Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
EMILY BLUNTS
Jan 1, 2005

Another tool like GMER is IceSword. It's done by a chinese programmer, but an english version is available. It looks crappy but does an okay job, sometimes some things can hide from gmer but not this, for example

Adbot
ADBOT LOVES YOU

EMILY BLUNTS
Jan 1, 2005

combofix is actually dozens of little utilities... some of them probably have to do some pretty crazy stuff to get at rootkits, and it's possible AV heuristics think you've got evil hacking tools.

EMILY BLUNTS
Jan 1, 2005

Here's how good trojans/viruses work:

Update your code and install base faster than antivirus companies can.

So yes, it's dangerous AND they're better at detecting it AND it's getting better at not getting detected. :)

EMILY BLUNTS
Jan 1, 2005

Orange Juilius posted:

HIPS prevents this from being a problem.


It's still within the realm of possibility to find an exploit in these systems as well, but if you find that's happening, chances are someone's out for you, as the average credit card harvester/botnet operator isn't going to waste time on the tiny segment of computers using them.

EMILY BLUNTS
Jan 1, 2005

CWSandbox is pretty good too, but that tells a different story, and if your funny file knows its in a VM it's going to just bail on you.

Adbot
ADBOT LOVES YOU

EMILY BLUNTS
Jan 1, 2005

You know how in the fine print household cleaners say you need to soak it on the surface for 30 seconds to really kill bacteria? Well, if you haven't done a 3-pass wipe it's possible that your computer could become breeding ground for format-resistant superviruses!

  • Locked thread