Welcome to SecurityForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

F-Prot for DOS 3.15 available

 
   Security Forums (Home) -> F-PROT RSS
Next:  F-prot wants to connect  
Author Message
Clay

External


Since: Mar 07, 2004
Posts: 53



(Msg. 1) Posted: Thu Jul 08, 2004 11:23 am
Post subject: F-Prot for DOS 3.15 available
Archived from groups: alt>comp>virus (more info?)

ftp://ftp.f-prot.com/pub/dos/

--
Clay mania dot com

 >> Stay informed about: F-Prot for DOS 3.15 available 
Back to top
Login to vote
kurt wismer

External


Since: Jul 04, 2003
Posts: 1562



(Msg. 2) Posted: Thu Jul 08, 2004 2:49 pm
Post subject: Re: F-Prot for DOS 3.15 available [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

null RemoveThis @zilch.com wrote:
> On Thu, 08 Jul 2004 09:18:52 -0700, Bart Bailey <me2 RemoveThis @privacy.net>
> wrote:
>
>>In Message-ID:<bjpqe0troj6qeb7meiikbfblr5lvdeu50s RemoveThis @4ax.com> posted on
>>Thu, 08 Jul 2004 11:23:14 -0400, Clay wrote: Begin
>>
>>>ftp://ftp.f-prot.com/pub/dos/
>>
>>Thanks Clay
>>Full scan with no hangups or crashes on compressed archives.
>
> But some new and unusual false alarms here. One is on Trend's
> Sysclean.com .... a real NoNo alerting on a competitor's scanner Smile

true that, but is the false alarm due to the lack of signature
encryption in trends product or is it all f-prot's fault?

--
"maxwell can tell he's in hell
just wants you to visit him there
same old game that he's playin'
his rules are never fair"

 >> Stay informed about: F-Prot for DOS 3.15 available 
Back to top
Login to vote
Nick FitzGerald

External


Since: Jul 03, 2003
Posts: 179



(Msg. 3) Posted: Sun Jul 11, 2004 11:55 pm
Post subject: Re: F-Prot for DOS 3.15 available [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

<null DeleteThis @zilch.com> wrote:

<<snip>>
> The differing philosophies of the av vendors are interesting. The KAV
> analysts apprently see no danger in the .sud files and no reason to
> alert on them.
>
> Where's Nick? Whatcha think? What if these .sud files appeared in a
> malware collection used for testing av detection. Are they "crud" that
> shouldn't cause a alert? Smile Who's right here? KAV or F-Prot?

I think both are kind of right...

I'm assuming you ran F-PROT with the "/dumb" (or perhaps "/collect")
switch -- I'd be quite surprised for it "false" on such files otherwise.

The confusion is over how to handle such odd-ball, non-natural but in a
sense "real" samples. From an AV-purist position, the Norton utility
that made these should have obfusctated them in some more thorough way
than just slapping a small header on them -- at a minimum XOR'ing the
file bodies, or perhaps compressing them with some proprietary alorithm
(or at least into a tweaked/proprietary format so they wouldn't be
recognized and automatically decompressed by another scanner).

> Personally, I'm glad that F-Prot alerted. It gives me a puzzle to chew
> on. I don't know how the damn Hackarmy sample wound up where it did.
> As I said, I don't use NAV. It's an old version of Norton Utilities I
> use sometimes for it's Speed Disk (defrag), Sytem Check, and NDD.
> Somehow, a recent System Check resulted in the subject .sud files
> being created (it seems). Certainly, I've been handling hackarmy
> samples I've downloaded from newsgroups to check and collect them. So
> that at least explains why a sample may have been in my c:\download
> directory. But I can't yet explain the Norton System Check behaviour.

Sorry -- can't help there either...

> Anyway, the question is, what's best for typical users? I'm reminded
> of old discussions of "false alarms" and "crud" and how av vendors
> aren't supposed to scare users unnecessarily. It's a continually
> interesting kind of issue and question.

Indeed.

The sysclean.exe "hit" is clearly a false alarm, but the .SUD files
are yet another of those very dubious grey areas where it is all too
easy argue faiurly convincingly that either of two opposite behaviours
is "right"...


--
Nick FitzGerald
 >> Stay informed about: F-Prot for DOS 3.15 available 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Run F-PROT for DOS from CD? - Can..
   Security Forums (Home) -> F-PROT All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]