Security Basics mailing list archives

RE: Looking for a Trojan


From: "David Harley" <david.a.harley () gmail com>
Date: Tue, 20 Jan 2009 18:33:37 -0000

AV software can only detect the virus/trojan it has 
definition for. So the argument that old trojan can be 
detected by updated AV can be said true with an assumption 
that since the trojan is old its would have been sampled by 
AV companies and most of AV software have it in the 
defination database. So, if u get a new trojan which is just 
days old then many AV (or even none) would detect it.

This is only partly true. Modern antimalware uses a variety of techniques
(heuristics, sandboxing etc) to detect new malware proactively that it
hasn't seen before. What it doesn't do is detect -all- new malware... 
--
David Harley BA CISSP FBCS CITP
Small Blue-Green World

 


Current thread: