Welcome to SecurityForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

new to F-Prot

 
   Security Forums (Home) -> F-PROT RSS
Next:  Ping: Art - Some Help Needed - F-Prot  
Author Message
mike hagen

External


Since: Jul 06, 2003
Posts: 2



(Msg. 1) Posted: Sun Jul 06, 2003 12:19 pm
Post subject: new to F-Prot
Archived from groups: alt>comp>anti-virus (more info?)

I've got a boot sector file F-Prot (windows) can't figure out. It claims
it's "suspicious". Also hiberfil.sys and pagefil.sys are listed as
running and so not scannable either, whether in xp or from safe
mode/command prompt. Any steps to turn these off at the prompt?

I'm running XP and just switched to this antivirus after Nortons cut me
off from updates a month before it's subscription expired. ;( Have not
figured out all the ins and outs of F-Prot yet.

Any suggestions for IDing the boot sector thing? Any competing
antivirus that might scan boot sectors that I don't have to buy before I
try?

 >> Stay informed about: new to F-Prot 
Back to top
Login to vote
Nick FitzGerald

External


Since: Jul 03, 2003
Posts: 179



(Msg. 2) Posted: Mon Jul 07, 2003 11:26 pm
Post subject: Re: new to F-Prot [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"mike hagen" <mhagen.TakeThisOut@olympus.net> wrote:

> I've got a boot sector file F-Prot (windows) can't figure out. It claims
> it's "suspicious". ...

Is that exactly, precisely and all that it says?

If you want more help I think you should post the exact, _uninterpreted_
text of the "warning" that F-PROT gives you. (You see, for starters, the
boot sector is not a "file", so you're not really helping your efforts
here by guessing at what the words might mean and "describing" your
interpretation of them...).

> ... Also hiberfil.sys and pagefil.sys are listed as
> running and so not scannable either, whether in xp or from safe
> mode/command prompt. Any steps to turn these off at the prompt?

Of course.

Both files, for performance reasons, _must_ remain purely and solely under
the OS' control -- one is the "hibernate file" (where the contents of
memory are written and the state of the registers at the moment you choose
to hibernate the sytem are written) and the other is the swap file (where
the system writes the the "less used" contents of memory so it can act as
if your machine has more memory than is physically installed). The latter
is 120% critical during the machine's operation and the former for a few
seconds before it completes going into, and the few seconds while it
"recovers" from, hibernation -- both are sufficiently important that the
host OS will not allow either to be messed with by anything but itself and,
in teh case of the hiberfil.sys, some BIOS code.

> I'm running XP and just switched to this antivirus after Nortons cut me
> off from updates a month before it's subscription expired. ;( Have not
> figured out all the ins and outs of F-Prot yet.

Well, it seems one of the "ins and outs" of F-PROT compared to NAV is that
it warns you about _all_ files that are inaccessible to it scanning, rather
than hiding some (or most or all -- how will you ever know??) of such files
"because its developers think they known best"...

> Any suggestions for IDing the boot sector thing? Any competing
> antivirus that might scan boot sectors that I don't have to buy before I
> try?

You can try another AV, but F-PROT probably has close to the best boot
sector heuristics, so if something else (depending precisely what!) finds
nothing suspicious, that may simply tell you something about the quality
of that product's boot sector heuristics... Cool


--
Nick FitzGerald

 >> Stay informed about: new to F-Prot 
Back to top
Login to vote
mike hagen

External


Since: Jul 06, 2003
Posts: 2



(Msg. 3) Posted: Mon Jul 07, 2003 11:26 pm
Post subject: Re: new to F-Prot [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Nick FitzGerald wrote:
> "mike hagen" <mhagen DeleteThis @olympus.net> wrote:
>
>
>>I've got a boot sector file F-Prot (windows) can't figure out. It claims
>>it's "suspicious". ...
>
>
> Is that exactly, precisely and all that it says?
>
yep. That's exactly what it says. It also says it can't deal with a
file it can't id.

I'm following up on all the suggestions - thanks much!
 >> Stay informed about: new to F-Prot 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Run F-PROT for DOS from CD? - Can I run F-PROT for DOS from a CD? ISTR that F-PROT for DOS filled 2 diskettes and probably now needs 3 diskettes. So I would prefer to burn a CD and run it from there. Does anyone know if this works?

F-Prot for Dos on XP - Hi, please forgive a possibly stupid Question. Before switching to WinXP I just got used to F-Prot for Dos. I think it's usefull to scan now and then before starting the OS. Now with WinXP I do miss this opportunity. Installing Win 98 just for F-Prot....

F-Prot for DOS - what are sign2.def and fssign2.def differ.. - Any F-Prot users out there who might be able to clear up some confusion for me about the files sign2.def and fssign2.def? I noticed some time ago that the file sign2.def no longer seemed to be updated on the fsecure site that I use for regular definitio...

F-PROT for DOS and WINXP - I understand WINXP only has a SIMULATED DOS mode. I do not run WINXP so I am asking for a friend who does use XP. Can F_PROT for DOS virus scanner be used on a PC running WINXP? Is F_PROT FOR DOS effective running from WINXP SIMULATED DOS mode? I find i...

NTFS, F-Prot like scanner - Is there a virsus scanner that anyone knows of that scans a NTFS volume before Windows loads?
   Security Forums (Home) -> F-PROT All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]