Go Back   Computer Juice > Computer Software > Multimedia, Drivers & Codecs
Register Points Site Spy New Posts Donate Unanswered Posts Members Search

>>> Get Paid to Hang Out Here! Activity = Points = Prizes. Want to Know More? <<<

Reply
 
LinkBack Thread Tools
  #1  
Old 26th Mar 2008
spot's Avatar
spot  Wales
CJ Donator
Intel Nvidia
spot is offline
 
Join Date: 23rd Feb 2008
Last Online: 6 Days Ago 01:43 AM
Posts: 539
iTrader: (0)
spot is on a distinguished roadspot is on a distinguished road
Default evilfantasy's All-in-1 Malware Free Codec Packs



That's a neat post and it'll be useful. You closed it to questions though, so excuse this follow-up thread.

I've always presumed that a resident virus checker will block any malware codec that a user accepts because I've always assumed the internet-downloaded codec has to go to disk before it's run. Do you think that's so, or do you think it's straight-to-memory and avoids the real-time scan?

Why are these things called codecs anyway? The coding portions never exist with the decoder portions, the packs are all decoders, the coders are built into entirely different programs.
__________________

My System: Tim

CPU(s):
Athlon 64 3500+
Motherboard:
Asus A8N-VM CSM
RAM:
Corsair PC3200 CL2 DDR-400 2GB
Graphics Card(s):
nVidia Geforce 6600 512MB
Sound Card:
Cherry RS 6000 M keyboard
Hard Drive(s):
Barracuda.7+ 2x200GB 58MB/s sustained
Optical Drive(s):
Samsung DVD-ROM TS-H352
Case / PSU:
Thermaltake Soprano
Cooling:
Stock
Network / Internet:
Telewest 2x20Mb/sec
Monitor(s):
SXGA flat panel
Operating System(s):
Slackware (2.6.24.3) (Fluxbox) (bash)

Want your system info in your signature?
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #2  
Old 26th Mar 2008
Cew27's Avatar
Cew27  United Kingdom
CJ Donator
 
Cew27 is offline
Send a message via MSN to Cew27
 
Join Date: 6th Sep 2007
Last Online: 18 Hours Ago 04:01 PM
Age: 16
Posts: 1,854
iTrader: (0)
Cew27 is on a distinguished road
Default evilfantasy's All-in-1 Malware Free Codec Packs

most of the above codecs are int he downloads section if not all of them
__________________
Im not a Geek!, Im Educated!
__________________

My System: Cewy's wonder macine

CPU(s):
intel core 2 quad q6600 @ 3.2Ghz
Motherboard:
evga 780i sli
RAM:
4 gig ocz 1066mhz sli
Graphics Card(s):
nvidia evga 8800 ultra ko
Sound Card:
onboard
Hard Drive(s):
750 gig seagate, 32meg cache
Optical Drive(s):
3 asus dvd writers, lightscribe
Case / PSU:
gigabyte 3d aurora
Cooling:
arctic cooling freezer 7 pro
Network / Internet:
dual gigabit lan ports
Monitor(s):
24" dell 2408wfp
Operating System(s):
vista home premium 64bit / ubuntu 64 bit

Want your system info in your signature?
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #3  
Old 26th Mar 2008
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: 16th Jul 2007
Last Online: 3 Hours Ago 07:29 AM
Posts: 4,914
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default evilfantasy's All-in-1 Malware Free Codec Packs

A bad codec can attack just the browser itself as a dll or an activex control. Yes it will have to be installed but as I like to say, the biggest piece of malware ever created is the mouse. Antivirus is useless in many cases of careless clicking. It is a roll of the dice on if it will catch the malicious file before or after it is installed. Some malware has the ability to temporarily turn off security long enough to install itself. Then it won't be found until it is too late, if found at all. Once you click accept or yes (whatever the case may be) the AV is powerless.

Also if it is some new malicious file it may not be in the AV database yet so it won't be found by your AV anyway.
__________________
.
.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #4  
Old 26th Mar 2008
spot's Avatar
spot  Wales
CJ Donator
Intel Nvidia
spot is offline
 
Join Date: 23rd Feb 2008
Last Online: 6 Days Ago 01:43 AM
Posts: 539
iTrader: (0)
spot is on a distinguished roadspot is on a distinguished road
Default evilfantasy's All-in-1 Malware Free Codec Packs

There's a very strict order to these things. AV packages scan what's saved to disk or loaded from disk, that's their focus. I agree that if the AV database doesn't identify the malware then the malware passes without being stopped. I'm not aware of any codec that downloads straight into memory and executes without a prior disk save. The writers of the players are aware of the danger of allowing that.

