Reply to post: The Participant Observer Problem

I've seen Kaspersky slap his staff with a walrus penis – and even I doubt the false-positive claims

Ken Moorhouse Silver badge

The Participant Observer Problem

>What I don't understand is how it is possible to misidentify a proper Windows system file. Surely MS can provide something like SAH256 hash values of every legitimate build they have released in the last decade or so?<

Yes, but the ultimate pwn is the Rootkit that can simulate the calculation of clean hashes. If this arrived on the machine before the AV engine could detect it then it would be difficult if not impossible to detect subsequently using an in situ scan. The AV engine would be relying on a corrupt source of information when checking file signatures.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon