UEFI malware rears ugly head again: Kaspersky uncovers campaign with whiff of China

phuzz

Re: Checksum? Hash?

"why doesn't a regular scan detect these attacks"

Most virus scanners start off by just comparing the hash of a file to a list of known viruses/malware, which means that all it takes is some padding, and a virus won't be detected.

More modern antivirus software can do some more in depth analysis, as well as monitoring for activity which might indicate a virus (eg, trying to modify which programs are launched at startup), but at the end of the day, most antivirus is helpless against a targeted attack.

