Software Review Kaspersky vs infected system in 2025

Reviews reflect the reviewer's setup and methods. Check the evidence and limitations.
Thread details
Content created by
TPSC
Good point, as even though @3:14 he says, "so how did we get infected?" he never mentions that source, or for our sakes, a possible source to be aware of, but only goes through the infection on the PC itself.
I'm pretty sure he ran over 1000 zero-day malware in one shot using Python code (as he usually does) and then oh it's a Microsoft Defender issue.
 
From what I have seen, the AV that is most proactive at preventing any unknown programs to add anything in MD's exclusion is Bitdefender. It blocks them whenever an attempt is made by anything unknown. One Defender's job is done by another Defender.
I heard that this is a bug and not a feature in Bitdefender, as some users claim that whitelisting does not work in Bitdefender and therefore anything they add will be blocked.
 
I heard that this is a bug and not a feature in Bitdefender, as some users claim that whitelisting does not work in Bitdefender and therefore anything they add will be blocked.
And the last I heard was to try disabling Antivirus and ATD then adding the exclusions, re-enabling them again, but I'm not sure that worked?
It was a bit of hit and miss for some, of those who tried using that feature.
 
Last edited:
I heard that this is a bug and not a feature in Bitdefender, as some users claim that whitelisting does not work in Bitdefender and therefore anything they add will be blocked.
That's a different thing. If I remember correctly, only exe file can be added to Bitdefender's behavior blocker (ATD). It's more like a limitation, less like a bug. But a pain for the users, of course.
What I mentioned in my previous comment is that, many malware try to add them/their working directory to Microsoft Defender's exclusion (not Bitdefender's) before executing malicious action since most people use MD. If you are using Bitdefender and you run those malware, after running when Bitdefender sees that the program is trying to add something to MD's exclusion, it stops that malware immediately without waiting for any further malicious action.
I wish MD did this or at least ask the user if they want to allow that or not.
 
That's a different thing. If I remember correctly, only exe file can be added to Bitdefender's behavior blocker (ATD). It's more like a limitation, less like a bug. But a pain for the users, of course.
What I mentioned in my previous comment is that, many malware try to add them/their working directory to Microsoft Defender's exclusion (not Bitdefender's) before executing malicious action since most people use MD. If you are using Bitdefender and you run those malware, after running when Bitdefender sees that the program is trying to add something to MD's exclusion, it stops that malware immediately without waiting for any further malicious action.
I wish MD did this or at least ask the user if they want to allow that or not.
Correct, only .exe files into ATD exclusions.
 
And the last I heard was to try disabling Antivirus and ATD then adding the exclusions, re-enabling them again, but I'm not sure that worked?
It was a bit of hit and miss for some, of those who tried using that feature.
This kind of test is like someone stabbing himself with a knife to see if he can die or not, and then blaming those who say that people do not die easily.
 
What I mentioned in my previous comment is that, many malware try to add them/their working directory to Microsoft Defender's exclusion (not Bitdefender's) before executing malicious action since most people use MD. If you are using Bitdefender and you run those malware, after running when Bitdefender sees that the program is trying to add something to MD's exclusion, it stops that malware immediately without waiting for any further malicious action.
Is this vulnerability only related to MD or other antivirus software share this, and what about MD hardeners, can they fix this issue?
 
This needs to be revised to:

"showing how the system was infected with a malware is highly unprofessional and unethical."
Wow..now the world need Leo to hide how a malware gets to windows just to prevent bad actors as if he is the only one with such knowledge. He shows wd has a signature to that specific malware and he then shows its infected, even a kid in elementary school can infect a windows system, if he switches wd off. Now if he hadn't done that, he is bound to show it to the world, making something look bad and then profetering from that is not " research" it's a con job.
 
Is it still valid? Inflated files bypassing KVRT?
KVRT has not been updated since 2020.

I cannot imagine that Kaspersky would reprogram KVRT to be able to process large sized files (> 200 MB).

As far as I recollect, there is no publisher out there that does NOT limit file size scanning to avoid slow scans and cause other problems - such as system instability. Some files would take an "impractical" amount of time to analyze.

It makes no sense to scan large sized files. Just like it don't make sense to pay a Somali pirate's ransom demand or install Kaspersky on any system with highly sensitive national security data on it.
 
