Mourning the loss of our friend, WhitPhil.
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
 
General Security
Tag Cloud
access audio black screen blue screen boot bsod connection crash dell desktop driver drivers dvd email error excel firefox hard drive hardware hdmi hijackthis internet keyboard laptop malware monitor network networking outlook problem ram recovery router safe mode screen slow sound spyware trojan upgrade vba video virus vista vundo windows windows 7 windows vista windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > General Security >
Solved: Hidden Viruses/Trojans in exe files

Tip: Click here to scan for System Errors and Optimize PC performance
[ Sponsored Link ]

Closed Thread
 
Thread Tools
Book's Avatar
Senior Member with 163 posts.
 
Join Date: Jun 2007
Experience: Advanced
22-Apr-2008, 09:41 AM #1
Solved: Hidden Viruses/Trojans in exe files
Hi,

For some time now, I've been using VirusTotal (a free online service) to scan various exe files that I download from the internet. The service scans the files with (currently) 32 different AVs. The problem is that almost ALWAYS some of those AVs will report something. I know it's possible for a trojan to be encrypted and therefore undetectable by its common signature. But if I execute that trojan, could it be opening ports in my computer and sending out information, messing around with my files and all that, WITHOUT my AV and firewall even report anything?? I'm really worried about this!

Thanks
lunarlander's Avatar
Computer Specs
Senior Member with 1,329 posts.
 
Join Date: Sep 2007
23-Apr-2008, 08:04 PM #2
Yes, they can disable firewall and disable/evade anitvirus programs.

You need to periodically check that your security apps are still running. For firewalls, you can test with grc.com. For antivirus, you can use the eicar test virus file. Suppliment your onboard antivirus with an online scan once a month from another vendor.

'the price of security is eternal vigilance'.
Book's Avatar
Senior Member with 163 posts.
 
Join Date: Jun 2007
Experience: Advanced
24-Apr-2008, 05:58 PM #3
I did both of these tests and it seems that my PC is most secure, but why is it then that some exe files are reported as having some sort of virus (from virus total), and my PC still remains so secure? I mean if it was a trojan of some sort, it must have services running, for example.

If it's an encrypted virus, during the execution of that file, if it was executing some suspicious code wouldn't I be warned? If it's an encrypted virus, is there any chance that I detect it?
Byteman's Avatar
Moderator with 14,997 posts.
 
Join Date: Jan 2002
Location: NY
Experience: Junkware Jouster
25-Apr-2008, 10:41 PM #4
Hi, The odds are that one of the scanners sees x file as a threat, but actually it may be a false positive, there have been many through the years, and which some of are still being found as threats.

It would help a great deal if you would post the filenames, showing the exact and full path the file(s) are located in, so we can help you better.
Book's Avatar
Senior Member with 163 posts.
 
Join Date: Jun 2007
Experience: Advanced
26-Apr-2008, 10:35 AM #5
It's not one particular file, it sometimes happens with many of the files I download from the internet. The files are not official executables from a company of some sort, but rather user-made and that's what makes me worry.

What I'm saying is:
OK, it may be impossible to detect a virus or a trojan by its signature (even if it's known) when it's encrypted in some file. But when I launch that file and execute the malicious code, wouldn't my AV or spybot detect the suspicious activity (rather than its signature) and block it or even notify me?
Byteman's Avatar
Moderator with 14,997 posts.
 
Join Date: Jan 2002
Location: NY
Experience: Junkware Jouster
26-Apr-2008, 09:07 PM #6
Hi, Yes, a decent antivirus or other security program should alert you to any suspicious file or activity.

When you download files, the better security programs also scan them then but as you say, there may be no detection right then. Probably half or better of the infected computers we help remove malware from here, are using P2P filesharing to download.... many of those people would not end up in such bad shape, if the files themselves that do contain malware were detected as they were downloading.

There is always newer types of malware and more new ways to spread it coming out all the time, so it doesn't pay to not scan downloads- even browsing the Net will sometimes pop up an alert> there are thousands of hacked, infected websites around so it does not always take a file download to get malware in a computer.

Last edited by Byteman : 26-Apr-2008 09:14 PM.
Book's Avatar
Senior Member with 163 posts.
 
