View unanswered posts | View active topics
|
Page 1 of 1
|
[ 9 posts ] |
|
| Author |
Message |
|
SirArthur
|
Post subject: Understanding AntiVirus Posted: Monday, 07 Feb 2005, 02:11 |
|
| Advanced forumer Завсегдатай |
Joined: Saturday, 08 May 2004, 10:50 Posts: 105 Location: Terra de Deus, Patria e Famila: Portugal
|
|
I see here many people saying that some hoax about ticket fix that is nothing more than a virus is clean because their AntiVirus said nothing. Well, it's time to explain a little "How AntiVirus Works" and "Why are those files "clean"":
Normally, when checking a file, AntiVirus use their virus hash database to find if the file is clean or not. As so, when you scan a brand new virus it will tell you nothing, once it's still an unknown virus. To it become a virus to your AV, you have to send the file to your AntiVirus maker, so he can make an update and insert that virus in to database.
Heuristic scans:
Mostly of AV nowadays have Heuristic scan. Heuristic is kind of scan by behavior instead of database. However it will never say to you that the file is a Virus, instead it says that the file "May behave like a virus". This isn't a way to get a 100% answer, once some files may match a virus pattern and not be a virus or some new virus may not match any virus pattern.
So, what should we do?
Well, in this forum there're some people that can disasm and understand files. Among them you can find me, d4rkm4nx, hCUPa, MaddoxX, etc. If you see a new "ticket fix" here, don't execute it before any of trustable people says if it is or not safe to do so.
To do if you don't want to wait:
As most common behavior of virus you can also open the EXE file with your notepad and check for those text inside:
RegCreateKeyA, ShellExecuteA, RegSetValueA, CreateFileA, \\software\\microsoft\\
if you find any of those texts you rather wait then get infected.
Keep it sharp, keep it clean. And remember some people is here to help you, some don't.
_________________ My projects status: Resumed. BTW: Visual Studio 2005 SUCKS
|
|
| Top |
|
 |
|
SigmaXIX
|
Post subject: Posted: Monday, 07 Feb 2005, 02:17 |
|
Joined: Sunday, 12 Dec 2004, 11:44 Posts: 41
|
As a computer scientist (senior year), I whole-heartedly agree with your explanation.
It takes the discovery of identifiable code or similar replication behavior in order to diagnose a virus.
After all, hasn't everybody sat back and played around with the idea of creating bit-based virii for fontsets by changing non-vital bits... I mean, creating path-based errata from the inner-workings of computer data? Even in-so-far as creating false-binary from RAM and known processor exploits in order to begin insertion of similarly-created code? It probably takes an autistic person to get at what i'm talking about.
I would suggest using a decompiler for these trojans, however most people reading may find it difficult.
Otherwise, does VS.2005 really sux, still!? Damn! I was just about to get a copy thru my school's MSDN academic alliance 
|
|
| Top |
|
 |
|
SirArthur
|
Post subject: Posted: Monday, 07 Feb 2005, 02:33 |
|
| Advanced forumer Завсегдатай |
Joined: Saturday, 08 May 2004, 10:50 Posts: 105 Location: Terra de Deus, Patria e Famila: Portugal
|
|
VS 2k5 is kind a like Office 2k3. More beautiful, more animations on the menu, but in the core brings nothing new to VS 2k3.
_________________ My projects status: Resumed. BTW: Visual Studio 2005 SUCKS
|
|
| Top |
|
 |
|
SigmaXIX
|
Post subject: Posted: Monday, 07 Feb 2005, 02:35 |
|
Joined: Sunday, 12 Dec 2004, 11:44 Posts: 41
|
|
honestly, it all went to hell after 6.0 for the rudimentary developers.
|
|
| Top |
|
 |
|
SirArthur
|
Post subject: Posted: Monday, 07 Feb 2005, 02:38 |
|
| Advanced forumer Завсегдатай |
Joined: Saturday, 08 May 2004, 10:50 Posts: 105 Location: Terra de Deus, Patria e Famila: Portugal
|
SigmaXIX wrote: honestly, it all went to hell after 6.0 for the rudimentary developers.
The .NET Framework is quite unpopular and how can we tell the end-user that to run, sometimes a 40 Kb app, they need to download a seven-head monster with 20 Mb from Microsoft?
_________________ My projects status: Resumed. BTW: Visual Studio 2005 SUCKS
|
|
| Top |
|
 |
|
esx
|
Post subject: Posted: Monday, 07 Feb 2005, 03:52 |
|
| I live here Три раза сломал клаву :) |
Joined: Saturday, 14 Aug 2004, 19:33 Posts: 3130
|
|
SO why don't moderators delete topics with viruses???
|
|
| Top |
|
 |
|
SirArthur
|
Post subject: Posted: Monday, 07 Feb 2005, 04:02 |
|
| Advanced forumer Завсегдатай |
Joined: Saturday, 08 May 2004, 10:50 Posts: 105 Location: Terra de Deus, Patria e Famila: Portugal
|
We seam to have a moderator problem here. Are those guys going mad? Keep virus on-topic delete non-virus, moving warnings to off-topic.

_________________ My projects status: Resumed. BTW: Visual Studio 2005 SUCKS
|
|
| Top |
|
 |
|
ClarencE
|
Post subject: Posted: Monday, 07 Feb 2005, 04:06 |
|
| I live here Три раза сломал клаву :) |
Joined: Sunday, 27 Jun 2004, 11:55 Posts: 3280 Location: gwapo ko
|
DemolitionMan wrote: SO why don't moderators delete topics with viruses??? DONE! , if i missed some, pls link them to me or znuff SirArthur wrote: We seam to have a moderator problem here. Are those guys going mad? Keep virus on-topic delete non-virus, moving warnings to off-topic.  what are you talking about? Quote: - Posting new topics which do not relate to the game, better post it in OFFTOPIC SECTION
well if you just post a note that you want this thread to be leave in main forum then i will agree with you..
|
|
| Top |
|
 |
|
Viper
|
Post subject: Posted: Tuesday, 08 Feb 2005, 06:54 |
|
| I live here Три раза сломал клаву :) |
Joined: Friday, 28 Jan 2005, 04:19 Posts: 2582 Location: Uk, england, london
|
damn that sigma dude is smart 
|
|
| Top |
|
 |
|
Page 1 of 1
|
[ 9 posts ] |
|
Who is online |
Users browsing this forum: No registered users and 4 guests |
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot post attachments in this forum
|
|