![]() ![]() |
Sep 15 2008, 03:11 PM
Post
#1
|
|
|
Regular Member ![]() ![]() Group: Honorary Members Posts: 97 Joined: 19-July 08 From: Devon, England Member No.: 2,931 |
QUOTE (Firestorm70 @ 14.09.2008 13:20)] I use a free program called MALWAREBYTES it's just a scanner and offers no real time protection but it can still remove malicious programs that KIS might have missed. There's nothing wrong with having something that gives a second opinion even if I believe KIS doesn't usually miss much. Be careful, however, with what you let this program remove/quarantine! It has the following detection methods: 1. registry keys (very often empty ones that were not deleted by your resident protection 2. MD5 checksums of a not so big malware-base 3. Files by name - yes, you heard that correctly; MalwareBytes also detects files by name. For example when I was playing with it, I planted a dummy txt file into System32 with the name amvo0.dll It was immediately detected as CODE C:\WINDOWS\system32\amvo0.dll (Trojan.Agent) -> Quarantined and deleted successfully. This, of course, is unacceptable for a program that wants to belong in a certain class! KIS/KAV and other security programs of that caliber, able to distinguish between false and genuine threats, will most likely leave this file intact because it presents no real threat. However, in your opinion, MalwareBytes may look cooler and better because it found the dummy file and 'protected' you from a really nasty threat; an empty text file... At the same time, detection by name alone may ruin your system as well! p2u |
|
|
|
Sep 15 2008, 04:28 PM
Post
#2
|
|
![]() Forum Deity ![]() ![]() ![]() ![]() ![]() ![]() Group: Administrators Posts: 6,240 Joined: 30-December 06 From: Northampton, MA USA Member No.: 884 |
A few points here , first and foremost MBAM is NOT antivirus software and is not restricted to antivirus techniques . These techniques are the reason antivirus software is not enough to protect your system .
MBAM detects malware through the following means : MD5 unique strings semi polymorphic strings unique GUID linked dlls (and other executable components) (these are bi-directional) unique load point to file (these are bi-directional) IPH (unique heuristics we created and without giving anything away bypasses all current polymorphic blackhat packers and encryption and is also immune to randomized file names) Unique file names combined with FP killing routines (we do not just do file name) There are many more but I dont want to give to much away . By combining cutting edge tech (like IPH) with old school tech and then everything in between we have been able to detect far more malware than some vendors who have been in the game more then 10 times longer than us . Vundo uses random file names but we detect it at over 95% in real world infections . Stats like this are the real reason some people are getting upset . -------------------- |
|
|
|
Sep 15 2008, 04:39 PM
Post
#3
|
|
![]() Forum Deity ![]() ![]() ![]() ![]() ![]() ![]() Group: Administrators Posts: 6,240 Joined: 30-December 06 From: Northampton, MA USA Member No.: 884 |
Here are two more reason some people are getting upset . Here is what happens when you type "malware" into google , both google recommended searches and search results .
Attached File(s)
-------------------- |
|
|
|
Sep 15 2008, 04:55 PM
Post
#4
|
|
![]() Marcin ![]() ![]() ![]() ![]() ![]() ![]() Group: Root Admin Posts: 4,212 Joined: 15-October 05 Member No.: 1 |
QUOTE This, of course, is unacceptable for a program that wants to belong in a certain class! I know Ewido used to do this, guess what they are now, AVG. Just because we detect certain files by name, does not mean we suck. In fact, it means the quite oppositve. We hit malware on multiple levels, you only listed three. What about the other fifteen or twenty? -------------------- |
|
|
|
Sep 19 2008, 02:34 PM
Post
#5
|
|
|
Regular Member ![]() ![]() Group: Honorary Members Posts: 97 Joined: 19-July 08 From: Devon, England Member No.: 2,931 |
...... you only listed three. What about the other fifteen or twenty? I'm sure you recognise that I was the messenger, Rubber Ducky - it wasn't me who wrote same in the Kaspersky forums! The author, p2u is, I believe, involved in computer forensics fwiw. Dave |
|
|
|
Sep 19 2008, 04:15 PM
Post
#6
|
|
|
Malwarebytes ![]() ![]() ![]() ![]() ![]() ![]() Group: Experts Posts: 2,371 Joined: 16-July 06 From: United States Member No.: 281 |
Hi BD,
Should computer forensics impress most of the developers here or something? It's one thing to know how to run software it's another to actually code the stuff. Don't get me wrong, the guy probably has extensive knowledge in various areas. But I don't agree with the statement that filename detection is necessarily a bad thing. It's part of a multi layered approach of malware detection. |
|
|
|
Sep 19 2008, 10:19 PM
Post
#7
|
|
![]() Marcin ![]() ![]() ![]() ![]() ![]() ![]() Group: Root Admin Posts: 4,212 Joined: 15-October 05 Member No.: 1 |
Dave,
Thanks for clarifying that. Where was that posted? -------------------- |
|
|
|
Sep 19 2008, 11:32 PM
Post
#8
|
|
|
Regular Member ![]() ![]() Group: Honorary Members Posts: 97 Joined: 19-July 08 From: Devon, England Member No.: 2,931 |
Dave, Thanks for clarifying that. Where was that posted? Hi Marcin Your friend Bruce asked me that by PM! It is here: http://forum.kaspersky.com/index.php?showtopic=84469 Review #13 #15 and #16 in particular HTH Dave |
|
|
|
Sep 20 2008, 01:18 AM
Post
#9
|
|
![]() Forum Deity ![]() ![]() ![]() ![]() ![]() ![]() Group: Honorary Members Posts: 3,960 Joined: 9-February 07 From: South Central Montana Member No.: 1,030 |
Malwarebytes is also an official ASAP member obviously this guy has a hard on for MBAM. Probably cleaned up some of his malicious code. The screen shots he is linking to are from March. Someone needs to slap some sense into him.
