Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
June 18, 2013, 06:31:06 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
668791
Posts
71123
Topics
145727
Members
Latest Member:
Thomas Murray
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
Leak Testing/Attacks/Vulnerability Research
viruses in ram or memory
« previous
next »
Pages:
[
1
]
Author
Topic: viruses in ram or memory (Read 27209 times)
pazsion
Comodo Loves me
Offline
Posts: 131
viruses in ram or memory
«
on:
March 28, 2009, 07:21:12 AM »
Most people think this is impossible. But it has heppend to me before and i have had to chnage ram or hd's out because of it..
Somehow turning off the power and remving them alone didnt remove the info or the program was in some area of the hd and used the memory to operate without detection..
They can also be installed remotely.. If the ip is not blocked it will re-infect your pc as long as there is a connection presant.
Logged
mjj09
Comodo Loves me
Offline
Posts: 192
Re: viruses in ram or memory
«
Reply #1 on:
March 28, 2009, 11:13:25 AM »
... a virus
ummm Comodo protects the memory to prevent this
Logged
pazsion
Comodo Loves me
Offline
Posts: 131
Re: viruses in ram or memory
«
Reply #2 on:
March 29, 2009, 03:15:03 PM »
yea but, most firewalls dont..
And i was just wondering if anyone here thught that a virus can't infect other parts of your computer.. like even ROM.. or your cpu..
Logged
HeffeD
Global Moderator
Comodo's Hero
Offline
Posts: 6624
Re: viruses in ram or memory
«
Reply #3 on:
March 29, 2009, 04:19:08 PM »
Quote from: pazsion on March 28, 2009, 07:21:12 AM
Most people think this is impossible. But it has heppend to me before and i have had to chnage ram or hd's out because of it..
If you swapped out some RAM because you thought it was infected, you wasted your money. RAM is volatile. This means that the contents are erased when the power is turned off. In other words, there is no virus hanging out permanently in your RAM. This is why you need to save anything you are working on before turning off your machine or you will lose what you were working on.
What
can
happen is a piece of malware can infect the data in your RAM on machine startup. If you fail to remove this offender from your HD, it can appear as though the virus is living in your RAM because it is reinstated every time you turn on your machine. But the malware is residing on your HD during power off, not in RAM.
ROM is persistent, but requires a re-flashing procedure to change any of the code existing on your EPROM. A flash can not take place invisibly (At least as far as I am aware) so you will know if this has taken place. Malware attempting to flash some portion of your systems ROM resources are going to be rare as it would need to be hardware specific and not something likely to be deployed in drive-by fashion. This would be more of a case of downloading a firmware update from an disreputable source.
Logged
Please read the
Forum Policy
!
Breast Cancer Awareness
American Cancer Society
pazsion
Comodo Loves me
Offline
Posts: 131
Re: viruses in ram or memory
«
Reply #4 on:
March 29, 2009, 11:27:41 PM »
TY heff
that elaborates so much better my thoughts in the original..And then expanded into areas i was curious about..
So this last incident i had recently someone was able to shutdown my pc..
not the first time its happend.. memory overflows usually give a BSOD and an address...
comodo has failed in the past for me.. And i'm trying to be aware of methods of attack..Maybe ways to prevent,stop or reverse an attack.. there was a firewall I tried awhile back that used older virii and ddos's AGAINST attacking ip's lols.. But i'm using comodo again =D Just sometimes you'll notice llittle glitches or something wont work right.. And you can stop a new process and real-time will then detect the virius..
"hacks" in video games are mostly prefab software with simple bindings and instructions that take advantage of the programmers commands that make it ez for them to make the game..or cheats- and they are setup in a simple point and click GUI.. no codeing needed.. thats not hacking...lols
A growing number a newer "hacks" in these games are going further. DDOS's viruses and trojans are being put into them. And w/e some geek comes up with =D. and since most newer mmo's are p2p... this kinda thing could get nasty ... thats the kinda thing that kills games.. also keep in mind the same games being hacked have the same problem on console games.. I dont even know how one would install such a thing on a PS3.. emulater in another OS?? lol hell u could Just install windows on ps3 and buy the pc versions..
Logged
Data
Guest
Re: viruses in ram or memory
«
Reply #5 on:
April 13, 2009, 09:32:59 AM »
Things can be written in such a way that they stay active in memory. They can survive a warm reboot. In other words, when you restart, the running code remains. Same If you hibernate or standby. If you rarely switch off, and you lack memory scanning (which is an AV job), then In theory, this running code would be ever present. Nothing short of a shutdown will dispose of It.
As HeffeD stated, If this code appears after a shutdown, It's on your HD somewhere.
Logged
pazsion
Comodo Loves me
Offline
Posts: 131
Re: viruses in ram or memory
«
Reply #6 on:
June 21, 2011, 07:35:03 PM »
well the current round of bufferover flows, defys logic. The ram is not burned out. system will not boot with it in. The monitor's memory is infected, and may be allowing it to re-infect the system. It's on screen displays don't appear. And it seems the more i try, the more faulty it makes this device.
The system appears to hang on screen, but the pc itself still functions for a bit, then it acctually freezes. If you dont shut down before this point, your monitor or mine. wont work on reboot. It seems to install on boot. I have yet to confirm this.
Logged
Jacob
Global Moderator
Comodo's Hero
Offline
Posts: 2735
Re: viruses in ram or memory
«
Reply #7 on:
June 21, 2011, 10:06:24 PM »
Quote
Somehow turning off the power and remving them alone didnt remove the info or the program was in some area of the hd and used the memory to operate without detection..
