Anti-malware Technique Evaluator (ATE) - Pwning AVs

No ratings

Presented at ZaCon4 2012 by

"The talk will consist of a live demonstration of some of the functionality of two rootkits that we have implemented which can collectively disable anti-malware software on a computer, log keys pressed, hide files and lastly force a bug check and disable the OS recoverability options in order to prevent the OS from booting. The two rootkits implemented form part of an evaluation framework named ATE (Anti-malware Technique Evaluator) that can be used to evaluate current anti-malware techniques. The rootkits themselves were demonstrated at last year's ZaCon and such will not be the focus of the presentation. The focus of the presentation will be to discuss the results attained from evaluating 9 commercial anti-malware products, namely: Avira Free Antivirus, avast! Internet Security 6, ESET Smart Security 5, AVG Anti-Virus Free Edition 2012, McAfee AntiVirus Plus, Microsoft Security Essentials, Ad-Aware Free Internet Security, Kaspersky Anti-Virus 2012 and Norton AntiVirus 2012."