Exetools

Exetools (https://forum.exetools.com/index.php)
-   General Discussion (https://forum.exetools.com/forumdisplay.php?f=2)
-   -   Symantec needs to read some tutorials (https://forum.exetools.com/showthread.php?t=6755)

spikecura 02-12-2005 20:12

I think NAV's "Bloodhound Heuistics" system is pretty nice... Havent seen a heusitic system of virus detection for virsues without signatures in any other software.

D-Jester 02-12-2005 20:38

I have to recommend ZoneAlarm Security Suite, Great detection, easy setup, easy to configure firewall, doesn't hinder performance (Which is why I switched from Norton) and it integrates well with XP SP2.

Give it a try!

MaRKuS-DJM 02-12-2005 21:22

don't use AV too, tired of updating this shit all the time, i use a computer for work, not for updating AV. signatures are too late for actual virus, modification so AV won't catch it is easy. they also catch cracks and inline-patches as virus, exactly as executed code inside PE Header, slow down every copy process so it takes at least 3x the time it would take without AV.
all i trust is my debugger. conclusion: AV doesn't protect you (as you see in Symantec UPX fault)

elephant 02-12-2005 22:10

I totally agree with you Markus. I follow your steps and also use sometimes virustotal service with suspicious files. It is great to be able to scan with multiple engines without messy or slowing down my system.

freddy2002 02-13-2005 05:13

No AntiVirus Scan Engine protect if:
EXE is packed
( if packer is known change OEP & create new starting bytes )

Only rare real Memory Scan&Protect Engines will work
(you have to start the Victim (risky)


All times are GMT +8. The time now is 02:01.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2026, vBulletin Solutions, Inc.
Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX