<div align="center">

</div>

Moon Secure AV is a free Antivirus for Windows under GPL license. It offers multiple scan engines, Net shield, Firewall, On access, on Exec scanner and rootkits preventions plus features from Commercial Antivirus applications.
Moon Secure AV is an open source Antivirus currently using the ClamAV engine due to fast response time and huge AV database, however we are implementing another engine that is heuristic and will allow users to customize the engine on the fly. Unlike clam it has an enterprise level real-time scanner.

It is built for Windows and will run on XP and Vista. It can scan portable drives and fixed drives. It is able to detect viruses, Trojans and spyware.


http://sourceforge.net/project/showf...roup_id=169560


Visit home page at http://www.moonsecure.com

CREDITS:
Daniel Lamb
Eric Hullibarger

ยี่ห้อนี้มีการพัฒนาระบบ heuristic ขึ้นมาเอง โดยดูจาก discussion ใน forum

Discussion Forums: Developers

Admin

<div class='quotetop'>QUOTE
Open dicussion for heuristic engine
By: TheSun HVA (sunmnpProject Admin) - 2007-11-20 19:17[/b]
Any one has an idea to contribute to development of an efficient heuristics engine please post it here

regards,
DUC


RE: Open dicussion for heuristic engine
By: Robert Scroggins (guitarbob) - 2008-03-18 09:58[/b]
Keep the heuristics simple for awhile--much malware is simple! My suggestions:

1) Flag code that disables/lowers security software (AVs/firewall/browser functions).
2) Flag code that limits/denies user access to his important functions (registry/control panel/folder options/find/file extensions/command shell, etc.)
3) Flag code that attempts to "harvest" information (AVs/email addresses/files)
4) Autorun code/registry entries (you may need to "soften" this by including something else also
5) File types that differ from their indicated extensions (.exe masked as graphic, etc.)
6) Patterns that are exhibited by malware: double extensions/unique file types/excessive use of one type of file extensions (such as 10 .exe files)
7) Obfuscation: use of common malware packers (example: MEW)/programming languages (Delphi)/encryption
8) Damaging code (del c:*.*/etc.)







RE: Open dicussion for heuristic engine
By: Branko Jermanis (brankoj) - 2008-03-27 05:09[/b]
I upgrade version of Moon Secure Antivirus to 2.2.2.160 and it detect standard UltraVNC program (WinVNC.exe) like virus "PUA.RAT.VNC-2". And UltraVNC setup can&#39;t start too, because on-the-fly detection.
It is standard program, and it is not virus.
It is not problem for me, but standard user on remote computer can remove this file with MoonSecure, and this is bad (if computer is in another town, and lose remote connection).[/b][/quote]

We need Your Help
Moon Secure AV has now grown into a very large project which is managed by a small team, we have all put a lot into the project both in time and money and now we are asking you the users of our program to help us improve our program further, we need help now by people submitting undetected virus samples here , we need a dedicated server to install a honeypot on to collect "in the wild" samples to get a dedicated server we need money so if anyone feels fit please could they get in touch with us via our contact page.


New Release
We have released an up to date version 2, with over 25,000 more virus definitions and a much more attractive GUI, please as always provide feedback via our forums or via the contact page.
Virus Submissions
After a short review we have decided to change the way users are allowed to submit undetected viruses, this is now available via this page , please provide details about detection i.e. what program detected it, what behaviour it caused. Please submit them in compressed files.


เวอร์ชั่นสองได้รับการพัฒนาให้ใช้งานกับวินโดวส์วิสต้าเรียบร้อยแล้ว และเพิ่มการทำงานแบบ heuristic ขึ้นมา โดยแอนตี้ไวรัสยี่ห้อนี้มีการสแกนแบบเรียลไทม์ ทั้ง on access และ on demand มีไฟร์วอลล์ ระบบกรองเว็บไม่พึงประสงค์ ป้องกันรูทคิต โทรจัน และสปายแวร์ ได้เช่นเดียวกับโปรแกรมที่ขายแบบคอมเมอร์เชียลยี่ห้ออื่นๆ

**Hidden Content: To see this hidden content your post count must be 5 or greater.**