![]() |
| Memory Scan Question |
|
Wild~Fire
|
You could probably find out if you used Filemon? It would be a waste of disk IO if it did write to disk first. I wasn't aware of an option to scan memory but there is an option to unload infected programs from memory so it must scan memory one of two ways.
|
||||||||||||
|
|
|||||||||||||
|
alch
Site Admin
|
Memory scan gets a exe and dll filename and scans the actual file.
|
||||||||||||
|
|
|||||||||||||
|
GuitarBob
|
Could similar code be used to scan a http/Javascript/whatever stream coming into the browser from the Web--to spot exploits, when a real-time scanner becomes available?
Regards, |
||||||||||||
|
|
|||||||||||||
|
Wild~Fire
|
GuitarBob, I think that you're heading into the territory of 'exploits' now rather than AV. I don't think that it's the AVs job to catch these things although some do. Anyways I use a HIPS with CW just to supplement the fact that there are exploits that AV don't catch.
|
||||||||||||
|
|
|||||||||||||
|
GuitarBob
|
You could be right, but I see that Clam has a few signatures for exploits and "bad" HTML. At one time AVs didn't bother with ad/spyware, but most of them have expanded their definition of "malware" to include the more malevolent kind now. We're probably going to see more malware move away from overt files--perhaps even browser-based rootkits. A browser scanning service would give ClamWin some very good functionality that is separate from Clam AV.
Regards, |
||||||||||||
|
|
|||||||||||||
|
sherpya
|
there are already signature for html files, but I don't known what they are targeting
|
||||||||||||
|
|
|||||||||||||
| Memory Scan Question |
|
||
|
Powered by phpBB © phpBB Group
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.


