Author Topic: Why use extra non-resident scanners?  (Read 2636 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Why use extra non-resident scanners?
« on: December 25, 2005, 02:20:18 PM »
Hi forum folks,

It is relatively easy to transform a widely spread trojan into a "stealth" one, that cannot be detected by an AV scanner. This is no "underground secret" anymore. Look here for the explanation, why this is so: http://home.arcor.de/scheinsicherheit/example.htm So note your scanners weaknesses. Use one resident scanner only, but use additional non-resident scanners, even when a software developer tells you otherwise. I use Avast + ClamWin + Bitdefender on-line scan + DrWebCureit + DrWeb pre-hyperlink scanner plug-in + stinger.exe. In case of doubt I update a suspicious file to either Jotti or Virustotal.

greets,

polonus

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: Why use extra non-resident scanners?
« Reply #1 on: December 25, 2005, 02:54:22 PM »
Very interesting reading or should that be disturbing reading.

I think this note is very relevant.
Quote
Note: Usually, only AV/AT scanners that feature an unpacking engine or a similar efficient technology can reliably detect compressed or crypted trojans.

I believe that avast has one of the better supported list of unpackers?

Whilst I'm unsure how we get around encrypted viruses, but an encrypted virus has to also have something to decrypt it and in its decrypted form in memory or otherwise, perhaps it can be detected.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

TAP

  • Guest
Re: Why use extra non-resident scanners?
« Reply #2 on: December 25, 2005, 02:59:34 PM »
I've used ewido anti-malware along side with avast! and this combo scanner gives me a very good result, ewido has found some malware (especially from P2P and underground site) that avast! missed from time to time and I've sent them to Alwil lab.


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Why use extra non-resident scanners?
« Reply #3 on: December 25, 2005, 06:42:56 PM »
Hi DavidR and Tap,

At the start of this thread : http://forum.kaspersky.com/index.php?showtopic=3349 you can read why advanced mem scanning should come to AV scanners as soon as possible. Here is additional information to better understand the backgrounds: http://www.securityfocus.com/infocus/1637

polonus
« Last Edit: December 25, 2005, 06:46:38 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!