Need a no-bullshit antivirus/trojan/malware scanner

If it's not ZDoom, it goes here.
User avatar
Nash
 
 
Posts: 17501
Joined: Mon Oct 27, 2003 12:07 am
Location: Kuala Lumpur, Malaysia
Contact:

Need a no-bullshit antivirus/trojan/malware scanner

Post by Nash »

I am usually VERY careful with this stuff but recently I think I may have done something to compromise my system, I need recommendations for a straight-to-the-point, no BS solution that can detect any of the rubbish on my system... help please.
User avatar
Caligari87
Admin
Posts: 6234
Joined: Thu Feb 26, 2004 3:02 pm
Preferred Pronouns: He/Him
Contact:

Re: Need a no-bullshit antivirus/trojan/malware scanner

Post by Caligari87 »

In my understanding, MalwareBytes was and still is a very thorough and respected solution, though it may not get everything. I'd say run that first then see if you're still having problems. Some of the more insidious stuff may need dedicated removal tools.

8-)
User avatar
SHayden
Posts: 176
Joined: Sat Jan 28, 2017 11:03 am
Location: Europe

Re: Need a no-bullshit antivirus/trojan/malware scanner

Post by SHayden »

Since you're talking about it can someone tell me a good antivirus or something, I'm using avast but I feel like it munches on my computer's resources almost like chrome and sometimes it kicks in and my game drops from 60 fps to 40-45 and it pisses me the hell out. >:(
User avatar
Solid-Head
Posts: 57
Joined: Thu Sep 11, 2014 1:07 pm

Re: Need a no-bullshit antivirus/trojan/malware scanner

Post by Solid-Head »

What did you install exactly before the problems start happening ?

Try using Ccleaner and check what is on Startup. Disable any entry that look suspicious and start deleting the malware manually (Don't forget in Regedit too).

There is no good antivrus. Nod32 and Kaspersky are good but use way too much ressources and leave atrocious mess in your files and registry after desintallation.
User avatar
Rachael
Posts: 13955
Joined: Tue Jan 13, 2004 1:31 pm
Preferred Pronouns: She/Her
Contact:

Re: Need a no-bullshit antivirus/trojan/malware scanner

Post by Rachael »

It might be a brand new variant of the Pantera trojan that was dropped with a Powershell-scripted trojan.

There's not enough analysis done on this variant yet because it *just* appeared. But it uses an obfuscated powershell script to spawn an .exe file that is Base-64 encoded inside the script.

Since the file was submitted to VirusTotal though - that means all anti-malware authors will be receiving a sample of this one, and hopefully it means that detections will be written by tonight and we might get some documentation on what it does.
User avatar
Nash
 
 
Posts: 17501
Joined: Mon Oct 27, 2003 12:07 am
Location: Kuala Lumpur, Malaysia
Contact:

Re: Need a no-bullshit antivirus/trojan/malware scanner

Post by Nash »

Yes, I've ran this through with Rachael privately and it appears she's had some of it figured out. This is VERY new, literally almost no results on Google.
User avatar
NeuralStunner
 
 
Posts: 12328
Joined: Tue Jul 21, 2009 12:04 pm
Preferred Pronouns: No Preference
Operating System Version (Optional): Windows 11
Graphics Processor: nVidia with Vulkan support
Location: capital N, capital S, no space
Contact:

Re: Need a no-bullshit antivirus/trojan/malware scanner

Post by NeuralStunner »

I've had good results in the past with Norman malware cleaner. Also a neat choice because it obfuscates itself to work around malware that blocks antivirus webpages and executables.
User avatar
Reactor
Posts: 2091
Joined: Thu Feb 03, 2011 6:39 pm
Location: Island's Beauty, Hungary

Re: Need a no-bullshit antivirus/trojan/malware scanner

Post by Reactor »

