Logo

CS.RIN.RU - Steam Underground Community

IRC: #cs.rin.ru at irc.rizon.net
It is currently Friday, 17 Apr 2015, 14:21

English | Русский




Post new topic Reply to topic  [ 9 posts ] 
Author Message

Post Post subject: Understanding AntiVirus   
Posted: Monday, 07 Feb 2005, 02:11   
Advanced forumer Завсегдатай
Joined: Saturday, 08 May 2004, 10:50
Posts: 105
Location: Terra de Deus, Patria e Famila: Portugal
I see here many people saying that some hoax about ticket fix that is nothing more than a virus is clean because their AntiVirus said nothing. Well, it's time to explain a little "How AntiVirus Works" and "Why are those files "clean"":

Normally, when checking a file, AntiVirus use their virus hash database to find if the file is clean or not. As so, when you scan a brand new virus it will tell you nothing, once it's still an unknown virus. To it become a virus to your AV, you have to send the file to your AntiVirus maker, so he can make an update and insert that virus in to database.

Heuristic scans:

Mostly of AV nowadays have Heuristic scan. Heuristic is kind of scan by behavior instead of database. However it will never say to you that the file is a Virus, instead it says that the file "May behave like a virus". This isn't a way to get a 100% answer, once some files may match a virus pattern and not be a virus or some new virus may not match any virus pattern.

So, what should we do?

Well, in this forum there're some people that can disasm and understand files. Among them you can find me, d4rkm4nx, hCUPa, MaddoxX, etc. If you see a new "ticket fix" here, don't execute it before any of trustable people says if it is or not safe to do so.

To do if you don't want to wait:

As most common behavior of virus you can also open the EXE file with your notepad and check for those text inside:

RegCreateKeyA, ShellExecuteA, RegSetValueA, CreateFileA, \\software\\microsoft\\

if you find any of those texts you rather wait then get infected.

Keep it sharp, keep it clean. And remember some people is here to help you, some don't.

_________________
My projects status: Resumed.
BTW: Visual Studio 2005 SUCKS


Top
 Profile  

Post Post subject:    
Posted: Monday, 07 Feb 2005, 02:17   
User Редкий гость
Joined: Sunday, 12 Dec 2004, 11:44
Posts: 41
As a computer scientist (senior year), I whole-heartedly agree with your explanation.

It takes the discovery of identifiable code or similar replication behavior in order to diagnose a virus.

After all, hasn't everybody sat back and played around with the idea of creating bit-based virii for fontsets by changing non-vital bits... I mean, creating path-based errata from the inner-workings of computer data? Even in-so-far as creating false-binary from RAM and known processor exploits in order to begin insertion of similarly-created code? It probably takes an autistic person to get at what i'm talking about.

I would suggest using a decompiler for these trojans, however most people reading may find it difficult.

Otherwise, does VS.2005 really sux, still!? Damn! I was just about to get a copy thru my school's MSDN academic alliance :?


Top
 Profile  

Post Post subject:    
Posted: Monday, 07 Feb 2005, 02:33   
Advanced forumer Завсегдатай
Joined: Saturday, 08 May 2004, 10:50
Posts: 105
Location: Terra de Deus, Patria e Famila: Portugal
VS 2k5 is kind a like Office 2k3. More beautiful, more animations on the menu, but in the core brings nothing new to VS 2k3.

_________________
My projects status: Resumed.
BTW: Visual Studio 2005 SUCKS


Top
 Profile  

Post Post subject:    
Posted: Monday, 07 Feb 2005, 02:35   
User Редкий гость
Joined: Sunday, 12 Dec 2004, 11:44
Posts: 41
honestly, it all went to hell after 6.0 for the rudimentary developers.


Top
 Profile  

Post Post subject:    
Posted: Monday, 07 Feb 2005, 02:38   
Advanced forumer Завсегдатай
Joined: Saturday, 08 May 2004, 10:50
Posts: 105
Location: Terra de Deus, Patria e Famila: Portugal
SigmaXIX wrote:
honestly, it all went to hell after 6.0 for the rudimentary developers.


The .NET Framework is quite unpopular and how can we tell the end-user that to run, sometimes a 40 Kb app, they need to download a seven-head monster with 20 Mb from Microsoft?

_________________
My projects status: Resumed.
BTW: Visual Studio 2005 SUCKS


Top
 Profile  

Post Post subject:    
Posted: Monday, 07 Feb 2005, 03:52   
I live here Три раза сломал клаву :)
Joined: Saturday, 14 Aug 2004, 19:33
Posts: 3130
SO why don't moderators delete topics with viruses???


Top
 Profile  

Post Post subject:    
Posted: Monday, 07 Feb 2005, 04:02   
Advanced forumer Завсегдатай
Joined: Saturday, 08 May 2004, 10:50
Posts: 105
Location: Terra de Deus, Patria e Famila: Portugal
We seam to have a moderator problem here. Are those guys going mad? Keep virus on-topic delete non-virus, moving warnings to off-topic.

:x

_________________
My projects status: Resumed.
BTW: Visual Studio 2005 SUCKS


Top
 Profile  

Post Post subject:    
Posted: Monday, 07 Feb 2005, 04:06   
I live here Три раза сломал клаву :)
Joined: Sunday, 27 Jun 2004, 11:55
Posts: 3280
Location: gwapo ko
DemolitionMan wrote:
SO why don't moderators delete topics with viruses???


DONE! , if i missed some, pls link them to me or znuff

SirArthur wrote:
We seam to have a moderator problem here. Are those guys going mad? Keep virus on-topic delete non-virus, moving warnings to off-topic.

:x


what are you talking about?

Quote:
- Posting new topics which do not relate to the game, better post it in OFFTOPIC SECTION


well if you just post a note that you want this thread to be leave in main forum then i will agree with you..

_________________
Image

http://rev-crew.info/index.php


Top
 Profile  

Post Post subject:    
Posted: Tuesday, 08 Feb 2005, 06:54   
I live here Три раза сломал клаву :)
Joined: Friday, 28 Jan 2005, 04:19
Posts: 2582
Location: Uk, england, london
damn that sigma dude is smart :P


Top
 Profile  
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 9 posts ] 


Who is online

Users browsing this forum: No registered users and 8 guests


Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum




Powered by phpBB® Forum Software © phpBB Group