|
|
|
|
Sep 20 2008, 08:00 AM
Post
#10
|
|
|
Regular Member ![]() ![]() Group: Honorary Members Posts: 97 Joined: 19-July 08 From: Devon, England Member No.: 2,931 |
Hi BD, Should computer forensics impress most of the developers here or something? I thought it might! p2u once came to Jenn's BB (at my invitation). Maybe I should have mentioned that although he is Dutch, he can speak fluid Russian. He is also a classical pianist! In other words ....... I think he is quite clever and should not be rubbished! On the subject (kinda!) I recently went here http://validator.w3.org/#validate_by_uri and typed in Jenn's web site address http://www.pqlr.com If you were to do the same I'd be interested in any comment you may have thereafter. Please PM or email me if you'd prefer. Have a great weekend! Dave |
|
|
|
Sep 20 2008, 10:47 AM
Post
#11
|
|
![]() Forum Deity ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderators Posts: 4,555 Joined: 31-December 07 From: Fortville, IN Member No.: 1,983 |
QUOTE (~BD~) p2u once came to Jenn's BB (at my invitation). Maybe I should have mentioned that although he is Dutch, he can speak fluid Russian. He is also a classical pianist! In other words ....... I think he is quite clever and should not be rubbished! He's Dutch, speaks Russian, and plays piano? And that's supposed to impress me? How does classical music make one an expert in how a security application should work? How does it qualify someone to advise in technical matters related to computers and software? Does speaking Russian make him a Microsoft MVP? QUOTE (~BD~) On the subject (kinda!) I recently went here http://validator.w3.org/#validate_by_uri and typed in Jenn's web site address http://www.pqlr.com If you were to do the same I'd be interested in any comment you may have thereafter. Please PM or email me if you'd prefer. pqlr.com is a parked domain. If you are concerned about the content, then contact the company that parked it. -------------------- |
|
|
|
Sep 20 2008, 01:27 PM
Post
#12
|
|
|
Malwarebytes ![]() ![]() ![]() ![]() ![]() ![]() Group: Experts Posts: 2,371 Joined: 16-July 06 From: United States Member No.: 281 |
I thought it might! p2u once came to Jenn's BB (at my invitation). Maybe I should have mentioned that although he is Dutch, he can speak fluid Russian. He is also a classical pianist! In other words ....... I think he is quite clever and should not be rubbished! On the subject (kinda!) I recently went here http://validator.w3.org/#validate_by_uri and typed in Jenn's web site address http://www.pqlr.com If you were to do the same I'd be interested in any comment you may have thereafter. Please PM or email me if you'd prefer. Have a great weekend! Dave Hi Dave. I wasn't trying to blow off the talented russian. You do realize however, that he disected a really old version of mbam? v1.09, which didn't support many of the technologies we have now. I suspect if he were to do his testing against the recent version, he'd find it's a bit more complicated than he makes it out to be. Specifically, mbam isn't an antivirus scanner, and so doesn't play by those rules. This allows us to catch many things by hueristics that others miss. And you don't have to take my word for this, a google search will show you. Comparing antivirus scanning technology to mbam is like comparing a motor and an engine; One's electric and the other isn't. No fair comparison can be established. Each performs well in it's own environment. I have nothing to say regarding the site, as I've told you many times, I really don't have time to explore sites unless said site might contain malicious scripts and/or trojan downloads. Have a good weekend Dave! |
|
|
|
Sep 22 2008, 06:39 PM
Post
#13
|
|
|
