Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #16  
Old 02-12-2005, 20:12
spikecura
 
Posts: n/a
I think NAV's "Bloodhound Heuistics" system is pretty nice... Havent seen a heusitic system of virus detection for virsues without signatures in any other software.
Reply With Quote
  #17  
Old 02-12-2005, 20:38
D-Jester's Avatar
D-Jester D-Jester is offline
VIP
 
Join Date: Nov 2003
Location: Ohio, USA
Posts: 269
Rept. Given: 39
Rept. Rcvd 61 Times in 41 Posts
Thanks Given: 0
Thanks Rcvd at 4 Times in 4 Posts
D-Jester Reputation: 61
I have to recommend ZoneAlarm Security Suite, Great detection, easy setup, easy to configure firewall, doesn't hinder performance (Which is why I switched from Norton) and it integrates well with XP SP2.

Give it a try!
__________________
Even as darkness envelops and consumes us, wrapping around our personal worlds like the hand that grips around our necks and suffocates us, we must realize that life really is beautiful and the shadows of despair will scurry away like the fleeting roaches before the light.
Reply With Quote
  #18  
Old 02-12-2005, 21:22
MaRKuS-DJM's Avatar
MaRKuS-DJM MaRKuS-DJM is offline
Cracker + Unpacker
 
Join Date: Aug 2003
Location: Virtual World / Network
Posts: 553
Rept. Given: 7
Rept. Rcvd 6 Times in 4 Posts
Thanks Given: 3
Thanks Rcvd at 16 Times in 10 Posts
MaRKuS-DJM Reputation: 6
don't use AV too, tired of updating this shit all the time, i use a computer for work, not for updating AV. signatures are too late for actual virus, modification so AV won't catch it is easy. they also catch cracks and inline-patches as virus, exactly as executed code inside PE Header, slow down every copy process so it takes at least 3x the time it would take without AV.
all i trust is my debugger. conclusion: AV doesn't protect you (as you see in Symantec UPX fault)
Reply With Quote
  #19  
Old 02-12-2005, 22:10
elephant elephant is offline
Friend
 
Join Date: Feb 2005
Posts: 94
Rept. Given: 2
Rept. Rcvd 29 Times in 15 Posts
Thanks Given: 132
Thanks Rcvd at 127 Times in 41 Posts
elephant Reputation: 29
I totally agree with you Markus. I follow your steps and also use sometimes virustotal service with suspicious files. It is great to be able to scan with multiple engines without messy or slowing down my system.
Reply With Quote
  #20  
Old 02-13-2005, 05:13
freddy2002
 
Posts: n/a
No AntiVirus Scan Engine protect if:
EXE is packed
( if packer is known change OEP & create new starting bytes )

Only rare real Memory Scan&Protect Engines will work
(you have to start the Victim (risky)
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



All times are GMT +8. The time now is 18:49.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )