Recommended Posts

the 32-bit virus code CAN STILL run on a 64-bit system with WOW

True. HOWEVER:

1. 32bit malcode can NOT see the 64bit processes.

2. If it was a kernel mode malcode (designed for 32bit systms), then it won't work because it can NOT tamper the kernel because of PG. Most 32bit kernel mode malcode relies on tampering the Service Descriptor Table, which is impossible to do under 64bit systems, unless the malcode can circumvent PG (which's very documented now), in which case we talk about 64bit designed malcode, not 32bit anymore.

I use x86, not had a virus in years :p

I'd get 64bit but I'd never have a real use for it, it wouldn't speed up my computer much and it would be too annoying trying to get 'hacked' files, uxtheme for example :p

True. HOWEVER:

1. 32bit malcode can NOT see the 64bit processes.

2. If it was a kernel mode malcode (designed for 32bit systms), then it won't work because it can NOT tamper the kernel because of PG. Most 32bit kernel mode malcode relies on tampering the Service Descriptor Table, which is impossible to do under 64bit systems, unless the malcode can circumvent PG (which's very documented now), in which case we talk about 64bit designed malcode, not 32bit anymore.

Correct as well. :)

I'll throw in also for everyone else that any 32-bit malware that adds a (32-bit) device driver, the device driver won't run under 64-bit Windows, as some rootkits and other nastys do.

and btw

the funny fact i came by this days

almost all PC today are windows 7 , "vista vaporized quickly"

and most of em are actually 7 x64 "if not all" :cool:

Most PCs (being used for desktops, I presume you did not include servers) are actually XP, according to Net Applications.

7 has an amazing uptake, but is only at about 2% of the market right now.

Reality is not exactly the same as the picture you are painting. ;)

It is simply cause most ppl are still using 32bit OS.

Thats not correct... I have seen a lot of people using 64 bit OS... more and more are moving to 64bit ...

Overall, 64-bit is safer for the same reason Macs and Linux are: number of users.

If I'm going to spend an hour writing code to disable systems, would I rather spend

that hour and effect 1 million systems, or 20 million?

Look at the number of "dangerous" websites. You know what MOST of them have in common? Porn. They either have porn, or just advertise it to get you to the site. Why? Because there's more people searching for porn that anything else. It's all in the numbers of potential victims.

Malware are not written based on the architecture... a 32 bit malware can run on a 64 bit machine just like a 32 bit software can run on a 64 bit OS. The reason they are safe is because of kernal patch protection(patch gaurd) in 64 bit OS. This features only in 64 bit OS

Thats not correct... I have seen a lot of people using 64 bit OS... more and more are moving to 64bit ...

...

You knowing people on a 64bit OS doesn't change the fact that the majority of people still use a 32bit OS.

One of my friends, every member of his family have laptops, all of them running Vista and 2 of them came with 4GB of RAM, and all of them had the 32bit version of Windows installed at the factory.

You knowing people on a 64bit OS doesn't change the fact that the majority of people still use a 32bit OS.

One of my friends, every member of his family have laptops, all of them running Vista and 2 of them came with 4GB of RAM, and all of them had the 32bit version of Windows installed at the factory.

https://www.neowin.net/forum/index.php?showtopic=704878

This generic poll gives you an idea about how people has adapting 64 bit..... obviously non techy wouldnt go for 64bit..

most vendors has started providing 64 bit OS as default OS..

I am not saying majority use 64 bit but 64 bit is getting adapted at a higher rate...

Malware are not written based on the architecture... a 32 bit malware can run on a 64 bit machine just like a 32 bit software can run on a 64 bit OS.

Not entirely true, because some malware targets system files that aren't accessible from within the 32-bit emulator.

The reason they are safe is because of kernal patch protection(patch gaurd) in 64 bit OS. This features only in 64 bit OS

Isn't that a contradiction? PatchGuard is a function that crashes the machine with a bluescreen if it notices that certain kernel structures have been modified in order to deter developers from doing it (it's almost exclusively legitimate software that does it). In order for malware to do this, it has to be written explicitly for 64-bit Windows, since 32-bit code cannot run in the 64-bit kernel (or find some way of accessing a buggy driver and tricking it into doing something on its behalf).

Any hypothetical 64-bit malware of this sort would have to take things like PG into account and either disable or work around it. This is perfectly possible, although obviously more work than on 32-bit where your code would just run, and so it's a slight deterrent.

Of course this is ignoring the fact that most malware actually does not modify the kernel.

https://www.neowin.net/forum/index.php?showtopic=704878

This generic poll gives you an idea about how people has adapting 64 bit..... obviously non techy wouldnt go for 64bit..

most vendors has started providing 64 bit OS as default OS..

I am not saying majority use 64 bit but 64 bit is getting adapted at a higher rate...

I think you'll find that a poll on an enthusiast forum doesn't disprove the fact that most of the world's billion PCs are 32-bit, and that malware authors will therefore primarily target these.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Hello, Christian Maas' XVI32 is a nice (and very small) hex editor. Speaking of hex editors, many years ago a colleague and I who both worked at Tribal Voice managed to edit a copy of the company's PowWow instant messaging client to make it behave better now that all of its lookup servers and other server-side tech was gone.  The program didn't support NAT (RFC-3022 was introduced in January 2001, the same time Tribal Voice was shuttered), but it still worked okay if you manually set up port-forwarding on your router.  The server at http://powwow.jazy.net/ hosts a copy (usual warnings about downloading and running untrusted code from random internet servers apply). I occasionally use some tools like Funduc Software's Search and Replace and Application Mover when I need to make mass-edits to text-based files or move programs with a hard-coded installation directories, respectively.  When I need to figure out the exact LCD panel inside of a laptop, EnTech Taiwan's Monitor Asset Manager is my go-to tool for that purpose. JD Design's website (now hosted on github.io) has a number of interesting freeware and shareware utilities.  I used to use their TouchPro utility to set the file timestamps on software I was mastering to match its version number (e.g., version 3.00 of a program had all of its files dates set to 3:00AM, and so forth). Karenware has a number of interesting freeware utilities, too. Regards, Aryeh Goretsky  
    • I still use HexChat! Not really as ancient as the 1994 AutoCAD above my post, but I have never found anything better to replace it. Yes we still operate an IRC server https://www.neowin.net/irc/ 😛 
    • At work we still have a couple of people that use a version of AutoCAD LT purchased in 1994. This predates Windows 95 and works fine on versions of Windows up to XP. Its long since run in an locked down isolated XP VM, accessible via RDP. I did install LibreCAD for them, however they said it was just too different to get to grips with. In all fairness one of them is now 75 and the other is almost 60.
    • On my music making (non internet) PC Sony Acid Pro 7.0 Adobe Audition 2015 Korg Legacy Collection Windows 7 SP1
    • Anyway to download these versions without being on the Experimental builds?
  • Recent Achievements

    • Week One Done
      Jeroen Wilms earned a badge
      Week One Done
    • Week One Done
      rolfus earned a badge
      Week One Done
    • One Month Later
      Leroy Jethro Gibbs earned a badge
      One Month Later
    • Conversation Starter
      flexorcist earned a badge
      Conversation Starter
    • One Month Later
      AndreaB earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      509
    2. 2
      +Edouard
      198
    3. 3
      PsYcHoKiLLa
      138
    4. 4
      ATLien_0
      90
    5. 5
      Steven P.
      81
  • Tell a friend

    Love Neowin? Tell a friend!