Re: Extracting signature snippets from AV databases

"Yuri Slobodyanyuk" <[email protected]> Tue, 9 May 2006 21:58:17 +0200
Newsgroups gmane.comp.security.virus
Message-ID <006f01c673a2$ed859a50$b8d6fea9@nasa>
Nothing directly answering your question comes to mind, but to get you
started here's a link to the "Ad-Aware PR" article at the www.rootkit.com
http://www.rootkit.com/newsread.php?newsid=471

With quite extensive reversing of Adaware workings.
The common sense tells me that such
information should be available on the Net, will try to Google it later.

SideNote: few years ago I watched the heated dabate on some forum (don't
remember any details) where AV vendor representative was accusing
open-source AV developers of reverse-engineering the virus-signatures
instead of gathering their own, so logic
says it has been done before by someone.