Re: Extracting signature snippets from AV databases
"Yuri Slobodyanyuk" <[email protected]> Tue, 9 May 2006 21:58:17 +0200
| Newsgroups | gmane.comp.security.virus |
|---|---|
| Message-ID | <006f01c673a2$ed859a50$b8d6fea9@nasa> |
Nothing directly answering your question comes to mind, but to get you started here's a link to the "Ad-Aware PR" article at the www.rootkit.com http://www.rootkit.com/newsread.php?newsid=471 With quite extensive reversing of Adaware workings. The common sense tells me that such information should be available on the Net, will try to Google it later. SideNote: few years ago I watched the heated dabate on some forum (don't remember any details) where AV vendor representative was accusing open-source AV developers of reverse-engineering the virus-signatures instead of gathering their own, so logic says it has been done before by someone.