Advanced Member ![]() ![]() ![]() Group: Honorary Members Posts: 119 Joined: 4-August 08 Member No.: 3,132 |
3. Files by name - yes, you heard that correctly; MalwareBytes also detects files by name. For example when I was playing with it, I planted a dummy txt file into System32 with the name amvo0.dll It was immediately detected as CODE C:\WINDOWS\system32\amvo0.dll (Trojan.Agent) -> Quarantined and deleted successfully. This, of course, is unacceptable for a program that wants to belong in a certain class! I also read about this behaviour in the avira forum |
|
|
|
Sep 23 2008, 04:45 AM
Post
#14
|
|
![]() Forum Deity ![]() ![]() ![]() ![]() ![]() ![]() Group: Administrators Posts: 6,240 Joined: 30-December 06 From: Northampton, MA USA Member No.: 884 |
I also read about this behaviour in the avira forum If anyone is part of any of these threads I would be interested to get a reaction the the following question : "vundo is randomly named and polymorphic yet MBAM detects it far more often then most AVs , how are they doing this with just file names and MD5s ?" This is another good one : "why is MBAM the only application that seems to have a handle on antivirus xp 2008 . it is randomly named and detected by next to no AVs on a regular basis , how are they doing this ?" It would also help us if it was made clear that we are not an AV . -------------------- |
|
|
|
Sep 23 2008, 01:42 PM
Post
#15
|
|
![]() Elite Member ![]() ![]() ![]() ![]() ![]() Group: Honorary Members Posts: 1,050 Joined: 25-December 05 From: Ont. Canada Member No.: 100 |
If anyone is part of any of these threads I would be interested to get a reaction the the following question : Do you have a reference for those statements?"vundo is randomly named and polymorphic yet MBAM detects it far more often then most AVs , how are they doing this with just file names and MD5s ?" This is another good one : "why is MBAM the only application that seems to have a handle on antivirus xp 2008 . it is randomly named and detected by next to no AVs on a regular basis , how are they doing this ?" It would also help us if it was made clear that we are not an AV . I can't seem to find them. -------------------- E5200 2.5GHZ, 4GB RAM, 320GB HD, Win7 Home Pro 64-bit, avast! V5 Free
P4 2.8GHZ, 1.5GB RAM, 40GB HD, XP Pro SP3, 32-bit, avast! V5 Free with Finjan SecureBrowsing, IE8, hpHosts, MVPS HOSTS files, MBAM Full, OpenDNS, SpeedFan, WinPatrol PLUS |
|
|
|
Sep 23 2008, 03:03 PM
Post
#16
|
|
![]() Marcin ![]() ![]() ![]() ![]() ![]() ![]() Group: Root Admin Posts: 4,212 Joined: 15-October 05 Member No.: 1 |
QUOTE Do you have a reference for those statements? They were questions Bruce was asking. -------------------- |
|
|
|
Jan 9 2009, 01:59 PM
Post
#17
|
|
|
Advanced Member ![]() ![]() ![]() Group: Honorary Members Posts: 119 Joined: 4-August 08 Member No.: 3,132 |
|
|
|
|
Jan 10 2009, 12:11 AM
Post
#18
|
|
![]() Marcin ![]() ![]() ![]() ![]() ![]() ![]() Group: Root Admin Posts: 4,212 Joined: 15-October 05 Member No.: 1 |
Posted back, guy is very misinformed.
-------------------- |
|
|
|
Jan 10 2009, 04:31 PM
Post
#19
|
|
![]() Elite Member ![]() ![]() ![]() ![]() ![]() Group: Honorary Members Posts: 1,050 Joined: 25-December 05 From: Ont. Canada Member No.: 100 |
Posted back, guy is very misinformed. Reminds me of of a Flame Warrior: http://redwing.hutman.net/~mreed/warriorshtm/lonelyguy.htm -------------------- E5200 2.5GHZ, 4GB RAM, 320GB HD, Win7 Home Pro 64-bit, avast! V5 Free
P4 2.8GHZ, 1.5GB RAM, 40GB HD, XP Pro SP3, 32-bit, avast! V5 Free with Finjan SecureBrowsing, IE8, hpHosts, MVPS HOSTS files, MBAM Full, OpenDNS, SpeedFan, WinPatrol PLUS |
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 9th February 2010 - 04:20 PM () |