HOW for exmaple image or mage.exe is working how in memeory processing unit itb coudl works
imagine we write a code that scan means go in apkckage of menas progrmafiles then take the fiels in the folder and scna of system32.exe and we make it trea dprocssing in mutkiepl process here thread image is went in back side
so all folders wher tehse files and we read the specimen of the file currenet file that in pattern nothong change in patterns hown it wil happens it have happens by image
so in memory processig unit we kept all patterns matching with files how thsi fiel will open it loadeed and print secodry memroy and in secodnary memroy files will go and scans that theer si in aptteerns nothign have unmatched menas file locations so we need for this apis of wokring means we tarce the runable file and all rananable file .exe files all .exe files will examine by the pattenrn matching there is tree in the file so it read by as string and then read the read execuatble and wirte exectable then upadte it bhwole menas all staring conervt in patterns
means what ahppens in antivirus it chekc firts teh foleder tehn kit chekc the locaiton of file and then chekck teh file sequence then sequence in teh file means sequnce of teh file menas what sequnce of the file is works
the in fiel we chekc the treee in bollelan perform becasye its bit or execuatbel file so how parsing will do
we take in stringn then conevrt it in tree of so what heoeons it checks the linking betwene assmeblly and the code and where in taht pattern msiamcth taht will be the maliciosiu code
meanas hwo assembly will cheke by assembly encodeer so means itis all aimges taht works ina ssmbly we have execuatble iamges and then we capture the addresses in memroy rpocessing unit if we memeory processing unit if we capture for only memory processing unit becaue my intention to enalrge my prodcut means memrory processing unit
so in memory procesing unit we have adddress in memrory from memeroyw e reach to assmebly so by antivirus hwo we get the memrpy locaiton so we get teh memroy location of file and tehn tsheo apttern in shape fo string apttern not parse tree taht will rpitn in memory so we get teh assmbly and oevr alpped mibehvae we chehkced and unsolevd to solev we delet taht malciosu code
contains
in memroy processing unit we have mmeroy processing unit in whihc dual address so we have cretaed an dpritn the iamge of oen file in os then in address then we have to reahc taht file in os sow e searhc the folder and physcial locaiton of file then we arse the file in tree means parsing tree then it chehck in asssmbly alansgue witha ddress and which data will not in prasing apirs of treee will remove if teher si filed is needee means if tehre is dictianry fo virus then ist serahc in memry lcoaiton of vrisu we parses and get address of avirbale or what so even file link where th fiel .link so we have to fidn out teh link addresss
so here how aprsing the code in such in orders becasue file its new things taht to chekc the file isndielyw e coudl chehck very well manenrs we coudl check by using mmrpuy rpcoessing unit we coudl replaced location of avribel in difefrnet memry processing unit part means we give to differnet mmeory procesing unit
in memory processig unit we put teh image of copy of the code during check in tree parisng orders means then after make zro adddresee we return that code to back inmmery procesing unit as .exe
every file evry link is imagses and i bit it alls images so we aprse file and then in sgtring based we comapre string.comatrto with dictiaonry of irus files if taht conenet then taht conet will erases from teh fiel if ist new techinowes imaging of file so iamge fo teh fiel is crucial key value apri then key value apirs then links so from anti vrisu dta base if we have givven the freee memry addresses values that like virus files in virus files we mainatin viorus acytivyt and if we fidn atht acitvity in files menas parsing and actcivyt mena s two memery addreses one for parsing so menas parse tree like binary tree and then hre what i am doing i am doing one thigns i asre file and keep that file atht is excutabel ro on difefr formats in secodnar memory addresses then i fidn have file taht is pasre from dictioanry file
then comapre with the tokens then compare of tokens then remove tshoe toekn tshoe si new and remoev tshe file form bianry fiel structre that folder s remove tsheo folders so how we isnatll virus activyt in antivirus we isnatslsl and comrpe it with virus activity
Comments
Post a Comment