Showing posts with label Virustotal Scanners. Show all posts
Showing posts with label Virustotal Scanners. Show all posts

Saturday, 15 August 2015

Kaspersky Accused Of Sabotage Anti-virus Companies


The Russian anti-virus firm Kaspersky Lab would have the virus for years of competing anti-virus companies sabotaged to show to clean files for malware, so important files were deleted or quarantined.

Let two former employees facing Reuters know. Kaspersky Lab, however, denies any wrongdoing. According to former employees, there was a secret campaign against Microsoft, AVG, Avast and other competitors that lasted for ten years. The plan would be carried out with the knowledge of Kaspersky founder Eugene Kaspersky. According to former employees, who wish to remain anonymous, Kaspersky found that the competition software imitated.

Microsoft, AVG and Avast showed earlier told Reuters that unknown parties in recent years had tried to cause false positives, such as the improper detection of clean files as malware is called. According to the former employees of Kaspersky were provided important files from malicious code, to upload them then to VirusTotal. This website Google scans files with dozens virus. Uploaded files are then shared with connected anti-virus companies.

If the malicious file seemed adequate to the original, the virus would clean file as malware can label. Microsoft says that in 2013 discovered thousands of these files and warned here at that time also ( pdf ). Kaspersky Lab said in a statement that it has never carried out such a secret campaign to mislead competitors with false positives. "Such actions are unethical, unfair, and if it is legal, at least questionable," said the Russian virus fighter.

Update

Eugene Kaspersky cites Reuters story on Twitter complete nonsense. "Usually I do not read to Reuters, but when I do I see false positives. This story was complete nonsense."

Friday, 22 May 2015

Secret Unit Google Fights Against Botnets And Click Fraud


Google has a secret unit of over a hundred people who are working every day with combating botnets click and ad commit fraud. The botnets generate traffic and clicks for ads and would advertisers and advertising platforms billions of euros.

Google is the largest ad provider on the Internet ad fraud and therefore constitutes a serious risk to giant internal. A risk is increasing. "We are at a point which malware is being used mainly for advertising fraud," says Douglas Hunter Google versus Ad Age . The website received a unique insight into the workings of the secret unit, whose existence has not been made ​​public by Google.

Malware

To combat fraud, the ad team analyzes all kinds of malware, which include Google through the online virus scan service VirusTotal receives. By analyzing the malware a click fraud botnet can be mapped. Then look at the traffic that generates the malware. Traffic which malware authors try to make it look as human as possible.

In the Google case "non-human" traffic will encounter the publisher ads showing not paid and the advertiser is no fee will be charged. By now inspire to step outside Google hopes other companies to share their findings and to tackle together ad fraud."Our job is to increase the cost for the fraudsters to a point that advertising fraud no longer interesting for them," concludes De Jager.

Sunday, 22 February 2015

Virustotal: "Easily Detect Malware With Free Microsoft Sysinternal Tool Process Explorer"

Microsoft has been offering the free program Process Explorer, but recently it cooperates with VirusTotal Google, allowing users to easily check their computer for malware. Process Explorer shows an overview of services, programs, and files that are running on the computer. Through the integration with VirusTotal hashes may be checked at VirusTotal.

VirusTotal is an online virus scanner that scans files by 57 virus scanners. By the online virus scan service via Process Explorer to call can be clearly or suspicious files on your computer are active. Microsoft security architect Roger Grimes late InfoWorld know how suspicious files then disable via Process Explorer. Then he removes the computer the file in question manually.

Grimes warns Windows users that deleting files is at your own risk. It can namely that a virus file wrongly regarded as malware or that the file in question is a driver or other important program component. Some malware can not be closed by Process Explorer. For this, use Grimes Autoruns , another free program from Microsoft, which prevents the infected file the next time Windows starts loading.

The security architect stressed that this detection is not perfect. Some malware to evade detection, although that is special, says Grimes. "In the future, do virus writers struggled to avoid Process Explorer and Autoruns, but this is currently not the case. This method is therefore one of the best protection methods that you can use."