|
| |||||||||
| Tags: bombs, virusmalpacker, zip |
![]() |
| | Thread Tools | Search this Thread |
|
#1
| |||
| |||
| zip bombs and virus"Mal/Packer" I've just used the "multi av" scanner on my PC and run all the vendors with the exception of Sophos reporting *14 viruses "Mal/Packer" which all happen to be keygens for one thing or another. I'm pretty sure these were all false positives although They were automatically deleted. (Copied and pasted from David H. Lipman a googled post) "MAL/packer is Sophos' heuristic detection of Trojans using new compression agents known to be used by malware. Sophos will use this Heuristic detection until the Trojan is fully identified and a signature is created." So does this mean all keygens will give this response under Sophos? Also reported was 9 "Appears to be" zip bombs....(3) ".part" files (3) ".iso" (1) ".rar" (1) ".bin" and (1) ".avi" From my understanding zip bombs are made for disruption for AV Prog's and don't run any code or damage your machine is that right? I must determine whether or not these are false positives too, I understand extensions can be renamed to fool AV Progs, but I ran the .avi file, which indeed was a film so I'm sure that's a false positive, but for the rest how does one determine whether these are what Sophos reports as "Appears to be" zip bombs? http://en.wikipedia.org/wiki/Zip_bomb http://www.sophos.com/security/analyses/malpacker.html -- -- Regards p.mc |
|
#2
| |||
| |||
| Re: zip bombs and virus"Mal/Packer"
From: "p.mc" <nothanks.ok> | Hi there | | I've just used the "multi av" scanner on my PC and run all the vendors with | the exception of Sophos reporting *14 viruses "Mal/Packer" which all happen | to be keygens for one thing or another. I'm pretty sure these were all false | positives although They were automatically deleted. | | (Copied and pasted from David H. Lipman a googled post) | "MAL/packer is Sophos' heuristic detection of Trojans using new compression | agents known to | be used by malware. Sophos will use this Heuristic detection until the | Trojan is fully | identified and a signature is created." | So does this mean all keygens will give this response under Sophos? | | Also reported was 9 "Appears to be" zip bombs....(3) ".part" files (3) | ".iso" (1) ".rar" (1) ".bin" and (1) ".avi" From my understanding zip bombs | are made for disruption for AV Prog's and don't run any code or damage your | machine is that right? | I must determine whether or not these are false positives too, I understand | extensions can be renamed to fool AV Progs, but I ran the .avi file, which | indeed was a film so I'm sure that's a false positive, but for the rest how | does one determine whether these are what Sophos reports as "Appears to be" | zip bombs? | | http://en.wikipedia.org/wiki/Zip_bomb | | http://www.sophos.com/security/analyses/malpacker.html | | -- | Using the Sophos module it may declare a large ciompressed file such as a; ISO file, Ghost file or PST as a "Zip Bomb", This is most likely a False detection. Yep. that was a good quote and I affirm the quote on Sophos' gheuristic detection. Keygenerators are malware. I would say the "Zip Bomb" dection are mostly false. The Mal/packer detections may be righteous detections. Sophos now has a switch to disable the detection of "Zip Bombs" I al strongly considering implementing it. -- Dave http://www.claymania.com/removal-trojan-adware.html http://www.ik-cs.com/got-a-virus.htm |
|
#3
| |||
| |||
| Re: zip bombs and virus"Mal/Packer"
"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message news:ensszCQCHHA.4740@TK2MSFTNGP03.phx.gbl... > From: "p.mc" <nothanks.ok> > > | Hi there > | > | I've just used the "multi av" scanner on my PC and run all the vendors with > | the exception of Sophos reporting *14 viruses "Mal/Packer" which all happen > | to be keygens for one thing or another. I'm pretty sure these were all false > | positives although They were automatically deleted. > | > | (Copied and pasted from David H. Lipman a googled post) > | "MAL/packer is Sophos' heuristic detection of Trojans using new compression > | agents known to > | be used by malware. Sophos will use this Heuristic detection until the > | Trojan is fully > | identified and a signature is created." > | So does this mean all keygens will give this response under Sophos? > | > | Also reported was 9 "Appears to be" zip bombs....(3) ".part" files (3) > | ".iso" (1) ".rar" (1) ".bin" and (1) ".avi" From my understanding zip bombs > | are made for disruption for AV Prog's and don't run any code or damage your > | machine is that right? > | I must determine whether or not these are false positives too, I understand > | extensions can be renamed to fool AV Progs, but I ran the .avi file, which > | indeed was a film so I'm sure that's a false positive, but for the rest how > | does one determine whether these are what Sophos reports as "Appears to be" > | zip bombs? > | > | http://en.wikipedia.org/wiki/Zip_bomb > | > | http://www.sophos.com/security/analyses/malpacker.html > | > | -- > | > > > Using the Sophos module it may declare a large ciompressed file such as a; ISO file, Ghost > file or PST as a "Zip Bomb", This is most likely a False detection. > > Yep. that was a good quote and I affirm the quote on Sophos' gheuristic detection. > Keygenerators are malware. > > I would say the "Zip Bomb" dection are mostly false. The Mal/packer detections may be > righteous detections. > > Sophos now has a switch to disable the detection of "Zip Bombs" I al strongly considering > implementing it. > > -- > Dave > http://www.claymania.com/removal-trojan-adware.html > http://www.ik-cs.com/got-a-virus.htm > > Thank's Dave BTW I've responded in a.c.v too. -- Regards p.mc |
![]() |
|
| Thread Tools | Search this Thread |
| |
Similar Threads for: "zip bombs and virus"Mal/Packer"" | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Power Mgt: "Turn off monitor" "Never" always reverts to "After 20 mins" | OpaPiloot | Windows XP Video | 3 | 25-06-2009 04:49 AM |
| Vista not wotking with "My Computer" or "Control Panel", "Screen Saver" | Platebanger | Vista Help | 6 | 05-02-2008 08:24 PM |
| Adding commands to "Folder Options/Edit File Type/Actions" grayed-out "Edit" & "Remove" | Green_XP | Customize XP | 1 | 06-11-2007 02:18 PM |
| msiexec.exe Application Error "The instruction at "0x00f33fe8" referenced memory at "0x00f33fe8". The memory could not be "written"." | Edward Ray | Office Setup | 5 | 28-07-2005 01:25 AM |
| KAV "Kaspersky Anti-Virus" Causes Blue Screen "no_more_irp_stack_locations" | Brandon | AntiVirus Software | 6 | 16-03-2004 07:32 AM |