digitalFAQ.com Forums [Archives]

digitalFAQ.com Forums [Archives] (http://www.digitalfaq.com/archives/)
-   Computers (http://www.digitalfaq.com/archives/computers/)
-   -   Virus Scan this file please. (http://www.digitalfaq.com/archives/computers/10118-virus-scan-file.html)

Prodater64 06-06-2004 09:41 AM

Virus Scan this file please.
 
Hi: rds_correia told me that this file (not zipped) trigered his AV program, reporting it a trojan.
Now I have zipped the file, can somebody tell me if an AV program point at it as a trojan. Thank you.


Edited JUL/02/2004 Test finished. Link withdrawned.


--------------------------
Visit: Intermediate guide: MencodeMe/Win32 - Avisynth - MakeAvis by Prodater64.
Visit: KVCD - MencodeMe - Auxiliar Task - KVCD Docking Gate by Prodater64.
Visit: Mencoder scripting with AVSEdit and Guide for Multiple Files by Prodater64.
Visit: Mini-guide quick and easy - DVD to (S)KVCD with MencodeMe by Maurus.
Visit: Mencode-me: a newbie oriented GUI - 0.23 is out! by VMesquita.
--------------------------

rds_correia 06-06-2004 09:51 AM

Hi Pro,
Now that it's zipped I were allowed to download it but then I made a scan on the zipfile and again the AV program detected Trojan Digarix.B.
Can somebody test this too please?
Cheers

bigggt 06-06-2004 10:12 AM

Hi i have never had this before but i get this message

http://www.digitalfaq.com/archives/error.gif

Dialhot 06-06-2004 11:46 AM

Quote:

Originally Posted by rds_correia
Hi Pro,
Now that it's zipped I were allowed to download it but then I made a scan on the zipfile and again the AV program detected Trojan Digarix.B.
Can somebody test this too please?
Cheers

Do you have Sophos ?
definitely a mistake of the scanner as you can see in the descrription of the virus :
Quote:

Description
Troj/Digarix-B is a multi-partite IRC backdoor Trojan.

The Trojan arives as a self extracting archive file cab32.exe that drops the following files:

\echo.txt
\windows\Rar.exe
\windows\backs.exe
\windows\cabscan.dll
\windows\dd4a.exe
\windows\dx32a.exe
\windows\inst.exe
\windows\mirc.hlp
\windows\msnmsgr.exe
\windows\pv.exe
\windows\repair\cabscan\fix\cabscan.dll
\windows\sleep.com
\windows\system32\cab\Rar.exe
\windows\system32\cab\TzoLibr.dll
...
http://www.sophos.com/virusinfo/anal...jdigarixb.html

Definitely NOT what can be done by the little tiny file send by Pro64 ;-)

fabrice 06-06-2004 02:18 PM

Hi,

Tested with McAfee, and nothing detected...

CU
Fabrice

Zyphon 06-06-2004 02:45 PM

Hi Por,

I tested this file with AVG Free Ver 6 and it detected the virus Qghosts.A

So I havent extracted the contents in the zip for fear of infection.

I hope this info can help you out Pro.

Dialhot 06-06-2004 03:29 PM

There is NO infection in this you can be sure about this.

Hydeus 06-06-2004 03:55 PM

Quote:

c:\documents and settings\administrator\desktop\mncsamplepreview.zi p>MNCSamplePreview.exe - Win32.BWG dropper.
CA E-trust Antivirus: todays signature

Phil, this was youre 5555 post :lol:

Prodater64 06-06-2004 04:03 PM

Quote:

Originally Posted by Dialhot
There is NO infection in this you can be sure about this.

I generated that exe with a bat2exe program.
Could be that this program infected my batch file in some way.
If not, is a AV bug or fail.

Dialhot 06-06-2004 04:17 PM

Quote:

Originally Posted by Prodater64
Could be that this program infected my batch file in some way.

It's always possible but the virii reported on your files are 1: completlty different one from the other - 2/ completly out of possibility allowed by a 28 kb (valid :!:) zip file .

Quote:

If not, is a AV bug or fail.
Yes it is. Your tool surel ygenerate something that is close to a real virus. A lot of virus, that's all.

