Welcome to SecurityForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

F-PROT for DOS: anomily ?

 
   Security Forums (Home) -> F-PROT RSS
Next:  Dave re upnpclient.exe being w32/backdoor.SO and ..  
Author Message
news

External


Since: Apr 27, 2005
Posts: 1



(Msg. 1) Posted: Wed Apr 27, 2005 11:34 am
Post subject: F-PROT for DOS: anomily ?
Archived from groups: alt>comp>virus, others (more info?)

Hi,
I've had Russian_Flag.A virus in my several [old ] PCs, and in many
fd0s. I thought F-PROT had solved the problem, but it kept on
returning unexpectedly, when I use DOS [for transporting linux
and Oberon-S3 orginated files] for printing.

Only now, on closer analysis did I noticed the message:
"Unable to remove the virus. ",
which I had apparently just been skipping over previously !

How/why can this particular copy of the virus not be removable,
when F-PROT ANTIVIRUS v3.14e removed many from fd0s & hdx1s
previously [ Always Russian_Flag.A virus ] ?

Equally confusing is that when I set:
find virus in "Local hard disk[s]", it finds the virus on /dev/hda1 [DOS C:]
and finds that /dev/hdc1 [DOS D:] is OK.
But when I set C: & D: individually as the 'check for virus' devices, it
passes both without finding any virus. The logs below show results.

Thanks for any information explaining these strange results.

== Chris Glur.

PS. some logs below.
------------ APRL2005.VIR ==

Virus scanning report - 27 April 2004 @ 10:59

F-PROT ANTIVIRUS
Program version: 3.14e
Engine version: 3.14.12

VIRUS SIGNATURE FILES
SIGN.DEF created 16 March 2004
SIGN2.DEF created 16 March 2004
MACRO.DEF created 15 March 2004

Search: Local hard disks
Action: Disinfect/Query
Files: "Dumb" scan of all files
Switches: /ARCHIVE /PACKED
No viruses found in memory.
Master Boot Sector Infection: Russian_Flag.A

Scanning C:
Scanning D:

Results of virus scanning:

Files: 1111
MBRs: 2
Boot sectors: 4
Objects scanned: 989
Infected: 1
Suspicious: 0
Disinfected: 0
Deleted: 0
Renamed: 0

Time: 2:10
------------ COMBINED.VIR ==
Virus scanning report - 27 April 2004 @ 11:13

F-PROT ANTIVIRUS
Program version: 3.14e
Engine version: 3.14.12

VIRUS SIGNATURE FILES
SIGN.DEF created 16 March 2004
SIGN2.DEF created 16 March 2004
MACRO.DEF created 15 March 2004

Search: Local hard disks
Action: Disinfect/Query
Files: "Dumb" scan of all files
Switches: /ARCHIVE /PACKED
No viruses found in memory.
Master Boot Sector Infection: Russian_Flag.A

Scanning C:
Scanning D:

Results of virus scanning:

Files: 1114
MBRs: 2
Boot sectors: 4
Objects scanned: 992
Infected: 1
Suspicious: 0
Disinfected: 0
Deleted: 0
Renamed: 0

Time: 2:11
COMBINED.VIR ==
Virus scanning report - 27 April 2004 @ 11:13

F-PROT ANTIVIRUS
Program version: 3.14e
Engine version: 3.14.12

VIRUS SIGNATURE FILES
SIGN.DEF created 16 March 2004
SIGN2.DEF created 16 March 2004
MACRO.DEF created 15 March 2004

Search: Local hard disks
Action: Disinfect/Query
Files: "Dumb" scan of all files
Switches: /ARCHIVE /PACKED
No viruses found in memory.
Master Boot Sector Infection: Russian_Flag.A

Scanning C:
Scanning D:

Results of virus scanning:

Files: 1114
MBRs: 2
Boot sectors: 4
Objects scanned: 992
Infected: 1
Suspicious: 0
Disinfected: 0
Deleted: 0
Renamed: 0

Time: 2:11
------------UNABLE.VIR ==
Virus scanning report - 27 April 2004 @ 11:39

F-PROT ANTIVIRUS
Program version: 3.14e
Engine version: 3.14.12

VIRUS SIGNATURE FILES
SIGN.DEF created 16 March 2004
SIGN2.DEF created 16 March 2004
MACRO.DEF created 15 March 2004

Search: Local hard disks
Action: Disinfect/Query
Files: "Dumb" scan of all files
Switches: /ARCHIVE /PACKED
No viruses found in memory.
Master Boot Sector Infection: Russian_Flag.A
Unable to remove the virus. <--- !!!??

Scanning C:
Scanning D:

*** Scanning aborted by user ***

Results of virus scanning:

Files: 261
MBRs: 2
Boot sectors: 4
Objects scanned: 249
Infected: 1
Suspicious: 0
Disinfected: 0
Deleted: 0
Renamed: 0

Time: 6:22
------------VIR4C.DAT ==
Virus scanning report - 27 April 2004 @ 11:09

F-PROT ANTIVIRUS
Program version: 3.14e
Engine version: 3.14.12

VIRUS SIGNATURE FILES
SIGN.DEF created 16 March 2004
SIGN2.DEF created 16 March 2004
MACRO.DEF created 15 March 2004

Search: c:
Action: Disinfect/Query
Files: "Dumb" scan of all files
Switches: /ARCHIVE /PACKED
No viruses found in memory.

