FYI: Avira detects

FYI: Avira detects "Shutdown Windows' servers" by special signature for this tool

Secure Home | Search | About
 General Computer Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
FYI: Avira detects "Shutdown Windows' servers" by special signature for this tool Volker Birk 08-07-2006
Posted by Volker Birk on August 7, 2006, 3:43 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,

Avira's AntiVir does not detect "Shutdown Windows' servers" as malware
because of generic detection algorithms.

It detects "Shutdown Windows' servers" because of a special signature
for this tool.

We did a small testing to proof that: I created a small test program:

http://www.dingens.org/servicetest.c
http://www.dingens.org/servicetest.exe

This program contains a copy of the code of "Shutdown Windows' servers",
which shutdowns one single service, Universal PnP. If AntiVir detects
with generic signatures, it has to detect this, too.

Then Markus Steinborn testet, if AntiVir realliy detects this. It does not:


Now it's clear, that Avira created a special signature for "Shutdown
Windows' servers", and that they're not detecting "by accident" or
something like that.

It's not necessary to whitelist for Avira, they just have to stop
blacklisting my tool.

Yours,
VB.
--
Ich würde schätzen, dass ca. 87% aller spontanen Schätzungen völlig für
den Arsch sind.

        Ralph Angenendt in debate@ccc.de

Similar ThreadsPosted
FYI: Avira reacted about "Shutdown Windows' servers" as malware August 7, 2006, 10:21 am
HIDS on Windows Servers February 25, 2008, 11:38 am
Windows Encryption Tool - Safe AES encrypted archives and on-fly image viewer February 28, 2005, 8:05 am
(OT) Web Hosting Special Offer................................................................................................................................................................................................................................. April 14, 2005, 8:03 am
A problem with emails containing special characters September 13, 2005, 7:07 am
EuroPKI'07 (+ Journal Special Issue) January 23, 2007, 4:19 pm
EuroPKI'07 (+ Journal Special Issue) January 23, 2007, 4:20 pm
Call for Papers: Special Issue on Security Certification January 26, 2006, 11:20 pm
Call for papers: Special Issue on: "Data and Application Security" October 21, 2006, 1:20 pm
Looking for pointers to get started with e-signature August 19, 2004, 1:26 pm

The site map in XML format XML site map

Contact Us | Privacy Policy