查看: 5146|回复: 23
收起左侧

[分享] BitDefender技术介绍篇 – Active Virus Control(AVC)

[复制链接]
红蛋蛋
发表于 2010-11-23 10:27:58 | 显示全部楼层 |阅读模式
本帖最后由 sniss 于 2011-1-11 13:35 编辑

What it does?
Monitors programs running on your PC as they execute, and then notes any suspicious actions that may or may not denote a malware application. If enough malicious actions are detected, the program which performed them is declared harmful and consequently blocked.

How does it fit in the scanning sequence?
It is the third layer of defense by monitoring the files that were rendered clean by B-Have and the antimalware signature scanner.


评分

参与人数 1经验 +5 收起 理由
鲁路修 + 5 感谢支持,欢迎常来: )

查看全部评分

红蛋蛋
 楼主| 发表于 2010-11-23 10:30:25 | 显示全部楼层
红蛋蛋
 楼主| 发表于 2010-11-23 10:31:45 | 显示全部楼层
(**) Most common process actions considered suspect by Active Virus Control:
§Not waiting for/requesting any type of user interaction

§Not displaying any type of UI when terminating the execution

§Copying or moving files in C:\Windows\ or C:\Windows\Systme32\

§Having as an icon and unrelated types of an icon (e.g. a process that has as an icon a folder icon; social engineering tactics)

§Executing code in other processes’ space (trying to execute code with higher privileges)

§Running files that have been created by themselves with information stored in its binary file.

§Copying its own contents inside a different file on a disk (replicating itself)

§Adding itself in the startup sequence of the Operating System.

§Hiding themselves from typical process enumeration applications.

§Dropping drivers in C:\Windows\System32\ and registering them

Important note:
None of the actions listed above is relevant enough by itself. This is why Active Virus Control keeps a score and monitors the process until a threshold is reached. Identifying only one of this actions, renders that specific process as suspect (to some degree), but not as malicious.


风行黑白
发表于 2010-11-23 10:57:22 | 显示全部楼层
晕……还不翻译啊……[:27:]
鲁路修
发表于 2010-11-23 11:51:52 | 显示全部楼层
本帖最后由 sniss 于 2010-11-23 11:53 编辑

补充一下:execute(罗马尼亚语)则只解释为执行
帅就是帅
发表于 2010-11-23 19:05:43 | 显示全部楼层
sniss 发表于 2010-11-23 11:51
补充一下:execute(罗马尼亚语)则只解释为执行

execute就是英语,ceo的e就是变形executive。。。。。
鲁路修
发表于 2010-11-23 19:08:46 | 显示全部楼层
回复 6楼 帅就是帅 的帖子

我的意思是说execute在罗马语中只翻译成执行,英语里还有其他的意思
帅就是帅
发表于 2010-11-23 19:11:20 | 显示全部楼层
sniss 发表于 2010-11-23 19:08
回复 6楼 帅就是帅 的帖子

我的意思是说execute在罗马语中只翻译成执行,英语里还有其他的意思

英语一般翻译也是执行。。。。就是我还真不知道它是罗马尼亚语。。。反正也差不多,英语大部分来自拉丁语,和罗马尼亚语都是印欧语系,分支不同罢了
鲁路修
发表于 2010-11-23 19:15:03 | 显示全部楼层
回复 8楼 帅就是帅 的帖子

嗯,国外的语言也很复杂,咱们别去管它了。
关键比特梵德的老家在罗马尼亚,所以...
帅就是帅
发表于 2010-11-23 19:17:45 | 显示全部楼层
sniss 发表于 2010-11-23 19:15
回复 8楼 帅就是帅 的帖子

嗯,国外的语言也很复杂,咱们别去管它了。

话说最近被你一搞BD区就火起来了,猫猫该早点给你版主哇。。。。这个月没人测试bd,乃也去呗
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-6-1 22:11 , Processed in 0.118206 second(s), 19 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表