View Single Post
  #3  
Old 06-03-2017, 13:45
tonyweb tonyweb is offline
Family
 
Join Date: Jan 2009
Posts: 190
Rept. Given: 190
Rept. Rcvd 95 Times in 36 Posts
Thanks Given: 1,910
Thanks Rcvd at 299 Times in 122 Posts
tonyweb Reputation: 95
Hello guys,
correct me if/where I am wrong but, as far as I have read, the infection starts only
Quote:
if the user executes programs stored on the pandemic file server.
It seems to me unlikely that one runs an executable directly on a remote share (are there scenarios where this actually happen?), I would copy it to my local machine beforehand and the executable is modified while copying (in order to run the remote program, its bytes must be actually trasferred to the target system's RAM).

In this case, couldn't a so-called antivirus detect the malicious activity as usual?
Maybe the "news" stays in the method itself not quite in the risk

Thanks and Regards,
Tony
__________________
Want to learn unpacking ... but I'm too stupid

Last edited by tonyweb; 06-03-2017 at 19:26.
Reply With Quote