ComputerForum.com ComputerForum.com  
TigerDirect
 
Go Back   Computer Forum > Computer Software > General Software

Reply
 
LinkBack Thread Tools Display Modes
Old 03-25-2005, 09:39 AM   #1 (permalink)
Gold Member
 
Sebouh's Avatar
 
Join Date: Sep 2004
Posts: 477
Default How to know if a file is a virus...

I was just imagining if i were to build an antivirus software, what do i make my software search for in the file to see if it is infected or its a virus. The same implies for an anti spy/adware/trojan softwares.
thanks.
__________________
sbho
Sebouh is offline   Reply With Quote


Old 03-25-2005, 01:19 PM   #2 (permalink)
Administrator
 
Praetor's Avatar
 
Join Date: Jul 2004
Location: Canada
Age: 25
Posts: 19,954
Default

You could have a look at the microops it calls
__________________
ASUS P5K Premium WiFi-AP, Q6600@3.7 / ASUS P5ND, E6400@3.8
4GB OCz Platinum XTC 8500 / 4GB CorsairXMS2 6400
5x500GB Seagate 7200.10 / 2x500 Seagate 7200.10
OCz 8800GTX 768MB @ 630/800 / 2x Galaxy 8800GT SLI
Praetor is offline   Reply With Quote
Old 03-25-2005, 01:30 PM   #3 (permalink)
Platinum Member
 
OS Dragon's Avatar
 
Join Date: Dec 2004
Location: Manchester
Posts: 732
Default

Well, its a complex question because there are many different type of virues: -
  • Common Viruses
  • Program Viruses
  • Boot Viruses
  • Stealth Viruses
  • Polymorphic Viruses
  • Multipartite Viruses
  • Macro Viruses
  • Windows Viruses
  • Malicious Program
And so on and so forth, I'm guessing that the antivirus (program) looks (or checks) at the algorithms in each program file to make sure its not malicious nor is it and algorithm that results in the deletion of a valuable program file. When viruses are applied to images, this is a whole new stage for me.
__________________
Just Google it... Knowledge Is Power
OS Dragon is offline   Reply With Quote
Old 03-25-2005, 03:36 PM   #4 (permalink)
Moderator - F@H Guru
 
jancz3rt's Avatar
 
Join Date: Sep 2004
Location: Czech Republic
Age: 23
Posts: 4,009
Default Yeah indeed

It check for certain patterns and algorithms within files and when infected recognizes them. This is why new variants come up often as they fool the antivirus....unless it already has teh virus definition files...into believing that teh files are safe when they are in fact not. They also search for specific .exe files etc...and check for running processes or the memory. It's very hard to answer the question but i hope I have elaborated on teh bove post.

JAN
__________________
A64 3700+ @ 2.65Ghz ::: 7300GT @ 600/1500 ::: 2GB RAM @ 440Mhz

www.CZ3RT.com ::: FOLDING FOR THE GOOD OF MANKIND ::: F@H Team 44358
jancz3rt is offline   Reply With Quote
Old 03-26-2005, 07:31 AM   #5 (permalink)
Gold Member
 
Sebouh's Avatar
 
Join Date: Sep 2004
Posts: 477
Default

so is it impossible for a one person to create an antivirus, or would it take a year to finish?
__________________
sbho
Sebouh is offline   Reply With Quote


Old 03-26-2005, 07:05 PM   #6 (permalink)
Moderator - F@H Guru
 
jancz3rt's Avatar
 
Join Date: Sep 2004
Location: Czech Republic
Age: 23
Posts: 4,009
Default Lol

Quote:
Originally Posted by Sebouh
so is it impossible for a one person to create an antivirus, or would it take a year to finish?
Unless you are extremely skilled, I would advise you to give up. Most antivirus programs that made it somewhere in today's world are made by teams of programmers, designers etc. So ..... prolly not possible.

JAN
__________________
A64 3700+ @ 2.65Ghz ::: 7300GT @ 600/1500 ::: 2GB RAM @ 440Mhz

www.CZ3RT.com ::: FOLDING FOR THE GOOD OF MANKIND ::: F@H Team 44358
jancz3rt is offline   Reply With Quote
Old 03-26-2005, 08:41 PM   #7 (permalink)
VIP Member
 
Lorand's Avatar
 
Join Date: Dec 2003
Location: Bucharest
Age: 41
Posts: 3,042
Default

This task was so easy in the good old days: write a program that makes a database of all the executables (exe, bat, pif, dll, etc.) with their name and size (or CRC) when the system is clean, then periodically verify them -- an infected file could have different size and surely different CRC. If you add a boot-sector check too then you'll have a bulletproof antivirus for all the viruses that are older than a decade.
But today's viruses are much cleverly written and you could identify them only by they signature. So even if you manage to write an antivirus program, updating it's signature database would be a full-time job...
Lorand is offline   Reply With Quote
Old 03-27-2005, 11:06 AM   #8 (permalink)
Gold Member
 
Sebouh's Avatar
 
Join Date: Sep 2004
Posts: 477
Default

well how about an anitspyware or adware progs, i know that spybot is written by one guy, am i wrong??
__________________
sbho
Sebouh is offline   Reply With Quote
Old 03-27-2005, 11:22 AM   #9 (permalink)
Platinum Member
 
OS Dragon's Avatar
 
Join Date: Dec 2004
Location: Manchester
Posts: 732
Default

He must reeally know his programming if it was one guy but I don't think that one person could make such a solid program without the help of any outside sources
__________________
Just Google it... Knowledge Is Power
OS Dragon is offline   Reply With Quote
Old 03-27-2005, 12:10 PM   #10 (permalink)
VIP Member
 
Lorand's Avatar
 
Join Date: Dec 2003
Location: Bucharest
Age: 41
Posts: 3,042
Default

Quote:
Originally Posted by Sebouh
well how about an anitspyware or adware progs, i know that spybot is written by one guy, am i wrong??
Did you read the Spybot's credits page?
Lorand is offline   Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 03:58 PM.


Powered by: vBulletin Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 ©2008, Crawlability, Inc.
Copyright © 2002-2008 Computer Forum and Web Design Forum