Prodater64 06-06-2004 04:27 PM

Quote:

Originally Posted by Dialhot
Quote:

Originally Posted by Prodater64
Could be that this program infected my batch file in some way.

It's always possible but the virii reported on your files are 1: completlty different one from the other - 2/ completly out of possibility allowed by a 28 kb (valid :!:) zip file .

Quote:

If not, is a AV bug or fail.
Yes it is. Your tool surel ygenerate something that is close to a real virus. A lot of virus, that's all.

My Norton AV does not report it as a trojan or virus.


--------------------------
Visit: Intermediate guide: MencodeMe/Win32 - Avisynth - MakeAvis by Prodater64.
Visit: KVCD - MencodeMe - Auxiliar Task - KVCD Docking Gate by Prodater64.
Visit: Mencoder scripting with AVSEdit and Guide for Multiple Files by Prodater64.
Visit: Mini-guide quick and easy - DVD to (S)KVCD with MencodeMe by Maurus.
Visit: Mencode-me: a newbie oriented GUI - 0.23 is out! by VMesquita.
--------------------------

http://www.digitalfaq.com/archives/error.gif

kwag 07-05-2004 09:32 AM

@All,

I've been using AVG Anti Virus for quite a while, and now I can say it's crap :x
It hasn't detected viruses on my machine, and gives weird scans on my wife's machine.
On her machine, I was constantly getting a random popup virus warning from AVG, but on a full scan, nothing would be detected.
Well, I downloaded AntiVir from www.free-av.com and all I can say is 8O 8O :D :D :D
Give it a shot :!:
It detected several viruses on my machine, even on some .RAR files, which were never detected by AVG or Norton.

-kwag

Jellygoose 07-05-2004 03:28 PM

Quote:

Originally Posted by kwag
@All,

I've been using AVG Anti Virus for quite a while, and now I can say it's crap :x
It hasn't detected viruses on my machine, and gives weird scans on my wife's machine.
On her machine, I was constantly getting a random popup virus warning from AVG, but on a full scan, nothing would be detected.
Well, I downloaded AntiVir from www.free-av.com and all I can say is 8O 8O :D :D :D
Give it a shot :!:
It detected several viruses on my machine, even on some .RAR files, which were never detected by AVG or Norton.

-kwag

AntiVir is the software I'm using. www.free-av.de
very very useful, free, and they update very frequently! :wink:

Zyphon 07-05-2004 03:52 PM

Quote:

Originally Posted by kwag
@All,

I've been using AVG Anti Virus for quite a while, and now I can say it's crap :x
It hasn't detected viruses on my machine, and gives weird scans on my wife's machine.
On her machine, I was constantly getting a random popup virus warning from AVG, but on a full scan, nothing would be detected.
Well, I downloaded AntiVir from www.free-av.com and all I can say is 8O 8O :D :D :D
Give it a shot :!:
It detected several viruses on my machine, even on some .RAR files, which were never detected by AVG or Norton.

-kwag

Thanks Karl. I must have misssd this post. I get some weird results in AVG and I dont like the it doesnt intercept and scan rar and zip files straight after you have downloaded them like Norton does.

I shall give this program a shot. :D

rds_correia 07-05-2004 04:52 PM

Hey guys,
I forgot to mention this in the begining of the thread.
I used Trendmicro's PCCillin for quite some time but one day I started feeling that it was very CPU demanding for my old PIII machine.
So for the last few months before this thread was born I've been using Free-Av with very good results.
That is aside from this Digarix.B issue...
Ohter than that it really is very good reporting viruses inside zip/rar file that unbelievably pc-cillin didn't detect with the right options enabled 8O .
About the Digarix.B issue, it really must be a flaw in their virus signatures :lol:
Cheers

bigggt 07-05-2004 05:22 PM

Hi guys i have been using AVG for ever now also and i think even on screensavers(tv show) they say it is one of the best

but lately i have been hearing bad things about it

maybe its time to switch

vmesquita 07-05-2004 05:46 PM

I've been using AVG also. I'll give AntiVir a try. :wink:

black prince 07-06-2004 07:22 AM

Let me second that Kwag, for problems with AVG. I just downloaded AntiVir
and will give it a try. I have Norton AV, but renewal of subscription is
getting near. 8)

