DragonMaster Jay

Honorary Members
  • Content count

  • Joined

  • Last visited

About DragonMaster Jay

  • Rank
    True Member
  • Birthday 04/08/1989
  1. You are most welcome! :) I hope it was great!

  2. Happy Belated Birthday!

  3. Last name Ever...first name Greatest!

  4. Sad to hear indeed. He worked on my site a bit, and I will say that he was a very hard worker. Hope you all get through this.
  5. The new CIS is a good one. Beat Kaspersky in Internet Security tests.
  6. 1 word: Comodo.
  7. It can not be classified as "rogue" because... 1. There is no unsolicited intrusion/penetration into the system 2. There is no explicit enforcement/offering to buy a higher/pro version of the same program. 3. Detection of the mentioned program is based on behavior (such as registry changes) 4. Can not find any illegitimate advertisements/offers in program.
  8. You seem to misunderstand the importance of this file, and what could happen if you change the internal assembly to a write code. If you add write features to this sample virus code, it will not be pretty to your OS. The fact that you can do an Assembly code analysis, as I did above, proves that the researchers whom designed it, were specifically aiming for what real virus code would look like. If you do an analysis (if you know Assembly code) of this file, you will realize it has all that is needed to implement a real virus. It contains an instruction pointer, a stack pointer, a data string, DOS function, and two places where it changes its bytes to make it polymorphic. One of the worst type of viruses we deal with is polymorphic viruses. EICAR test file is still a good example virus and should still be used.
  9. I've been told the reason AVs will detect it is for normal users to test the responsiveness of their real-time protection. Also, you can stick it in a zip folder or similar format, and see if the antivirus will still detect it, no matter if it is in a compressed file or not. Dumped EICAR test file in debugger:
  10. Hmm.. Can someone else try, or can TM be disabled temporarily. That is expected behavior, it is supposed to freeze before it can be saved.