Spybot Logo
Go Back   Safer Networking Forums > Blogs
Register ProjectsBlogs FAQ Search Today's Posts Mark Forums Read Home Support Download Donate

The founder of Spybot-S&D blogging about a few things too techy for the news section of Spybot-S&D website. And maybe also about things too unrelated, who knows.
Old

Spybot 2.0: Scripting

Posted 2009-08-14 at 13:00 by PepiMK
Updated 2009-08-25 at 09:11 by PepiMK

The complexity of malware is causing new challenges for anti malware software every day. Randomized malware that has thousands of new variants out calls for loose heuristics, detection patterns need to be slightly adjusted all the time, and new technologies call for new methods of reaction.

The standard approach to store malware detection patterns has been databases for decades. We've been using databases ourselves for the past ten years, with just slight adjustments (like subfunctions,...
PepiMK's Avatar
Member of Team Spybot
Views 1947 Comments 2 PepiMK is offline
Old
Rating: 5 votes, 4.60 average.

Spybot 2.0: cleaning concepts

Posted 2008-12-22 at 00:55 by PepiMK
Tags spybot2

With the rising of rootkits and professional malware, cleaning those away got more and more important and should earn a more prominent position next to scanning.

The cleaning concept in Spybot-S&D 1.x is already doing a lot, like for example trying more than a dozen methods to get rid of files. It's a bit one-dimensional though, and one of its worst disadvantages is the need to do sometimes do a complete rescan on boot to cleanup some files. Cleaning in Spybot 2.0 will therefore...
PepiMK's Avatar
Member of Team Spybot
Posted in Spybot 2.0
Views 7043 Comments 6 PepiMK is offline
Old

Spybot 2.0: the scan method

Posted 2008-12-09 at 13:06 by PepiMK

I've read it mentioned as a request for 2.0, and it's been a controversial thing for a long time, so I thought this earns its own 2.0 blog entry.

The standard AV (antivirus) approach at scanning is filesystem based, iterating through all or selected file partitions or folders. Extend that to AS (antispyware), and you'll add a full registry iteration as well. Each file/registry entry will be compared to a set of detection rules.

Our "current" (1.x) approach is...
PepiMK's Avatar
Member of Team Spybot
Posted in Spybot 2.0
Views 6928 Comments 12 PepiMK is offline
Old

A few things about reporting bugs

Posted 2008-12-01 at 13:32 by PepiMK

No direct 2.0 blog post this week, the next one will be discussing the differences between various scanner models, a topic I need more time to write about since its far from easy. Instead, an older entry I had saved as a draft but never published so far, and looking for an excuse to use it in the 2.0 blog posts line, which is kind of important at least for error reporting on the 2.0 beta

---

Many might have noticed that I set a high value on proper bug reporting, but...
PepiMK's Avatar
Member of Team Spybot
Posted in Uncategorized
Views 2862 Comments 0 PepiMK is offline
Old

Spybot 2.0: updating concepts

Posted 2008-11-24 at 23:33 by PepiMK

Updating is an area where we feel quite torn, because it just cannot be solved perfectly. On the one hand, privacy paranoia should require all Internet connections to be established on explicit user request and choice. Background downloads are often among malware criteria, and as such, we wanted to avoid them for a long time.

On the other hand, there's user comfort. The average user does not want to be disturbed by having to actively care about his security software too much, and we...
PepiMK's Avatar
Member of Team Spybot
Posted in Spybot 2.0
Views 3675 Comments 4 PepiMK is offline

All times are GMT +2. The time now is 02:57.


Copyright © 2000-2009 Safer Networking Limited. All rights reserved.