Spybot Search & Destroy can also be a viable option. It helped meg countless times, and it is very capable of annihilatin' lots of unwanted visitors. Its "immunization" feature is also a very effective one to say the least.
And the best of all - it is free! I'd say give it a try.
User avatar
R4L
Global Moderator
Posts: 425
Joined: Fri Mar 03, 2017 9:53 am
Preferred Pronouns: He/Him
Operating System Version (Optional): Windows 11 Pro
Graphics Processor: ATI/AMD with Vulkan/Metal Support
Contact:

Re: Need a no-bullshit antivirus/trojan/malware scanner

Post by R4L »

Definitely recommend MalwareBytes and the sister app Adwcleaner. If it is really persistent, HijackThis and ComboFix usually work with a little know-how. Clam-Win is a viable A/V as well.
User avatar
Rachael
Posts: 13955
Joined: Tue Jan 13, 2004 1:31 pm
Preferred Pronouns: She/Her
Contact:

Re: Need a no-bullshit antivirus/trojan/malware scanner

Post by Rachael »

None of those work to detect it yet. I just reanalyzed the file, and it's still fairly unknown.

https://www.virustotal.com/#/file/8ddf4 ... /detection
User avatar
R4L
Global Moderator
Posts: 425
Joined: Fri Mar 03, 2017 9:53 am
Preferred Pronouns: He/Him
Operating System Version (Optional): Windows 11 Pro
Graphics Processor: ATI/AMD with Vulkan/Metal Support
Contact:

Re: Need a no-bullshit antivirus/trojan/malware scanner

Post by R4L »

Rachael wrote:None of those work to detect it yet. I just reanalyzed the file, and it's still fairly unknown.

https://www.virustotal.com/#/file/8ddf4 ... /detection
Ah, I missed Nash's second post. Didn't realize it was new-new. Still, MalwareBytes should have a definition for it soon especially with the payload uploaded.
User avatar
Rachael
Posts: 13955
Joined: Tue Jan 13, 2004 1:31 pm
Preferred Pronouns: She/Her
Contact:

Re: Need a no-bullshit antivirus/trojan/malware scanner

Post by Rachael »

Yeah, it's really a question of how often AV vendors check VirusTotal. Apparently it seems, not very often.
User avatar
Nash
 
 
Posts: 17501
Joined: Mon Oct 27, 2003 12:07 am
Location: Kuala Lumpur, Malaysia
Contact:

Re: Need a no-bullshit antivirus/trojan/malware scanner

Post by Nash »

In the end, I just decided to format because I didn't want to take any chances. Oh well.
User avatar
Rachael
Posts: 13955
Joined: Tue Jan 13, 2004 1:31 pm
Preferred Pronouns: She/Her
Contact:

Re: Need a no-bullshit antivirus/trojan/malware scanner

Post by Rachael »

This is a really good demonstration of the true threat of malware:

No matter how careful you are, no matter how many virus scanners you have, no matter how good you think your virus scanner is - all the virus scanners in the world are not going to protect you when something new comes out. Does that mean it's useless to have one? Of course not. But it's by no means a substitute for practicing "safe internetting". And backing up your shit frequently.

The first time this file got scanned, it came up with about 12 vague positives, mostly obtained through heuristics. Now - detection is a lot more robust. But it's still not perfect - many scanners are not processing this file properly.

https://www.virustotal.com/#/file-analy ... E5NTc5Mg==

Anyway - I hope you all learned something. It's a dangerous world out there - always stay safe! :)
kb1
Posts: 64
Joined: Thu Oct 11, 2012 6:47 pm

Re: Need a no-bullshit antivirus/trojan/malware scanner

Post by kb1 »

Rachael wrote:This is a really good demonstration of the true threat of malware:

No matter how careful you are, no matter how many virus scanners you have, no matter how good you think your virus scanner is - all the virus scanners in the world are not going to protect you when something new comes out.
My method protects me pretty much 100%, but it's not for everyone:
1. Don't connect your main PC to any network connected to the internet.
2. Scan your files on your internet network, for a few weeks, to give the major AV vendors time enough to detect and create signatures for the latest malware.
Post Reply

Return to “Off-Topic”