AuthorTopic: FAO. computer genius'  (Read 782 times)

0 Members and 1 Guest are viewing this topic.

Edge

  • Guest
FAO. computer genius'
« on: June 25, 2006, 10:01:59 »
Why does my virus/malware scanner miss/skip files :?:

These are what it misses:-

Cannot open file C:\hiberfil.sys
Cannot open file C:\pagefile.sys
Cannot open file C:\WINDOWS\system32\config\default
Cannot open file C:\WINDOWS\SoftwareDistribution\EventCache\{21C43F47-E5C3-4E3D-80DC-D3B8A4D85744}.bin
Cannot open file C:\Documents and Settings\d90\Application Data\ispnews\ispn.ini

What if anything can i do about it :?:

Offline andycwb

  • Posts: 326
  • Attack: 100
    Defense: 100
    Attack Member
  • Karma: +0/-0
  • Referrals: 0
Re: FAO. computer genius'
« Reply #1 on: June 25, 2006, 10:15:35 »
Quote from: "TRUG"
Why does my virus/malware scanner miss/skip files :?:

These are what it misses:-

Cannot open file C:\hiberfil.sys
Cannot open file C:\pagefile.sys
Cannot open file C:\WINDOWS\system32\config\default
Cannot open file C:\WINDOWS\SoftwareDistribution\EventCache\{21C43F47-E5C3-4E3D-80DC-D3B8A4D85744}.bin
Cannot open file C:\Documents and Settings\d90\Application Data\ispnews\ispn.ini

What if anything can i do about it :?:


hiberfil.sys and pagefile.sys are copies of in memory data.  Both of these files are effectively scanned by the "in memory" virus detection.  They are also large files (hiberfil.sys will be the same size as the physical memory in the machine, and pagefile.sys is typically 1.5 to 4 times bigger).

The others are non-executable files that will be used to store data that is very unlikely to contain a virus, so the scanner won't check them.    It takes time to check every single file, and it's not worth checking the very low risk ones.  Even if one of theses files does get infected with a virus, it will be detected and shut down once it becomes active - before it can do any damage.  

As long as your AV software is kept up to date, I wouldn't worry.

Andy

P.S. Computer Security is my day job.
"You came here in *that thing*?  You're braver than I thought."
Td5 Discovery, TD5 Alive Re-Map, QT Diff Guards, Safari Snorkel
Steering Guard, FT-8900 radio, roof rack

Edge

  • Guest
FAO. computer genius'
« Reply #2 on: June 25, 2006, 12:40:48 »
Thanks Andy :D .

Dont suppose you can recommend a security programme for us who are PC dumb :?:

At the moment i'm testing "F-Secure2006".

Offline andycwb

  • Posts: 326
  • Attack: 100
    Defense: 100
    Attack Member
  • Karma: +0/-0
  • Referrals: 0
FAO. computer genius'
« Reply #3 on: June 25, 2006, 12:58:39 »
To be honest, if you're not a PC guru, they're pretty much all the same.  Norton, Symantec, F-secure, McAfee are all as good as each other.  I've run into some problems with Panda's firewall product, but their anti-virus side is great.

For an extra level of security on a Windows PC, go to Control Panel, Administrative Tools, Services, and disable each of the following services - you don't need them unless you're running a Windows network, and they are a common attack route.  

To disable the service, right click each one, go to Properties, and then select Startup Type: Disabled, and hit OK.

The services to disable are Server, Workstation, Messenger and Computer Browser.   Despite their important sounding names, you only need them if you want to copy files from one computer to another.
"You came here in *that thing*?  You're braver than I thought."
Td5 Discovery, TD5 Alive Re-Map, QT Diff Guards, Safari Snorkel
Steering Guard, FT-8900 radio, roof rack

Edge

  • Guest
FAO. computer genius'
« Reply #4 on: June 25, 2006, 14:03:42 »
Your a star Andy :D
If you have any other snippets of advice, chuck them my way :D .

Bet there will be a few others watching this who'll be grateful too :D

Offline discograham

  • Posts: 484
  • Attack: 100
    Defense: 100
    Attack Member
  • Karma: +0/-0
  • Referrals: 0
FAO. computer genius'
« Reply #5 on: June 25, 2006, 15:28:04 »
Quote from: "TRUG"
Your a star Andy :D
If you have any other snippets of advice, chuck them my way :D .

Bet there will be a few others watching this who'll be grateful too :D


 :lol: YEP...
*The grave of Karl Marx is just another communist plot*
*Racial prejudice is a pigment of the imagination*
*Last Tuesdays meeting of the apathy society has just been cancelled*

HORNET
Disco 300tdi ES, Rebel steering guard, QT diff guards, QT cones, Pro-comp ES9000 shocks, 2" lift, Extended stops,  Safari snorkel, 33/12.50/15 Khumo's, Greenway light bar, Rock and tree sliders, nice new door seals and an empty wallet.

MKMC

www.crag-uk.org

www.northants-green-lane.co.uk

www.northants4x4.com

 






SimplePortal 2.3.5 © 2008-2012, SimplePortal