View Single Post
  #3  
Old 06-09-2011, 11:33
EMPiRE EMPiRE is offline
Administrator
 
Join Date: Feb 2002
Posts: 1,356
Thanks: 8
Thanked 157 Times in 108 Posts
EMPiRE is on a distinguished road
I understand that it is hard to check a packed file which they cannot decrypt but that is a bit too easy!

AV software should be more intelligent, if they encounter a packed file it should execute it inside its own sandbox and then check the results. It will be hard to make this foolproof but it is possible.