Scanning C:

Results of virus scanning:

Files: 178
MBRs: 0
Boot sectors: 0
Objects scanned: 168

Time: 0:07

No viruses or suspicious files/boot sectors were found.
------------VIR4HDS.DAT ==
Virus scanning report - 27 April 2004 @ 11:12

F-PROT ANTIVIRUS
Program version: 3.14e
Engine version: 3.14.12

VIRUS SIGNATURE FILES
SIGN.DEF created 16 March 2004
SIGN2.DEF created 16 March 2004
MACRO.DEF created 15 March 2004

Search: Local hard disks
Action: Disinfect/Query
Files: "Dumb" scan of all files
Switches: /ARCHIVE /PACKED
No viruses found in memory.
Master Boot Sector Infection: Russian_Flag.A

*** Scanning aborted by user ***

Scanning C:

Results of virus scanning:

Files: 0
MBRs: 2
Boot sectors: 4
Objects scanned: 1
Infected: 1
Suspicious: 0
Disinfected: 0
Deleted: 0
Renamed: 0

Time: 0:08

 >> Stay informed about: F-PROT for DOS: anomily ? 
Back to top
Login to vote
Zvi Netiv

External


Since: May 01, 2005
Posts: 170



(Msg. 2) Posted: Sun May 01, 2005 4:04 pm
Post subject: Re: F-PROT for DOS: anomily ? [Login to view extended thread Info.]
Archived from groups: alt>comp>virus (more info?)

news RemoveThis @absamail.co.za wrote:

> Hi,
> I've had Russian_Flag.A virus in my several [old ] PCs, and in many
> fd0s. I thought F-PROT had solved the problem, but it kept on
> returning unexpectedly, when I use DOS [for transporting linux
> and Oberon-S3 orginated files] for printing.
>
> Only now, on closer analysis did I noticed the message:
> "Unable to remove the virus. ",
> which I had apparently just been skipping over previously !

Russian_flag is an old boot/MBR infector. It activates on August 20 and
displays the russian flag, from which it draws its name. RF uses int 13 stealth
and relocates the uninfected MBR to logical sector 8 (0/0/9 CHS). F-Prot for
DOS detects Russian-flag only when inactive, i.e. from clean boot, and misses it
totally otherwise (which may explain part of your findings).

> How/why can this particular copy of the virus not be removable,
> when F-PROT ANTIVIRUS v3.14e removed many from fd0s & hdx1s
> previously [ Always Russian_Flag.A virus ] ?

The way F-Prot removes this particular virus is by restoring the uninfected MBR
from logical sector 8. A possible reason for which F-Prot cannot clean a
particular instance is because it does not find the relocated MBR where it
expects it to be. Such condition could be created by mirroring the boot drive,
rather than by spontaneous infection. The only way to contract this virus is by
attempting to boot of an infected floppy.

> Equally confusing is that when I set:
> find virus in "Local hard disk[s]", it finds the virus on /dev/hda1 [DOS C:]
> and finds that /dev/hdc1 [DOS D:] is OK.
> But when I set C: & D: individually as the 'check for virus' devices, it
> passes both without finding any virus. The logs below show results.

You gave quite many details, but fail providing the important ones. Wink Like
under what conditions your tests were conducted (e.g. external boot from floppy
or self boot of the hard drive? Under what OS?). A possible reason for the
ambiguous results could be self boot from an infected drive (and a blind
F-Prot). Moreover, Russian_flag only affects the PHYSICAL boot drive (drive 128
in BIOS notation). Logical drives (C, D, etc.) have nothing to do with that,
although F-Prot is supposed to check the MBR unless you used the /NOBOOT switch.

Removal/cleaning:

For the 101th time: Antivirus programs are NOT to be used for the removal of
boot infectors. They may sometimes work, but in many instances you risk losing
access to the drive and its content, especially if running under W2K or XP.

If running under Win 9x/Me, get yourself a DOS boot floppy, preferably made
under Windows 98 ( www.invircible.com/iv_tools.php#makeresq ) and boot from.
From the A: prompt, run FDISK /STATUS You should see a list of allocated
partitions and logical drives. Continue with the next step only if the "status"
command yields sensible data (that you know to be correct). Run then FDISK /MBR
and the virus should be gone.

Lastly, since Russian_flag reappears on your drives, that means that you may
have [an] infected boot floppy[ies]. Get
www.invircible.com/iv_tools.php#fixboot and process your floppies with.

> Thanks for any information explaining these strange results.

Not strange at all.

Regards, Zvi
--
NetZ Computing Ltd. ISRAEL www.invircible.com www.ivi.co.il (Hebrew)
InVircible Virus Defense Solutions, ResQ and Data Recovery Utilities

 >> Stay informed about: F-PROT for DOS: anomily ? 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Run F-PROT for DOS from CD? - Can I run F-PROT for DOS from a CD? ISTR that F-PROT for DOS filled 2 diskettes and probably now needs 3 diskettes. So I would prefer to burn a CD and run it from there. Does anyone know if this works?

F-Prot for Dos on XP - Hi, please forgive a possibly stupid Question. Before switching to WinXP I just got used to F-Prot for Dos. I think it's usefull to scan now and then before starting the OS. Now with WinXP I do miss this opportunity. Installing Win 98 just for F-Prot....

F-Prot for DOS - what are sign2.def and fssign2.def differ.. - Any F-Prot users out there who might be able to clear up some confusion for me about the files sign2.def and fssign2.def? I noticed some time ago that the file sign2.def no longer seemed to be updated on the fsecure site that I use for regular definitio...

F-PROT for DOS and WINXP - I understand WINXP only has a SIMULATED DOS mode. I do not run WINXP so I am asking for a friend who does use XP. Can F_PROT for DOS virus scanner be used on a PC running WINXP? Is F_PROT FOR DOS effective running from WINXP SIMULATED DOS mode? I find i...

NTFS, F-Prot like scanner - Is there a virsus scanner that anyone knows of that scans a NTFS volume before Windows loads?
   Security Forums (Home) -> F-PROT All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]