<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.spybot.info/index.php?action=history&amp;feed=atom&amp;title=Choosing_advanced_file_parameters</id>
	<title>Choosing advanced file parameters - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.spybot.info/index.php?action=history&amp;feed=atom&amp;title=Choosing_advanced_file_parameters"/>
	<link rel="alternate" type="text/html" href="https://wiki.spybot.info/index.php?title=Choosing_advanced_file_parameters&amp;action=history"/>
	<updated>2026-05-02T06:53:01Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.15</generator>
	<entry>
		<id>https://wiki.spybot.info/index.php?title=Choosing_advanced_file_parameters&amp;diff=839&amp;oldid=prev</id>
		<title>CCRDude: First draft</title>
		<link rel="alternate" type="text/html" href="https://wiki.spybot.info/index.php?title=Choosing_advanced_file_parameters&amp;diff=839&amp;oldid=prev"/>
		<updated>2008-05-27T18:16:01Z</updated>

		<summary type="html">&lt;p&gt;First draft&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;[[Image:FileAlyzer-opensbi-tab.png|thumb|300px|OpenSBI tab]]&lt;br /&gt;
[[FileAlyzer]] is our file analysis tool that, starting with the 1.6 OpenSBI edition, allows to easily create [[Advanced file parameters|advanced file parameters]] for selected files.&lt;br /&gt;
&lt;br /&gt;
==Quick Steps==&lt;br /&gt;
* Run [[FileAlyzer]] by right-clicking a file and select to analyze it, or run it from the Start menu and select a file to analyze in the dialog it will show.&lt;br /&gt;
* Switch to the OpenSBI tab to view the basic properties it has added.&lt;br /&gt;
* Browse other categories (tabs) to load more identifying information in the file.&lt;br /&gt;
* When you&amp;#039;ve seen enough, switch back to the OpenSBI tab.&lt;br /&gt;
* The list will show you the parameters for everything you&amp;#039;ve viewed, just tick the properties you want to use, and copy and paste the parameters from the field at the bottom into [[OpenSBI Edit Lite]].&lt;br /&gt;
&lt;br /&gt;
==Details==&lt;br /&gt;
In the beginning of adware and spyware, those products were seldomly updated and did not use tactics to avoid detection. Detection for such static files can easily be added by using the standard [[filesize]] and [[md5]] attributes.&lt;br /&gt;
&lt;br /&gt;
With malware evolving though, issues are getting more complex. You may need to compare various samples of a similar type to find a common ground if the file is pseudo-random. FileAlyzer offers a few simple identification methods here:&lt;br /&gt;
&lt;br /&gt;
* If the file is codesigned, [[authx509|parameters]] for various fields of the signature are added to this list when loading the file.&lt;br /&gt;
* If you switch to the &amp;#039;&amp;#039;PE sections&amp;#039;&amp;#039; tab, a [[md5(sections)|hash of the overall content]] will be added (in case the file is only random through padded information after the end of the actual file), as well as [[md5(section)|hashes for each section]] (useful e.g. in case only some sections are randomized).&lt;br /&gt;
* Every resource you view will get added to the list. Clear, unchanged product images can be used to [[md5(res)|identify files this way]].&lt;br /&gt;
* [[field(version)|Version resource fields]] as well as [[md5(version)|hashes]] are added when viewing the &amp;#039;&amp;#039;Version&amp;#039;&amp;#039; tab.&lt;br /&gt;
* The &amp;#039;&amp;#039;Hex view&amp;#039;&amp;#039; tab allows you to select any range of bytes and add a [[findbinary(searcharea)|parameter for that]].&lt;br /&gt;
* So do the various lists of detected [[findtext(searcharea)|GUIDs, URLs, filenames, and registry locations]].&lt;br /&gt;
&lt;br /&gt;
==Considerations==&lt;br /&gt;
Keep in mind that the more complex parameters you choose, the more affect this has on overall scanning time. &amp;#039;&amp;#039;Standard&amp;#039;&amp;#039; overall hashes are easier in that regard, since they get cached, but the properties of a specific resource or even random data somewhere in the file are quite unique and slowing the system down. [[APBoost]], a new 1.6 technology, helps reducing that load, but you&amp;#039;re still encouraged to think &amp;#039;&amp;#039;cheap&amp;#039;&amp;#039; (in terms of time cost to scan files) on the CPU.&lt;br /&gt;
&lt;br /&gt;
==Warning==&lt;br /&gt;
Analyzing multiple files of the same product is possible with [[FileAlyzer]], but sometimes it is not very comfortable to detect a common ground between files. We might decide at a later point to make other tools for this purpose available.&lt;br /&gt;
&lt;br /&gt;
[[Category:Tutorials]]&lt;/div&gt;</summary>
		<author><name>CCRDude</name></author>
	</entry>
</feed>