Join Date: Jun 2007
Experience: Advanced
28-Apr-2008, 05:35 PM #7
So if it started messing around with my files and editing stuff, it would in fact get noticed from my AV?

Weird this is that if I write in a batch file something like
del c:\windows
and maybe even make it an executable, my AV will not detect this as a virus!
Book's Avatar
Senior Member with 163 posts.
 
Join Date: Jun 2007
Experience: Advanced
18-May-2008, 07:26 PM #8
I've read in another forum that you can encrypt a trojan to make it invisible.. When executing the trojan, won't it need to get unencrypted in some temporary file, and then executed (therefore the AV will detect it)?

Why won't AV software detect malware based on their activity rather than a signature? The signature detection is so weak, that any dedicated user will be able to bypass!
lotuseclat79's Avatar
Distinguished Member with 14,984 posts.
 
Join Date: Sep 2003
Location: -71.45091, 42.27841
18-May-2008, 07:50 PM #9
Hi Book,

Not all AVs are signature based, i.e. NOD32 is an example of a heuristic AV based on patterns.

-- Tom
Book's Avatar
Senior Member with 163 posts.
 
Join Date: Jun 2007
Experience: Advanced
21-May-2008, 05:28 AM #10
Is there a way I can keep NOD32 with my current AV?
Gizzy's Avatar
Computer Specs
Distinguished Member with 3,437 posts.
 
Join Date: Aug 2005
Location: NJ, USA
Experience: Comp Security Enthusiast
21-May-2008, 05:50 AM #11
no you shouldn't run more than 1 av,

a better idea would be to use a behavior blocker like TheatFire it looks for viruses by it's behavior not it's signature.
lotuseclat79's Avatar
Distinguished Member with 14,984 posts.
 
Join Date: Sep 2003
Location: -71.45091, 42.27841
21-May-2008, 09:49 AM #12
Quote:
Originally Posted by Book View Post
Is there a way I can keep NOD32 with my current AV?
Hi Book,

Contrarily, it is possible to have more than one AV. The point is to use one only in Safe mode to do a thorough scan of your disks, and then use the other for real-time detection when your computer is fully booted up and connected to the Internet - i.e. never run them both at the same time.

I'd recommend using NOD32 when connected to the Internet, and the other (installed AV) in Safe mode, i.e. this does not include any remote web site scanning your disks, processes, etc. over the Internet.

-- Tom
__________________
The independence created by philosophical insight is - in my opinion - the mark of distinction
between a mere artisan or specialist and a real seeker after truth. - Einstein 1944
Imagination is more important than knowledge. - Einstein
Blackmirror's Avatar
Computer Specs
Distinguished Member with 28,046 posts.
 
Join Date: Dec 2006
Location: uk
Experience: Chocoholic
21-May-2008, 10:41 AM #13
It is always a good idea to scan any files you download from the internet
Whether you trust the source or not

There are some real nasty baddies out there waiting to be unleashed

I have noriced AVG 8 is fantastic at spotting these
My son sent me an infected mp3
AVG nabbed it as i was trying to play it
__________________
In the cookies of life, friends are the chocolate chips.
Book's Avatar
Senior Member with 163 posts.
 
Join Date: Jun 2007
Experience: Advanced
22-May-2008, 07:15 AM #14
Thanks for the link Gizzy, the program looks pretty good.

In my opinion, more AVs should be joining with the trend, not to detect threats based on signature, but on behaviour.

You say you got an infected mp3? I thought only executable files could contain a virus (exe of bat or any other executable). How could an mp3 execute code?

Last edited by Book : 22-May-2008 07:40 AM.
lunarlander's Avatar
Computer Specs
Senior Member with 1,329 posts.
 
Join Date: Sep 2007
22-May-2008, 09:15 AM #15
A virus mp3 probably embeds an exploit for a particular mp3 player and also code. So the idea is that it uses a bug in the mp3 player to insert its own code, and the mp3 player executes that code as if it were its own.
Closed Thread Bookmark and Share

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Smart Search

Find your solution!



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.

Thread Tools


You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -5. The time now is 07:43 AM.
Copyright © 1996 - 2009 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2009, Jelsoft Enterprises Ltd.
Powered by Cermak Technologies, Inc.