ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
Memory Scan Question
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
When ClamWin performs a memory scan, does it actually scan the segments of RAM or does it cache the data to a temp file(s) on disk and then scan the file(s)?

Regards,
View user's profileSend private message
Wild~Fire


Joined: 03 Nov 2007
Posts: 0
Reply with quote
You could probably find out if you used Filemon? It would be a waste of disk IO if it did write to disk first. I wasn't aware of an option to scan memory but there is an option to unload infected programs from memory so it must scan memory one of two ways.
View user's profileSend private message
alch
Site Admin

Joined: 27 Nov 2005
Posts: 0
Reply with quote
Memory scan gets a exe and dll filename and scans the actual file.
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
Could similar code be used to scan a http/Javascript/whatever stream coming into the browser from the Web--to spot exploits, when a real-time scanner becomes available?

Regards,
View user's profileSend private message
Wild~Fire


Joined: 03 Nov 2007
Posts: 0
Reply with quote
GuitarBob, I think that you're heading into the territory of 'exploits' now rather than AV. I don't think that it's the AVs job to catch these things although some do. Anyways I use a HIPS with CW just to supplement the fact that there are exploits that AV don't catch.
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
You could be right, but I see that Clam has a few signatures for exploits and "bad" HTML. At one time AVs didn't bother with ad/spyware, but most of them have expanded their definition of "malware" to include the more malevolent kind now. We're probably going to see more malware move away from overt files--perhaps even browser-based rootkits. A browser scanning service would give ClamWin some very good functionality that is separate from Clam AV.

Regards,
View user's profileSend private message
sherpya


Joined: 22 Mar 2006
Posts: 0
Location: Italy
Reply with quote
there are already signature for html files, but I don't known what they are targeting
View user's profileSend private message
Memory Scan Question
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic