PureAV Alpha1 Build 105 - Antivirus in PB :D

Developed or developing a new product in PureBasic? Tell the world about it.
Inf0Byt3
PureBasic Fanatic
PureBasic Fanatic
Posts: 2236
Joined: Fri Dec 09, 2005 12:15 pm
Location: Elbonia

PureAV Alpha1 Build 105 - Antivirus in PB :D

Post by Inf0Byt3 »

Hi, this is just a small preview of the upcoming PureAV, world's smallest antivirus totally made in PB4.0. Please test it and if you like it and wanna help with the development, PM me.
The engine uses very simple detection algos. I am thinking to LGPL it, as soon it gets bigger - now it's too simple :D.

The only detected item for now is Eicar Standard antivirus test file - included in the package. Hope you like it...

Here's the link:
File:1->PureAV_0.1_Alpha1_Build_105.zip
Image
None are more hopelessly enslaved than those who falsely believe they are free. (Goethe)
thefool
Always Here
Always Here
Posts: 5875
Joined: Sat Aug 30, 2003 5:58 pm
Location: Denmark

Post by thefool »

haha :D
i cant download the file as my current av aborts it.

*pausing it*
i'll be back with a report later :D


edit:
Works nicely :) Looks real good hehe
Inf0Byt3
PureBasic Fanatic
PureBasic Fanatic
Posts: 2236
Joined: Fri Dec 09, 2005 12:15 pm
Location: Elbonia

Post by Inf0Byt3 »

Thanks :).
None are more hopelessly enslaved than those who falsely believe they are free. (Goethe)
thefool
Always Here
Always Here
Posts: 5875
Joined: Sat Aug 30, 2003 5:58 pm
Location: Denmark

Post by thefool »

and by the way: It DOES detect eicar :P

Now needed: Support for scanning packed files (inside zip files, not 100% needed though as they arent that dangerous when packed :) ), support for scanning a single file, support for doing a running-processes-and-their-modules only scan (i miss that from av's!), on-access scan (not needed 100% atm), scanning packed and protected files (use a pe-identifyer to see what kind of packer they are using. If they use things like MEW or so thats often used to compress trojans, instead of a virus alert throw in a heuristic warning that it CAN be a trojan. Simply unpack upx packed files to a temp dir, and for other packers try some generic unpackers they might work. Grap a look at programmerstools.org)
Inf0Byt3
PureBasic Fanatic
PureBasic Fanatic
Posts: 2236
Joined: Fri Dec 09, 2005 12:15 pm
Location: Elbonia

Post by Inf0Byt3 »

Yes, they are on the list now :D, although I'll need some help. If you find any free time, I hope you can help me with the packed exes? That would be very cool.
None are more hopelessly enslaved than those who falsely believe they are free. (Goethe)
thefool
Always Here
Always Here
Posts: 5875
Joined: Sat Aug 30, 2003 5:58 pm
Location: Denmark

Post by thefool »

Inf0Byt3 wrote:Yes, they are on the list now :D, although I'll need some help. If you find any free time, I hope you can help me with the packed exes? That would be very cool.
I could probably help you a little. Though it will require use of external tools..!
Inf0Byt3
PureBasic Fanatic
PureBasic Fanatic
Posts: 2236
Joined: Fri Dec 09, 2005 12:15 pm
Location: Elbonia

Post by Inf0Byt3 »

Thanks! External tools , you mean depackers and stuff?
None are more hopelessly enslaved than those who falsely believe they are free. (Goethe)
thefool
Always Here
Always Here
Posts: 5875
Joined: Sat Aug 30, 2003 5:58 pm
Location: Denmark

Post by thefool »

Yup :)

btw im having a look at that delphi source, and something else a nice guy sent me (about running and injecting pe's in memory)
Inf0Byt3
PureBasic Fanatic
PureBasic Fanatic
Posts: 2236
Joined: Fri Dec 09, 2005 12:15 pm
Location: Elbonia

Post by Inf0Byt3 »

Great! I own you :D. I hope it's translateable...
None are more hopelessly enslaved than those who falsely believe they are free. (Goethe)
dagcrack
Addict
Addict
Posts: 1868
Joined: Sun Mar 07, 2004 8:47 am
Location: Argentina
Contact:

Post by dagcrack »

I think you "owe" him, but, anyway, everyone Owns him :lol:
:wink:

Silly me, I suggested some stuff via PM just to find out thefool suggested the same over here..! :lol:

I worked with delphi 4 years ago, wheres the source?
! Black holes are where God divided by zero !
My little blog!
(Not for the faint hearted!)
Shannara
Addict
Addict
Posts: 1808
Joined: Thu Oct 30, 2003 11:19 pm
Location: Emerald Cove, Unformed

Re: PureAV Alpha1 Build 105 - Antivirus in PB :D

Post by Shannara »

Inf0Byt3 wrote:I am thinking to LGPL it, as soon it gets bigger - now it's too simple :D.
Inf0Byt3
PureBasic Fanatic
PureBasic Fanatic
Posts: 2236
Joined: Fri Dec 09, 2005 12:15 pm
Location: Elbonia

Post by Inf0Byt3 »

@dagcrack:
No problem, you couldn't know thefool said that too :D. BTW, here's the link to the code I was trying to find a translation for:
http://www.purebasic.fr/english/viewtopic.php?t=20750
Give it a try if you have any free time :D.

@shannara
:?: What's wrong with LGPL
None are more hopelessly enslaved than those who falsely believe they are free. (Goethe)
Num3
PureBasic Expert
PureBasic Expert
Posts: 2812
Joined: Fri Apr 25, 2003 4:51 pm
Location: Portugal, Lisbon
Contact:

Post by Num3 »

W :shock: W !!!!

Now i'm impressed !!!

Great work!
Inf0Byt3
PureBasic Fanatic
PureBasic Fanatic
Posts: 2236
Joined: Fri Dec 09, 2005 12:15 pm
Location: Elbonia

Post by Inf0Byt3 »

Thanks Num3! If I suceeded to impress you, which are a good coder, I' m good :D.
None are more hopelessly enslaved than those who falsely believe they are free. (Goethe)
va!n
Addict
Addict
Posts: 1104
Joined: Wed Apr 20, 2005 12:48 pm

Post by va!n »

archive is corrupt! file is everytime 43.102 bytes here
va!n aka Thorsten

Intel i7-980X Extreme Edition, 12 GB DDR3, Radeon 5870 2GB, Windows7 x64,
Post Reply