Stefan Schiffert给我的回复:
Unpacking won't solve every problem. Keep in mind you easily can combine several layers of packers so that neither NOD32, KAV, BD, Dr.Web or anyone else can unpack nor emulate them.
脱壳不能解决全部的问题。请记住你可以轻松的进行多层的加壳这样不管nod32,kav,bd,dr.web或其他的软件甚至是有仿真器功能的软件都不可以对他们进行脱壳。(themida就是其中之一)
And what good is being able to unpack some modified variant of a packer, if the emulation takes more than 60 seconds? The scan speed of NOD32 on malware collections with enabled adv. heuristic is horrible, like 100 times slower than AntiVir. Do you think it's really worth to pay this price just to have "nicer" or more exact detection?
如果仿真器用了超过60秒钟的时间来进行脱壳,有什么好处吗?(nod32永远的痛)nod32在开启高启发之后在进行大量病毒扫描的时候速度十分的糟糕,甚至于100倍慢于antivir。你真的认为值得支付这样的代价来取得更“好”或者准确的侦测吗?
Besides, KAV, NOD32, BD and Dr.Web all also started to add packer/crypter based detections, or are already doing so for a long while. Peed.Gen, Packer.Morphine, Packer.Win32.CryptExe, Win32.Pacex.Gen and so on and so on. Heck, tell me any antivirus program which is *not* doing this by now!
顺便说一句,kav,nod32,bs和dr.web都开始在基础侦测中加入报壳,或者已经使用了很久了。peed.gen(bitdefender的),packer.morphine(antivir的),packer.win32.cryptexe(kav的),win32.pacex.gen(nod32的)和其他很多很多。这样吧,请告诉我哪个杀毒软件现在“没有”这样做!
So again, it's good to have lots of unpacking and good emulation but it won't solve all the detection problems. Malware authors still can bypass the detection if they want to and put enough work into it.
所以再次的,拥有大量的脱壳和好的仿真器是很好的,但是并不能解决侦测问题。病毒制造者一样可以免杀,如果他们放入足够的精力来做的话
[ 本帖最后由 mofunzone 于 2007-5-16 15:11 编辑 ] |