio
Monitor(s) Displays
Apple Cinema display, Samsung LCD
Screen Resolution
1920 X 1080
Hard Drives
4 X 1TB SATA
Mouse
Toshiba wireless laser
Internet Speed
> 20MB up

My Computer

Computer Manufacturer/Model Number
HP
OS
Windows 7 Enterprise x64
CPU
AMD Athlon II X4 @ 2.6ghz
Memory
8GB
Graphics Card(s)
Galaxy 250 GTS 512MB Super-Clocked
Screen Resolution
1600x900
Hard Drives
640GB hard Drive
1.5TB External Hard Drive
PSU
700W OCZ StealthxStreme
Cooling
2 Heatsink and 3 Fans
Internet Speed
3MB/sec download, 322kb/sec upload
Hi there

Maybe later

BTW MSE DID find these successfully (as did Malwarebytes).

CAREFUL if you install these for trialling how good your AV software is -- Keep away from other machines in the LAN if you play around testing.

enc snapshot.

Cheers
jimbo
 

Attachments

  • virus.png
    virus.png
    157.6 KB · Views: 79

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom built, several laptops HP/ASUS
OS
Linux CENTOS 7 / various Windows OS'es and servers
CPU
Intel i7 Intel i5
Memory
8GB, 16GB
Graphics Card(s)
On Motherboard
Sound Card
Realtek HD audio
Monitor(s) Displays
Apple Cinema display, Samsung LCD
Screen Resolution
1920 X 1080
Hard Drives
4 X 1TB SATA
Mouse
Toshiba wireless laser
Internet Speed
> 20MB up
I m confused. In your 1st post, you said that MSE gave a clean bill of health. Now you are saying that MSE was able to detect these items. ???
 

My Computer

Computer Manufacturer/Model Number
Samsung NP530U4B-S02IN
OS
Windows® 8 Pro (64-bit)
CPU
Intel® Core™ i5 Processor 2467M (1.60GHz, 3MB L3 Cache)
Motherboard
Samsung Electronics
Memory
6GB DDR3 System Memory at 1,333MHz (on BD 4GB + 2GB x 1)
Graphics Card(s)
AMD Radeon™ HD7550M 1GB DDR3 (Ext. Graphic)
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
35.56cm (14.0) SuperBright 300nit HD LED Display
Screen Resolution
1366x768
Hard Drives
1TB S-ATA II Hard Drive (5400RPM) with ExpressCache 16GB SSD
Internet Speed
sucks
Antivirus
Microsoft Security Essentials
Browser
Google Chrome (Sync enabled)
I m confused. In your 1st post, you said that MSE gave a clean bill of health. Now you are saying that MSE was able to detect these items. ???
I am also confused about this.
I would just like to say MSE is amazing and saved me so many times.
The best anti-virus I have used. Been using it since beta and have been quite surprised.
 

My Computer

OS
Windows 7 Ultimate x64
CPU
Intel Core i7 920
Motherboard
Asus P6T
Memory
6GB Corsair 1333MHz XMS3
Graphics Card(s)
2 ATI Radeon 4850s
Sound Card
Razer Barracuda AC-1 Sound Card
Monitor(s) Displays
Acer 24" P241w
Screen Resolution
1920x1200
Hard Drives
1x Western Digital 500GB 7.2k RPM (RAID0)
1x Seagate 500GB 7.2k RPM (RAID0)
1x Seagate 640GB 7.2k RPM (RAID0)
PSU
Antec Truepower Quattro 1000W
Case
Thermaltake Spedo Advance
Keyboard
Microsoft Sidewinder X6
Mouse
Logitech G5
Other Info
Headset: Sennheiser PC350
No Anti-virus or Anti-spyware software program is 100% correct in their detections and definitions.
This is one of the reasons we urge people to run 'online' scans as well as keeping their personal 'Anti-malware' and vulnerable software programs up to date.

I won't dispute that MSE could have missed this {Vundo} infection, but I've also seen other Antivirus apps missed it too.

Vundo/Virtumond is getting really nasty :mad: ... and it changes all the time. We see rootkits, Backdoor Trojans --> = thiefware (critical information stolen and sold) downloaded with this particular fake codec, fake anti-spyware/virus, infected web page/banner scripts, etc...

What SIMPLE programs did you download :sarc:
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Back
Top