Endless Paradigm

Full Version: Test Your Anti
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Pages: 1 2 3 4
ESET got it as soon as I saved it.
Any *good* AV app shouldn't be relying on instances of certain strings to be present >_>
Is there any actual anti that does that?
ZiNgA BuRgA Wrote:Any *good* AV app shouldn't be relying on instances of certain strings to be present >_>

If they don't detect viruses based on their coding, how will they find them?
Am not sure.  But an ASCII printable string certainly should not be used to judge whether a virus is one or not.  At the very least, it should base judgements on binary strings.  I would say that hashing is perhaps more reliable.
Though I've never trusted AV anyway, since it's extremely easy to bypass.  With the above example, if that string really is what it looks for, simply changing it gets this "virus" past your AV.
ZiNgA BuRgA Wrote:Am not sure.  But an ASCII printable string certainly should not be used to judge whether a virus is one or not.  At the very least, it should base judgements on binary strings.  I would say that hashing is perhaps more reliable.
Though I've never trusted AV anyway, since it's extremely easy to bypass.  With the above example, if that string really is what it looks for, simply changing it gets this "virus" past your AV.

yeah i changed it and it was undetected. i changed "eicar" to frogg and it didnt pic it up.
Pages: 1 2 3 4
Reference URL's