I think Avast has this option.
Some business solutions as well, like CP Harmony.

There are loads of ways to spot these bloated files.

The best way (very accurate) is to take few random samples from different places of the file (byte snapshots) and calculate the shannon entropy. Usually it will be very low entropy because attackers need to transmit the bloated file, more often than not via email. To compress it from 1.5 GB or whatever to 25 mb, it needs to have a lot of repetition. The repetition causes the low shannon entropy, usually 2 or less.

It is important to note that behavioural analysis and memory analysis in real time which is found in the Kaspersky products can detect the memory anomalies (like 1.5GB file allocating 10 mb of RAM) as well as various other parameters.

KVRT is not the best tool to measure the efficiency of Kaspersky.

With the bloated files a lot of products have problems, the solutions are usually band aids which attackers very quickly tear apart.

Often these bloated files come with modules for a nice taste of DLL sideloading.
Some solutions are good at spotting side-loading, others not so much.
 
KVRT has not been updated since 2020.

I cannot imagine that Kaspersky would reprogram KVRT to be able to process large sized files (> 200 MB).

As far as I recollect, there is no publisher out there that does NOT limit file size scanning to avoid slow scans and cause other problems - such as system instability. Some files would take an "impractical" amount of time to analyze.

It makes no sense to scan large sized files. Just like it don't make sense to pay a Somali pirate's ransom demand or install Kaspersky on any system with highly sensitive national security data on it.
Screenshot 2025-10-26 at 22-49-14 Windows Search kaspersky - Softpedia.png
 
I have found an option but for archive files only regarding MD; however, I do not what is the default size.

View attachment 292351
But that’s for archives, these files are not archives. They are padded. So the malicious executable (rat server) which will be detected by 60/72 on VT is put in the middle (more or less) and around it there are insanely large strings from the sort of AAAAAAAAAAABBBBBBBBBBBCCCCCCCCCCCCDDDDDDDDD and so it goes until from 150 kb file you get 1GB. On runtime the malicious server is extracted in memory, everything else is ignored.

This repetition enables the compression so the malware can be transmitted, often in a password protected archive.

There are many ways behavioural blocking can spot these, for starters it can notice processes that don’t really have a file on disk. This is not malicious on its own but combined with other indicators is a good start. They then initiate many connections in a rapid succession, often to generated domains or low reputation domains. It all adds up.

For developers that know what they are doing.
 
Last edited:
Here comes "common sense" to play; when I extract 10 MB archive to more than 500 MB folder, I should suspect malicious inflation.
Note that the initial malware of this class is only between 2-4MB. Once run it will create a hidden system directory where the actual stealer will be dropped. Once there it will expand itself by adding nonsense code to itself thereby expanding to well over 700MB. This is their evasion tactic as some (K) AV's have limits on the file size they scan, while others (N) do not.

Like in the video title, a Fun Fact.
 
Note that the initial malware of this class is only between 2-4MB. Once run it will create a hidden system directory where the actual stealer will be dropped
In such a case, the real-time AV is defective; the initial malware is not inflated to be outside the size limit, and even if not includede in its signatures, its behavioral analysis did not flage its malicious start of payload.
So, in such a scenario, it is not the matter of size.
 
Once run it will create a hidden system directory
Not very hidden usually, not to say that when you open AppData/Roaming, it literally pokes your eyes out.

Anyway, the tactics and techniques vary from group to group, and from variant to variant.
In such a case, the real-time AV is defective; the initial malware is not inflated to be outside the size limit, and even if not includede in its signatures, its behavioral analysis did not flage its malicious start of payload.
So, in such a scenario, it is not the matter of size.
There are many different families using inflation. For example PrivateLoader (which is the one that causes an explosion of 50 malicious connections as soon as it executes) is just a stage1 loader. It decrypts the payloads in memory (some variants) however there must be a persistence artefact. Smash and Grab is not that common.

Other notable variants that have resorted to inflation are Epoch, True Bot, Trick Bot, Origin, Black Basta.
Notable APTs are Cozy Bear and a few others.

Majority of the inflated malware also attempts to create Defender exclusions, often as broad as the whole C drive.

Only then additional payloads and persistence will be created, at this stage Defender won’t detect them.

Most of the inflated malware also comes with UAC bypasses which facilitate the creation of exclusions as well as the efficient operation of the malicious payloads.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top