There are two types of malware. There's the sort that burrows in through buffer overflows and executes without getting saved first, or which rely on script language security holes. They can and do try to turn off the security before embedding themselves permanently. That mechanism simply isn't available to malware which is downloaded or arrives as an email attachment, all of which have to be saved first before they can be executed.

Anyway - the "click yes to run" variety simply has to come off the disk, there's no mechanism in the operating system to accept before it's stored. All of those have been AV-scanned, assuming there's a resident AV scanner.
__________________

My System: Tim

CPU(s):
Athlon 64 3500+
Motherboard:
Asus A8N-VM CSM
RAM:
Corsair PC3200 CL2 DDR-400 2GB
Graphics Card(s):
nVidia Geforce 6600 512MB
Sound Card:
Cherry RS 6000 M keyboard
Hard Drive(s):
Barracuda.7+ 2x200GB 58MB/s sustained
Optical Drive(s):
Samsung DVD-ROM TS-H352
Case / PSU:
Thermaltake Soprano
Cooling:
Stock
Network / Internet:
Telewest 2x20Mb/sec
Monitor(s):
SXGA flat panel
Operating System(s):
Slackware (2.6.24.3) (Fluxbox) (bash)

Want your system info in your signature?
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #5  
Old 26th Mar 2008
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: 16th Jul 2007
Last Online: 3 Hours Ago 07:29 AM
Posts: 4,914
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default evilfantasy's All-in-1 Malware Free Codec Packs

Are you saying that there is no malware embedded in codecs?

EDIT: Fake codecs.
__________________
.
.

Last edited by evilfantasy : 26th Mar 2008 at 04:58 PM.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #6  
Old 26th Mar 2008
spot's Avatar
spot  Wales
CJ Donator
Intel Nvidia
spot is offline
 
Join Date: 23rd Feb 2008
Last Online: 6 Days Ago 01:43 AM
Posts: 539
iTrader: (0)
spot is on a distinguished roadspot is on a distinguished road
Default evilfantasy's All-in-1 Malware Free Codec Packs

Of course not, they're famed for having them.

I'm saying that a fake codec can't run and deliver its payload before it's been saved to disk.

If there's a resident AV scanner then it would have to be unrecognized for it to be effective. I don't think there's a significant proportion which would go unrecognized. Consequently I think having a resident AV scanner is a reasonable protection against the fake codec route of infection.
__________________

My System: Tim

CPU(s):
Athlon 64 3500+
Motherboard:
Asus A8N-VM CSM
RAM:
Corsair PC3200 CL2 DDR-400 2GB
Graphics Card(s):
nVidia Geforce 6600 512MB
Sound Card:
Cherry RS 6000 M keyboard
Hard Drive(s):
Barracuda.7+ 2x200GB 58MB/s sustained
Optical Drive(s):
Samsung DVD-ROM TS-H352
Case / PSU:
Thermaltake Soprano
Cooling:
Stock
Network / Internet:
Telewest 2x20Mb/sec
Monitor(s):
SXGA flat panel
Operating System(s):
Slackware (2.6.24.3) (Fluxbox) (bash)

Want your system info in your signature?
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #7  
Old 26th Mar 2008
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: 16th Jul 2007
Last Online: 3 Hours Ago 07:29 AM
Posts: 4,914
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default evilfantasy's All-in-1 Malware Free Codec Packs

I see your point and it is valid, only I have seen first hand (in the malware forum) the damage the fake codecs can cause. It is a very common way of infecting a computer. An AV is a layer of protection but far from a catch all, even for known threats. Depending what is written into the file you can be infected with the whole spectrum of virus/trojan/worm etc.

See this post for a better explanation.
__________________
.
.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote

Please support this forum, donate towards our running costs.


Reply


Thread Tools

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
wmp11 codec muay Multimedia, Drivers & Codecs 3 28th Jun 2008 01:24 PM
All-in-1 Malware Free Codec Packs evilfantasy Multimedia, Drivers & Codecs 0 26th Mar 2008 05:40 AM
Windows media player codec computer lover786 Multimedia, Drivers & Codecs 13 24th Mar 2008 08:27 AM
Help! i need a new codec i think! cheesepuff Multimedia, Drivers & Codecs 4 2nd Feb 2008 01:28 PM
codec tinkerbell Multimedia, Drivers & Codecs 2 29th Jan 2008 12:30 PM


Copyright ©2006 - 2008 Computer Juice - Forums - Free PC Help, IT Support and Repairs.

Powered by vBulletin® Copyright ©2000 - 2008 Jelsoft Enterprises Ltd. SEO by vBSEO ©2008, Crawlability, Inc.

Page copy protected against web site content infringement by Copyscape