Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security FullDisclosure
[Top] [All Lists]

Re: [Full-disclosure] Is this a Virus?

Subject: Re: [Full-disclosure] Is this a Virus?
Date: Sat, 31 Dec 2005 11:13:28 -0500
On 12/29/05, Shawn Cox <shawn.cox@pcca.com> wrote:

I doubt it's a virus.  Filling up a hard-disk is counter productive to
propagation.  Though I do think it was an option in the VCL of old.


Hi:

Well if the virus releases the space before infection, can be productive to
the propagation since it would reserve that space you won't be able to fill
with other data ;).

Generally is easy to detect a virus. Feed your computer with a couple of
fresh executables, and some will go out modified with high probability and
most times with the size increased. Warning there are slow viruses that
takes it's time to reproduce, and usually last years before somebody even
notices. However this is not very usual, generally viruses eat whaetever you
give them except some with bait detection. Most check baits for the size,
and some do more advanced thingies like analize the file for knows routines
in High level laguages or variations in the instructions. If interested I
have a lot of literature around and a huge 5000+ virus collection build over
the years. Some are still on schedule for reversing but if anyone is
interested just gime a call it would be great to save myself some time.

Regards
Waldo Alvarez
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
<Prev in Thread] Current Thread [Next in Thread>