Thanks

-BP

bigggt 07-08-2004 07:06 PM

Hi

Just wondering what the results are with people that have switched from AVG

Are you happy with the new program

I still am yet to try

kwag 07-08-2004 08:33 PM

Quote:

Originally Posted by bigggt
Are you happy with the new program

:ole:

kwag 07-09-2004 11:03 AM

This program is just wonderful :D
I'm getting about 10 E-Mails a day with attached viruses (probably from people that love me :lol: ) and the program just detects EVERYTHING :mrgreen:
I'm actually saving the viruses on the vault, so when I have a little time, I'll return the viruses to the originators. ( I have all the trace back headers on some :cool: ) :rotf:

-kwag

Dialhot 07-09-2004 11:16 AM

Quote:

Originally Posted by kwag
I have all the trace back headers on some :cool: ) :rotf:

Hum hum... Don't you know a lot of viruses use zombie machine as post relay ?
More, in email as in real life, how to eradicate a virus ? By destroying ALL the instances. One source is enought to contiminate the whole planet.
By sending back a virus to someone you just jeopardize the whole Internet ! Just think about that.

kwag 07-09-2004 06:43 PM

Quote:

Originally Posted by Dialhot
Hum hum... Don't you know a lot of viruses use zombie machine as post relay ?

Some are relayed, and some are stupid people that don't know what they are doing, and theiy can be traced back ;)
Quote:

More, in email as in real life, how to eradicate a virus ? By destroying ALL the instances. One source is enought to contiminate the whole planet.
As long as Microsoftr exists, we will always have computer viruses :lol:
Quote:

By sending back a virus to someone you just jeopardize the whole Internet ! Just think about that.
I guess I'll go back to my BSD E-Mail client, which just won't care about the MS attachments :cool:
That way I don't have to worry, and I don't even need an anti virus.
I might just do that :!:

-kwag

Dialhot 07-09-2004 06:52 PM

Quote:

Originally Posted by kwag
I guess I'll go back to my BSD E-Mail client, which just won't care about the MS attachments :cool:

I thought you were on thunderbird 8O
Firefox + thunderbird. Who need others ? ;)

kwag 07-09-2004 07:49 PM

Quote:

Originally Posted by Dialhot
Quote:

Originally Posted by kwag
I guess I'll go back to my BSD E-Mail client, which just won't care about the MS attachments :cool:

I thought you were on thunderbird 8O

I am :!:
Quote:

Firefox + thunderbird. Who need others ? ;)
Nobody :lol:
But the fact is that even if you use Thunderbird on WIn$ows, the viruses can still trigger, if you don't have a good antivirus.
On BSDs, any M$ virus is just a binary joke file :D

-kwag

rds_correia 07-11-2004 08:59 AM

Quote:

Originally Posted by kwag
On BSDs, any M$ virus is just a binary joke file :D

Hi Karl,
Then I should assume that those new *nix Antivirus programs were made to deal with real *nix threats only, am I right?
I thought that *nix viruses were myths...
Cheers

Dialhot 07-11-2004 10:07 AM

Quote:

Originally Posted by rds_correia
I thought that *nix viruses were myths...

There are Virus for cellular phones now ! Any operating system has its viruses.

Note: M$ recently bought the most important anti-virii editor on linux !

kwag 07-11-2004 10:47 AM

Quote:

Originally Posted by rds_correia
Hi Karl,
Then I should assume that those new *nix Antivirus programs were made to deal with real *nix threats only, am I right?
I thought that *nix viruses were myths...
Cheers

They are myth, as long as you are running as a regular user, and not as super user.
I always run my BSD box as my user name, and only log on as "root" to do maintenance. So if I download some weird virus (I have NEVER seen any viruses on FreeBSD, by the way), and it screwes up the system, it would only mess up my personal "home" directory and everything below it. None of the system files will get screwed up, because of the *nix permissions. :)

-kwag


All times are GMT -5. The time now is 08:03 AM  —  vBulletin © Jelsoft Enterprises Ltd

Site design, images and content © 2002-2024 The Digital FAQ, www.digitalFAQ.com
Forum Software by vBulletin · Copyright © 2024 Jelsoft Enterprises Ltd.