Jump to content

Malwarebytes

Quick question...


12 replies to this topic

#1
swagger

    Elite Member

  • Honorary Members
  • PipPipPipPipPip
  • 887 posts
  • Gender:Male
  • Location:South Carolina
Someone help me out, what is the term when one scanner hijacks another scanner's detection when scanning files? For the life of me, I cannot think of the term used. I believe exile once told me about it.

Thanks in advance
Desktop ----- AMD Athlon 3700+ (2.64Ghz), 2GB DDR 400, ASUS A8N-SLI Premium, 500GB HD, Windows XP Pro SP3, Avira Antivir Personal, MBAM Pro
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal

#2
srtools1980y

    Elite Member

  • Honorary Members
  • PipPipPipPipPip
  • 816 posts
Why can't you pm exile?

#3
yardbird

    Forum Deity

  • Honorary Members
  • PipPipPipPipPipPip
  • 3,726 posts
  • Gender:Male
  • Location:Sedona. Arizona, USA
  • Interests:Where we keep the World Safe
@ swagger

great!!!!! now I forgot also :) :)
Posted Image
No trees were harmed in the posting of this message...however an extraordinarily large number of electrons were horribly inconvenienced.
http://www.tentrexindustries.com/

#4
sho-dan

    कैंसर योद्धा

  • Honorary Members
  • PipPipPipPipPipPip
  • 3,023 posts
  • Gender:Not Telling
  • Location:Jah Jersey Shore
.
"Don't worry about a thing,
'Cause every little thing gonna be all right!"

#5
swagger

    Elite Member

  • Honorary Members
  • PipPipPipPipPip
  • 887 posts
  • Gender:Male
  • Location:South Carolina

View Postsrtools1980y, on Sep 23 2009, 03:18 PM, said:

Why can't you pm exile?

Because I'm not certain it was him and it would be educational for all to know the term.

View Postyardbird, on Sep 23 2009, 03:38 PM, said:

@ swagger

great!!!!! now I forgot also :) :blink:


Haha, sorry! Hopefully someone will remember
Desktop ----- AMD Athlon 3700+ (2.64Ghz), 2GB DDR 400, ASUS A8N-SLI Premium, 500GB HD, Windows XP Pro SP3, Avira Antivir Personal, MBAM Pro
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal

#6
Marcus

    Elite Member

  • Honorary Members
  • PipPipPipPipPip
  • 592 posts
  • Gender:Male
  • Location:London, UK

View Postswagger, on Sep 23 2009, 09:48 PM, said:

Because I'm not certain it was him and it would be educational for all to know the term.




Haha, sorry! Hopefully someone will remember

swagger, you don't mean a more general term like "piggybacking" or a short phrase which includes that word, like "piggyjackbacking" :blink: do you?

PS. I've just invented that last term!

#7
swagger

    Elite Member

  • Honorary Members
  • PipPipPipPipPip
  • 887 posts
  • Gender:Male
  • Location:South Carolina
I think it was more technical... but it was definitely access hijacking. When one scanner accesses/scans the file, the other hijacks the scan and detects the file
Desktop ----- AMD Athlon 3700+ (2.64Ghz), 2GB DDR 400, ASUS A8N-SLI Premium, 500GB HD, Windows XP Pro SP3, Avira Antivir Personal, MBAM Pro
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal

#8
exile360

    exile

  • Moderators
  • PipPipPipPipPipPip
  • 12,959 posts
  • Gender:Male
I've referred to an AV having a file locked in memory before. That could be it. It's sort of like the ultimate "Access Denied" approach used by AV's when a detection is made to stop the nasty from escaping while it's taking action or waiting for the user to tell the AV what to do with the detection (ie Ignore, Quarantine, Delete etc).
Samuel E Lindsey
Product Manager

Posted Image

Follow us: Twitter, Become a fan: Facebook

#9
swagger

    Elite Member

  • Honorary Members
  • PipPipPipPipPip
  • 887 posts
  • Gender:Male
  • Location:South Carolina
Nope that's not it... Maybe I'm explaining it wrong... I thought I was pretty clear though. One scanner is scanning with one active protection scanner in the background... The scanner that is scanning accesses the files and as it does, the active protection scanner detects those files when it wouldnt have before.
Desktop ----- AMD Athlon 3700+ (2.64Ghz), 2GB DDR 400, ASUS A8N-SLI Premium, 500GB HD, Windows XP Pro SP3, Avira Antivir Personal, MBAM Pro
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal

#10
exile360

    exile

  • Moderators
  • PipPipPipPipPipPip
  • 12,959 posts
  • Gender:Male
Ah, the way that my MBAM does when Kaspersky scans something because it executes any files it checks in realtime inside an emulator. Yes, I remember now, but can't for the life of me recall the terminology I used :) .
Samuel E Lindsey
Product Manager

Posted Image

Follow us: Twitter, Become a fan: Facebook

#11
yardbird

    Forum Deity

  • Honorary Members
  • PipPipPipPipPipPip
  • 3,726 posts
  • Gender:Male
  • Location:Sedona. Arizona, USA
  • Interests:Where we keep the World Safe
I'm trying to google what swagger posted & I can't find it??? :)
Posted Image
No trees were harmed in the posting of this message...however an extraordinarily large number of electrons were horribly inconvenienced.
http://www.tentrexindustries.com/

#12
swagger

    Elite Member

  • Honorary Members
  • PipPipPipPipPip
  • 887 posts
  • Gender:Male
  • Location:South Carolina
Haha strange... But it was you exile who used the term. I thought so. I believe it was via PM but I can't be sure. It was early this year and my memory isn't the greatest these days. Well if anyone thinks of it, please let me know!
Desktop ----- AMD Athlon 3700+ (2.64Ghz), 2GB DDR 400, ASUS A8N-SLI Premium, 500GB HD, Windows XP Pro SP3, Avira Antivir Personal, MBAM Pro
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal

#13
Marcus

    Elite Member

  • Honorary Members
  • PipPipPipPipPip
  • 592 posts
  • Gender:Male
  • Location:London, UK

View Postswagger, on Sep 24 2009, 01:12 PM, said:

Haha strange... But it was you exile who used the term. I thought so. I believe it was via PM but I can't be sure. It was early this year and my memory isn't the greatest these days. Well if anyone thinks of it, please let me know!

...Let's see if I can help... it's called "co-operation" if you're on one side of the fence or "nicking the enemy's info" (otherwise known as "dancing with the enemy") if you're on the the other side.

For all you current or former college lecturer-types think "byte-plagiarism".

At this point hot, strong filter coffee is needed to sort out a decaffeinated brain - and then I might talk some sense later. :)





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us