View Single Post
  #2  
Old 17-09-2008, 08:48
TippeX's Avatar
TippeX TippeX is offline
zeroes and ones.....
 
Join Date: Jan 2003
Posts: 3,842
Thanks: 2
Thanked 33 Times in 23 Posts
TippeX is on a distinguished road
Quote:
Originally Posted by Nihilanth View Post
@All
Are virus programs able to detect virii even if you haven't, for say,
executed a EXE?(The virus hasn't been activated/initialized)
the online ones are, virustotal definately does, when i was trying to 'fix' the nod32 issue i used their site lots, patching the exe, uploading, changing code, compiling, uploading .. about 80 times, then i tracked down the exact block of code that caused the false positive...
i then encrypted the procedure so it wasn't 'visible' (not even the api names were visible), yet nod32 through virustotal still saw the code.. so it has to be executing it... from this i was also able to determine that the server they are running on is 64bit

so, for overall ease, i'd really recommend using virustotal.com to do the scanning as it covers a lot of antiviruses and seems to be pretty decent.. and free which is rare these days (and nope, im not affiliated with them in any shape or form... nor do i really consider this advertising)
__________________
bleh
DO NOT PM me with questions, leave that in the forums...ESPECIALLY if i dont know you...
Reply With Quote