App Review Scriptor Infection Who You Gonna Call?

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Seems they [computer security companies] ever forget that scripts are the first part of evolvement for creation of viruses throughout history; which is simple to construct and hold already massive destruction.

However due to the trends on IT security issue then plans are change.
 

cruelsister

Level 43
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,224
T- Wow! I haven't thought of Agent.btz for quite a while; back then it was known as the Silly worm.

This was, of course, a Scriptor; but instead of Buckshotting different malware to various places in the system this one replicated itself to something like 8-10 different directories while hiding itself. And just like what occurred in this video you could delete all but one and on reboot it would populate itself right back (if memory serves it also renamed the worm core and put it in different directories). It also scanned all drives from A:\ to Z:\. They were reduced to reimaging something like a billion hard drives one by one until the Girls from the TAO came to the rescue.

As for other products, I'm not a fan of the traditional AV product at all. Other products like AppGuard and Sandboxie (favorites of Umbra) are effective but as you point out do require a firm hand in order use properly. Comodo is my favorite as it can be set up so that both experienced and novice users can use it with equal effectiveness.

ps- Your mom has VERY good taste! I like her.

M
 
  • Like
Reactions: done and Tony Cole

Tony Cole

Level 27
Verified
May 11, 2014
1,639
Thank you cruelsister I've learnt a great deal from your posts and video's, you could easily be a teacher - nice to have the advanced info, but easy to understand.

Yes, my mum a x 3 pairs of Jimmy Choo, they are lovely shoe's.

Tony :)
 
  • Like
Reactions: done

Solarquest

Moderator
Verified
Staff Member
Malware Hunter
Well-known
Jul 22, 2014
2,525
How to stop\defend against scriptors ? = Don't install the interpreter and use an anti-executable (e.g. NVT ERP).

You can use Comodo products - which will sandbox Unrecognized script files, but be forwarned that there are scripts that can "reach outside" the sandbox and make permanent changes to the system - like deleting files (I just submitted one to Comodo Engineering).

Of course, you can set the Comodo sandbox to Block any Unrecognized file - and that will include scripts.

Unless you are an indiscriminate downloader\installer I wouldn't worry about it too much. Plus, you won't be installing Python, perl, AutoIT interpreters and running those type scripts, so the issue really is moot.

You are much more likely to experience a drive-by download of the javascript (.js) variety than anything else - which Comodo will handle either with via the sandbox or HIPS (I use HIPS - but it causes novices more mistakes than anything else since rule creation is not clear in some CIS HIPS alerts).

Comodo does much better at protecting against scriptors than all other suites I have tested. The user can just go with the default sandbox settings = Fully Virtualized or for maximum security set it to Block (all Unrecognized files).

Comodo isn't absolutely perfect, but then, nothing IT ever is... it's got you covered in the vast majority of scriptor cases.

Anti-executable configuration settings are included in CIS because that is an option for the user - as part of the Comodo default-deny protection model.

I can tell you from a lot of testing that it really does work.

Hello Hjlbx,
Did the sample you submittet to Comodo always escape from sandbox or only in some security levels?
Did it also escape from sandboxie? and VM?
Thank you!!!
 
  • Like
Reactions: done

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top