Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 02-11-2005, 00:11
tbone
 
Posts: n/a
Symantec needs to read some tutorials

Apparently they don't know how to unpack UPX:

hxxp://www.zdnet.com.au/news/security/0,2000061744,39180674,00.htm

Reply With Quote
  #2  
Old 02-11-2005, 00:31
vbgamer45
 
Posts: n/a
Pretty funny just read it on slashdot.org too. I think they should rethink the way they identify viri, not real big fan on the current way they detect them using virus defentions.
Reply With Quote
  #3  
Old 02-11-2005, 05:32
MrAnonymous
 
Posts: n/a
Pathetic, glad I use kaspersky :> Norton's really gone down hill the last couple years and I guess they just keep sliding..
Reply With Quote
  #4  
Old 02-11-2005, 06:01
elephant elephant is offline
Friend
 
Join Date: Feb 2005
Posts: 94
Rept. Given: 2
Rept. Rcvd 29 Times in 15 Posts
Thanks Given: 132
Thanks Rcvd at 127 Times in 41 Posts
elephant Reputation: 29
For those interested:

- Original Symantec advisory
hxxp://www.sarc.com/avcenter/security/Content/2005.02.08.html

- ISS advisory
hxxp://xforce.iss.net/xforce/alerts/id/187

- Secunia advisory
hxxp://secunia.com/advisories/14179/

Last edited by elephant; 02-12-2005 at 04:28.
Reply With Quote
  #5  
Old 02-11-2005, 07:40
aldente aldente is offline
VIP
 
Join Date: Jul 2003
Posts: 266
Rept. Given: 27
Rept. Rcvd 7 Times in 5 Posts
Thanks Given: 36
Thanks Rcvd at 10 Times in 9 Posts
aldente Reputation: 7
i'd recommend nod32

quite good results, and - what is much more important to me - the fastest scanner available and you turn off checking executables before they are being loaded, so you can scan just what YOU want

no problems so far with different software-products, while norton-bullshit is famous for it's problems. in addition, nav is designed for dummy-users
Reply With Quote
  #6  
Old 02-11-2005, 07:49
AgentSmith
 
Posts: n/a
Interesting related story from article pointed by MrAnonymous:
Does anybody like Norton AntiVirus? and this pragraph:
"So the situation right now is that Norton AntiVirus 2005 ?which costs more than AU$90 from Symantec�s Web site and is labelled "The world's most trusted antivirus solution" -- can be fooled by a simple script into turning off its auto-protect functionality and leaving the computer at a malicious user's mercy."

I'm using Kaspersky and it is fine but the problem is that it slows down the computer big time...ingoring the fact that on it took 3 hours to perform a full system scan on 2 drives.

Does anybody here have expirience with good anti vir/trojan tool that will work in background and be almost "invisible".

10x to all suggestion in advance
Reply With Quote
  #7  
Old 02-11-2005, 08:38
miller2005
 
Posts: n/a
I got a virus becuse of Norton once. The virus was packed with UPX Norton didn't detect it.
Now I use kaspersky and know trouble yet.
Reply With Quote
  #8  
Old 02-11-2005, 10:56
WhoCares's Avatar
WhoCares WhoCares is offline
who cares
 
Join Date: Jan 2002
Location: Here
Posts: 468
Rept. Given: 11
Rept. Rcvd 32 Times in 25 Posts
Thanks Given: 69
Thanks Rcvd at 247 Times in 94 Posts
WhoCares Reputation: 32
NAV Corp Edition 8.0(latest is v9.x) hang my system when I open a folder which contains a exe file generated by ASPackDie. I reproduced it by sending the generated exe to my friends. But if I manually unpack the packed exe, it's ok.
__________________
AKA Solomon/blowfish.
Reply With Quote
  #9  
Old 02-11-2005, 15:09
spokey
 
Posts: n/a
WhoCares could you hook me up with that file or a file which is packet with same packer (version), we use both corp versions here at my job, would be nice 2 test it
Reply With Quote
  #10  
Old 02-11-2005, 15:23
xobor xobor is offline
Friend
 