Hmf... This is pretty obvious; If you remove the HD from the PC, and plug it back in; the data is not going anywhere..
Unless of course you set the HD on fire or run a moderately powerful magnet against the HD.. If you remove the RAM and then place it back; now thats debatable, depending on the time between removal and place back..
Quote
A flash can not take place invisibly (At least as far as I am aware) so you will know if this has taken place;
If, I'm reading this correctly; you are saying "A flash can not take place hidden"? this is not true;
You can flash your ROM in XP via Command Prompt (an evil prank i use to pull on my students and took them days in order to figure it out), This can be done in C+ as well or Batch. and The affect is applied immediately and can be hidden or shown depending on what the malicious dev wants;
CIS Does protect against such thing
Quote
This means that the contents are erased when the power is turned off
Also Only Partially True!
Data Can Still Survive In RAM(only for a moment) when You shut off your PC/Laptop. (Longer if Power is being cycled through the motherboard - Shorter if No Power is being cycled through the motherboard).
CIS Does protect against such thing
Logged
OTR Truck Driver
Please Follow The Forum Rules!
EricJH
Global Moderator
Comodo's Hero
Offline
Posts: 16990
Re: viruses in ram or memory
«
Reply #8 on:
June 22, 2011, 11:53:27 AM »
Quote from: Jacob on June 21, 2011, 10:06:24 PM
Hmf... This is pretty obvious; If you remove the HD from the PC, and plug it back in; the data is not going anywhere..
Unless of course you set the HD on fire or run a moderately powerful magnet against the HD.. If you remove the RAM and then place it back; now thats debatable, depending on the time between removal and place back..
Read my comment further down.
Quote
If, I'm reading this correctly; you are saying "A flash can not take place hidden"? this is not true;
You can flash your ROM in XP via Command Prompt (an evil prank i use to pull on my students and took them days in order to figure it out),This can be done in C+ as well or Batch. and The affect is applied immediately and can be hidden or shown depending on what the malicious dev wants;
CIS Does protect against such thing
You are a truly evil teacher.
Quote
Also Only Partially True!
Data Can Still Survive In RAM(only for a moment) when You shut off your PC/Laptop. (Longer if Power is being cycled through the motherboard - Shorter if No Power is being cycled through the motherboard).
CIS Does protect against such thing
That is highly theoretical.
DRAM
stores charges but needs to be refreshed:
Quote
Typically, manufacturers specify that each row must be have its storage cell capacitors refreshed every 64 ms or less, as defined by the JEDEC (Foundation for developing Semiconductor Standards) standard.
Having it refreshed every 64 ms means that in practice that once you took out and put back a memory module the memory will be empty.
On top of that even if there still would be voltage on the memory module it would leak away in the blink of an eye due to lack of refreshing.
«
Last Edit: June 22, 2011, 12:23:44 PM by EricJH
»
Logged
Please read:
Introduction to the 5.x Sandbox
With CIS v4 my p2p client (uTorrent, e Mule...) is not working properly anymore
Jacob
Global Moderator
Comodo's Hero
Offline
Posts: 2735
Re: viruses in ram or memory
«
Reply #9 on:
June 22, 2011, 12:31:15 PM »
Quote
You are a truly evil teacher.
I was teaching on the affects of malicious software,
My philosophy is, If you know how to destroy something, You'll know more on how to protect it
Quote
That is highly theoretical
Ah; So We have a debate
Quote
DRAM stores charges but needs to be refreshed:
I was thinking universal, If it's buffered, Instead of DRAM what about those who are using SRAM still?
Quote
....that once you took out and put back a memory module the memory will be empty.
What about those who have a restart? or shutdown wait few seconds and start up?
«
Last Edit: June 22, 2011, 12:35:21 PM by Jacob
»
Logged
OTR Truck Driver
Please Follow The Forum Rules!
EricJH
Global Moderator
Comodo's Hero
Offline
Posts: 16990
Re: viruses in ram or memory
«
Reply #10 on:
June 22, 2011, 01:41:39 PM »
Quote from: Jacob on June 22, 2011, 12:31:15 PM
I was teaching on the affects of malicious software,
My philosophy is, If you know how to destroy something, You'll know more on how to protect it
Very true...
Quote
Ah; So We have a debate
I was thinking universal, If it's buffered, Instead of DRAM what about those who are using SRAM still?
What about those who have a restart? or shutdown wait few seconds and start up?
I am not familiar with buffered memory but as far as I know that is not used in consumer computers.
If a refresh rate of typically 64 ms is needed then that means that if a refresh is done that is seriously out of synch the integrity of data can no longer be guaranteed. I find it highly improbable information would survive.
I don't know exactly what happens when doing a reboot. But I don't recall ever having seen a description of an attack that started in RAM after its information survived reboot.
Logged
Please read:
Introduction to the 5.x Sandbox
With CIS v4 my p2p client (uTorrent, e Mule...) is not working properly anymore
Jacob
Global Moderator
Comodo's Hero
Offline
Posts: 2735
Re: viruses in ram or memory
«
Reply #11 on:
June 22, 2011, 03:33:11 PM »
Quote
I don't know exactly what happens when doing a reboot. But I don't recall ever having seen a description of an attack that started in RAM after its information survived reboot.
With CIS Installed this cannot happen; As it prevents Access to Physical Memory and interprocess memory access and also it sandbox's unknown application(s) so kernel level is nearly impossible to achieve this type of exploit;
But if you didn't have any protection this type of exploit could happen;
Logged
OTR Truck Driver
Please Follow The Forum Rules!
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.053 seconds with 20 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com