Author Topic: 5 Hours old ZeroAccess Rootkit is blocked by Evo-Gen Technology!!!  (Read 2940 times)

0 Members and 1 Guest are viewing this topic.

true indian

  • Guest
Thanks to spywar for the test ;D ...like 4 to 5 hours old brand new Zeroaccess against avast:

results :

data.exe
https://www.virustotal.com/en/file/c193fedefd5bd6d78dd881cee711c0b67caf553c4669cd1164eaf4880eefdc1c/analysis/

execution
http://image.noelshack.com/fichiers/2013/10/1362572293-2013-03-06-131746.png

this is just so amazing!!!  ;D

spywar

  • Guest
Re: 5 Hours old ZeroAccess Rootkit is blocked by Evo-Gen Technology!!!
« Reply #1 on: March 06, 2013, 01:34:53 PM »
To those that would like to see Evo-Gen / Similarity Search / Autosandbox detection / in action (with undetected FRESH samples of course ...)

Please watch these :

http://www.youtube.com/user/spywarosaurus/videos?view=0&flow=grid

spywar

true indian

  • Guest
Re: 5 Hours old ZeroAccess Rootkit is blocked by Evo-Gen Technology!!!
« Reply #2 on: March 06, 2013, 01:35:41 PM »
Once again thanks spywar for your tests they have been really fruitful  ;D

spywar

  • Guest
Re: 5 Hours old ZeroAccess Rootkit is blocked by Evo-Gen Technology!!!
« Reply #3 on: March 07, 2013, 09:25:00 AM »
Another great performance with many autosandbox's detections !

http://www.youtube.com/watch?v=utvReJDa8hE   

spywar

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: 5 Hours old ZeroAccess Rootkit is blocked by Evo-Gen Technology!!!
« Reply #4 on: March 07, 2013, 09:52:16 AM »
I'm just wondering what the hell happened with the samples that weren't detected the first run in Auto Sandbox...
Visit my webpage Angry Sheep Blog

spywar

  • Guest
Re: 5 Hours old ZeroAccess Rootkit is blocked by Evo-Gen Technology!!!
« Reply #5 on: March 07, 2013, 10:44:48 AM »
I'm just wondering what the hell happened with the samples that weren't detected the first run in Auto Sandbox...
Don't know why the sample was not autosandboxed first but was on second execution ... It's cloud based so things like that can happen no ?

true indian

  • Guest
Re: 5 Hours old ZeroAccess Rootkit is blocked by Evo-Gen Technology!!!
« Reply #6 on: March 07, 2013, 11:10:29 AM »
I'm just wondering what the hell happened with the samples that weren't detected the first run in Auto Sandbox...

I was wondering the same thing dont know what happened there...first time I have ever seen that weird a issue  :o

spywar

  • Guest
Re: 5 Hours old ZeroAccess Rootkit is blocked by Evo-Gen Technology!!!
« Reply #7 on: March 07, 2013, 11:17:17 AM »
BTW, I asked Vlk over an e mail ...

« Last Edit: March 07, 2013, 11:34:55 AM by spywar »

spywar

  • Guest
Re: 5 Hours old ZeroAccess Rootkit is blocked by Evo-Gen Technology!!!
« Reply #8 on: March 07, 2013, 02:16:59 PM »
New one, here is a comparaison of Trend Micro vs Avast!

http://www.youtube.com/watch?v=wiTHW_gzVKE&feature=player_embedded

Both are really good to protect user while surfing but Avast did a great job again with these new toys ...

spywar

  • Guest
Re: 5 Hours old ZeroAccess Rootkit is blocked by Evo-Gen Technology!!!
« Reply #9 on: March 07, 2013, 05:09:53 PM »
Reason :

During my test at the same time : One of the FileRep servers was down.