beardednose
Jul 21 2003, 02:58 PM
Article from http://www.gfi.com/mailsecurity/wptrojans.htm. Good article, but keep in mind the sponsor sells the "solution".... Excerpt.... Anti-virus software recognizes only a portion of all known Trojans and does not recognize unknown Trojans.... If the person planning to attack you finds out what anti-virus software you use, for example through the automatic disclaimer added to outgoing emails by some anti-virus engines, he will then create a Trojan specifically to bypass your virus scanner engine.... To effectively protect your network against Trojans, you must follow a multi-level security strategy: - implement gateway virus scanning and content checking at the perimeter of your network for email, HTTP and FTP - It is no good having email anti-virus protection, if a user can download a Trojan from a website and infect your network. - implement multiple virus engines at the gateway - Although a good virus engine usually detects all known viruses, it is a fact that multiple virus engines jointly recognize many more known Trojans than a single engine. - quarantine/check executables entering your network via email and web/FTP at the gateway. You have to analyze what the executable might do....
linuxwolf
Aug 10 2003, 02:07 AM
Thats all very well (joining multiple antivirus engines), if you think you can pull it off.. What i have experienced is that one antiviruse sees anothers virus definitions as a virus, it also sees every file on your system "infected" beacause it may have been "marked" as you may find out moving from zonealarm to mcaffee. You ask it to clean all the files and it TOTALLY screws up your system, and thats problem number one.
Number two is many more ports can be opened etc and the current firewalls i've seen most networks running haven't support for ipv6. This could also lead to more holes as it is trying to read 9AkjNk::8787da::khdkjh::73879837 As a ipv4. This MAY cause a buffer overflow (i doubt it) or confuse the filtering system....
Number three is no matter how many virus definitions there are they can be so easilly edited, if you have a root kit on a shelll, you could set a crond service with the kernel name or something else, and have it every 5 hours run a background process to change the file size (root kit) by adding or removing white spaces (zeros) and rename it? Thing is, when all the antivirus stop all the viruses, which wont happen i hope, there will be nothing left.. But i think computers are only limited by their spec, not by imagination.
BDK
Oct 24 2003, 05:56 AM
Use a trojan scanner get TDS-3 http://tds.diamondcs.com.auAnd Port Explorer while there ! shows ports in use and maps them to processes, and shows them in red if they are running "hidden"
akis
Dec 7 2003, 02:06 PM
 the method on win i use for every trojan is.... 0)install an anti-virus(also update it)and a well knowed firewall 1)netstat throw command for the connectios.if i see something suspicious i proceed to the second step 2)alt_ctrl_del for listing the running proccesses.if you know your system very good you will found out what is the suspicious file 3)find it and delete it after killing it from the proccesses 4)open registry and find the startup HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion <- the usual way a trojan can make itself bootable.find and delete the suspicous keys from the folders run,runonce etch.. 5)the steps 1-4 are my method of removing any trojan....even tha undetectable. 6)if you want to be more insane install a keylogger and take a look at the logs..mabe you will found out that someone is using your computer!
usefull info....
10x m8s !
Dillinja
Dec 8 2003, 11:06 PM
| QUOTE (akis @ Dec 7 2003, 02:06 PM) | 1)netstat throw command for the connectios.if i see something suspicious i proceed to the second step 2)alt_ctrl_del for listing the running proccesses.if you know your system very good you will found out what is the suspicious file 3)find it and delete it after killing it from the proccesses 4)open registry and find the startup HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion <- the usual way a trojan can make itself bootable.find and delete the suspicous keys from the folders run,runonce etch.. 5)the steps 1-4 are my method of removing any trojan....even tha undetectable. |
Thats slightly over-optimistic isnt it? Just because a trojan/virus/malware is undetectable, doesnt mean its your average nasty after some nice hex editing, where you go to your registry settings and boom, there it is in frot of you. There has been some designed to sit at the base of the protocol stack, thereby defeating firewalls (since the trojan is now the gatekeeper), netstat, etc etc.. For more...d/l the text from m3du54 here: http://www.hackingdynasty.com/text/texts.php?sect=misc
akis
Dec 9 2003, 10:29 AM
Dillinja well that's the method i use for common trojans.....not for well hide trojans(don't figure out that yet).anyway http://www.hackingdynasty.com/ is very good!they have some excellent manuals
Dillinja
Dec 9 2003, 12:34 PM
| QUOTE (akis @ Dec 9 2003, 10:29 AM) | | Dillinja well that's the method i use for common trojans.....not for well hide trojans(don't figure out that yet).anyway http://www.hackingdynasty.com/ is very good!they have some excellent manuals |
There are some excellent texts there for sure! Most areas well covered.
Flowby
Dec 9 2003, 11:55 PM
You cant see all trojans in proces bar !You even cant find the infected file becouse it isnt shown in your computer lol!Once i was exsperimenting with the my friends exsperimental file when i run it ,it has bypased firewall ,proces box ,and i was looking for it i dindnt find it anywhere (I know the name of it)...... NEW TROJANS ARE COMING,NEW TEHNOLOGIES(LAN BYPAS,ROOTKIT,AKA) CHECK this trojan out you wont belive! I will send you a private mesage ,becouse i dont want to make it dedected..... bye
uk-nutta
Dec 12 2003, 02:38 AM
I have a habit which i would like to share with u all. I INFECT MYSELF FOR FUN
Spookie
Jan 17 2004, 03:39 AM
Heres a link on an Anti-Trojan Review. You may find the information interesting. Anti-trojan Software
BDK
Jan 29 2004, 07:13 AM
Well the latest best protection is here  Stop ALL current and probably future DLL trojans and Rootkits, as well as more. Stop termination of AV / FW and modification of those processes (like patching them to not alarm on anything) Process Guard, www.diamondcs.com.au/processguard Infect yourself for fun while you play with this  well you can TRY
nulladd
Jan 29 2004, 03:06 PM
so how do many of you get infected by trojans (game trainers, files of this forum, etc), my simple solution is to run suspect files in good ol vmware to see what they do although saying that theres no harm in a bit more protection
Trojan^kid
Feb 3 2004, 04:00 AM
Trojans become hard to detected packers hex edit and u culde be infcted with atrojan in a web pages .html .php or .ram .swf cheers
Spookie
Feb 6 2004, 03:07 AM
What I find interesting is the push of the dialers to the user via the web browser. Pretty smooth.
qcred11
Apr 3 2004, 12:35 AM
Yeah.. best thing to protect yourself from trojans is good firewall rules + PestPatrol (PestPatrol rated 10/10 on Anti-Trojan.org software reviews).By the way don't forget to update Pestpatrol database with new trojans signatures, otherwise that software will be worhtless. I'm using this combination for more than a year... didn't have any problems.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
|