Join Date: May 2002
Location: Slovakia
Posts: 117
Rept. Given: 6
Rept. Rcvd 4 Times in 4 Posts
Thanks Given: 2
Thanks Rcvd at 23 Times in 15 Posts
xobor Reputation: 5
@AgentSmith

try nod32 - is fast and don't use much resources

or try avast home - it's free and new version is much faster then previous

regards
Reply With Quote
  #11  
Old 02-11-2005, 16:46
WhoCares's Avatar
WhoCares WhoCares is offline
who cares
 
Join Date: Jan 2002
Location: Here
Posts: 468
Rept. Given: 11
Rept. Rcvd 32 Times in 25 Posts
Thanks Given: 69
Thanks Rcvd at 247 Times in 94 Posts
WhoCares Reputation: 32
spokey,
I encountered that problem about one year ago when I unpacked UltraISO with ASPackDie, so it's a pity to have no such an exe file now. I remember that I disabled the real-time file protection of NAV then the exe ran well. I think there must be some bug in NAV engine driver so that it can't handle malformed PE file.
__________________
AKA Solomon/blowfish.
Reply With Quote
  #12  
Old 02-11-2005, 18:47
Eskimobob
 
Posts: n/a
Personally I found the corp edition to be better than the regular editiont they give out. I don't like either truely but if I had to chose the lesser of two evils, that's what I would choose.

Also back when IE 6.0 was getting bombed (it still is in many respects) with ActiveX spyware I ran into a virus that disabled Norton (Normal Edition) because nortan used IE 6.0's API in their software. Then it downloaded the rest of the virus and installed itself.

Quite creative and ingenious if you ask me but that's how most viruses are. Ingenious.

Either way, I like Bit Defender and as AgentSmith said, kaspersky.
Reply With Quote
  #13  
Old 02-11-2005, 22:34
dyn!o's Avatar
dyn!o dyn!o is offline
Friend
 
Join Date: Nov 2003
Location: Own mind
Posts: 214
Rept. Given: 1
Rept. Rcvd 1 Time in 1 Post
Thanks Given: 8
Thanks Rcvd at 0 Times in 0 Posts
dyn!o Reputation: 1
Guys, I suppose this thread went a little exaggerated. I don't care about Symantec AV (I don't use it because it takes too much resources) but here goes my humble opinion.

The problem is not that Symantec cannot handle UPX (for sure they can) but Symantec Norton Anti-Virus engine vulnerabilitiy. I believe the problem should be treated rather as Symantec SDE/T team oversight. Similar kind of vulnerabilities exist in many titles but the more popular "exploited" application is the sooner and louder you will hear about it. World's monopolists are in the worst situation - each day hundreds of people are trying to find bugs and exploits.

If you are really interested if they have problems with packers (ASPack, UPX, PECompact, etc.) then answer is NO. They (Symantec, Kaspersky, McAfee) do have problems but with advanced protectors (for instance: few viruses were protected with XProtector + XP VM signatures) and advanced metamorph engines (own made) used in few viruses.

Regards.
Reply With Quote
  #14  
Old 02-12-2005, 13:39
just4urim
 
Posts: n/a
Hi Eskimobob ,

Norton AV has a dll named "OfficeAv.dll" that could be loaded whenever the IE downloads some ActiveX or files .
Quote:
Originally Posted by Eskimobob
..Also back when IE 6.0 was getting bombed (it still is in many respects) with ActiveX spyware I ran into a virus that disabled Norton (Normal Edition) because nortan used IE 6.0's API in their software. Then it downloaded the rest of the virus and installed itself...
May be this dll doesn't treated well , but what about the NAV guard ? (ofcourse , as it uses most of the resources , users disable it first! ) did u disable it ?
in my book , no antivirus is reliable exactly , for each of the has some disadvantages .
you yourself should protect your system . while all recent viruses are almost only a worm (they don't infect a file) .
Viruses are good teachers !
Reply With Quote
  #15  
Old 02-12-2005, 18:00
jjhsd jjhsd is offline
Friend
 
Join Date: Mar 2002
Posts: 26
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 0 Times in 0 Posts
jjhsd Reputation: 0
I don't use any AV program, as virus definition always comes after new virus, which means it is too late in most time.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



All times are GMT +8. The time now is 02:48.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )