Detection within Installation files

Detection within Installation files

Secure Home | Search | About
 Computer Software Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Detection within Installation files Art 09-27-2005
Posted by Art on September 27, 2005, 8:09 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
One kind of test of scanners that seems to be rare is that of their
ability to detect a variety of malware "within" install files.
Catching malware prior to installation is obviously a important
preventative.

I used a list of rogue web sites:

http://kppfree.altervista.org/spylist.htm

to steer me to a number of installation files. Below are just three
results of AV scanning using KAV:
*************************************
http://www.kazaa-download-manager.com
Install file: KDM-Setup.EXE
Trojan-Downloader.Win32.Small.asf data004
AdWare.Win32.WebHancer.351 whAgent.exe
AdWare.WebHancer whInstaller.exe

whsurvery.exe

webhdll.dll

whiehlpr.dll

http://www.mp3musicsearch.net
Install file: mp3ms.exe
AdWare.Win32.NewDotNet WISEOO24.BIN
Server-Proxy.Win32.MarketScore.k WISE0025.BIN
AdWare.Win32.SaveNow.bo WISE0026.BIN

http://www.kazaap.org
Install File: kazaap-3.6.exe
Adware.Win32.MediaBack data002
Trojan-Clicker.Win32.VB.dn data003
Trojan-Downloader.Win32.Agant.jt data005
*************************************
Notice the variety of Trojans and Adware in every install file.

One of the deficiencies of many or most spyware/adware/Trojan scanners
is their inability to scan "within" install files and act as a
preventative. One approach would be to upload install files to Virus
Total. That would only be viable if the file size is small enough. If
you have low upload speed, and/or the server is maxing out, this
approach could be painful :)

Having several free on-demand antivirus scanners on hand is another
approach. The best preventative though is to only download and install
known reputable software from trusted sources.

If your scanner, whatever kind, doesn't alert on at least the three
install files above, you are being short-changed. Demand of your
vendor that they learn to do a better job at preventative type of
scanning.

Art

http://home.epix.net/~artnpeg


Similar ThreadsPosted
is that a good offer for a server installation? June 30, 2005, 1:41 pm
Any rootkit prevention, detection and/or repair suitable for use by the average user? August 12, 2006, 5:04 pm
Microsoft Research: Strider GhostBuster Rootkit Detection and "...stealth software that hides in BIOS, Video card EEPROM" September 19, 2005, 11:58 pm
Charset Files June 21, 2005, 12:39 pm
mystery files February 15, 2006, 3:15 pm
hidden files April 17, 2006, 10:09 am
deleted files November 14, 2006, 2:33 am
Change in system files October 2, 2005, 3:13 pm
Symantec and the number of files October 20, 2005, 4:42 pm
Is there a danger opening WMV files in XP? May 11, 2006, 6:52 am

The site map in XML format XML site map

Contact Us | Privacy Policy