Go Back   TechArena Community > Technical Support > Computer Help > Microsoft Windows Security > Security Virus
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read SiteMap

Tags: , ,

zip bombs and virus"Mal/Packer"

Security Virus


Reply
 
Thread Tools Search this Thread
  #1  
Old 15-11-2006
p.mc
 
Posts: n/a
zip bombs and virus"Mal/Packer"

Hi there

I've just used the "multi av" scanner on my PC and run all the vendors with
the exception of Sophos reporting *14 viruses "Mal/Packer" which all happen
to be keygens for one thing or another. I'm pretty sure these were all false
positives although They were automatically deleted.

(Copied and pasted from David H. Lipman a googled post)
"MAL/packer is Sophos' heuristic detection of Trojans using new compression
agents known to
be used by malware. Sophos will use this Heuristic detection until the
Trojan is fully
identified and a signature is created."
So does this mean all keygens will give this response under Sophos?

Also reported was 9 "Appears to be" zip bombs....(3) ".part" files (3)
".iso" (1) ".rar" (1) ".bin" and (1) ".avi" From my understanding zip bombs
are made for disruption for AV Prog's and don't run any code or damage your
machine is that right?
I must determine whether or not these are false positives too, I understand
extensions can be renamed to fool AV Progs, but I ran the .avi file, which
indeed was a film so I'm sure that's a false positive, but for the rest how
does one determine whether these are what Sophos reports as "Appears to be"
zip bombs?

http://en.wikipedia.org/wiki/Zip_bomb

http://www.sophos.com/security/analyses/malpacker.html

--

--


Regards
p.mc



Reply With Quote
  #2  
Old 16-11-2006
David H. Lipman
 
Posts: n/a
Re: zip bombs and virus"Mal/Packer"

From: "p.mc" <nothanks.ok>

| Hi there
|
| I've just used the "multi av" scanner on my PC and run all the vendors with
| the exception of Sophos reporting *14 viruses "Mal/Packer" which all happen
| to be keygens for one thing or another. I'm pretty sure these were all false
| positives although They were automatically deleted.
|
| (Copied and pasted from David H. Lipman a googled post)
| "MAL/packer is Sophos' heuristic detection of Trojans using new compression
| agents known to
| be used by malware. Sophos will use this Heuristic detection until the
| Trojan is fully
| identified and a signature is created."
| So does this mean all keygens will give this response under Sophos?
|
| Also reported was 9 "Appears to be" zip bombs....(3) ".part" files (3)
| ".iso" (1) ".rar" (1) ".bin" and (1) ".avi" From my understanding zip bombs
| are made for disruption for AV Prog's and don't run any code or damage your
| machine is that right?
| I must determine whether or not these are false positives too, I understand
| extensions can be renamed to fool AV Progs, but I ran the .avi file, which
| indeed was a film so I'm sure that's a false positive, but for the rest how
| does one determine whether these are what Sophos reports as "Appears to be"
| zip bombs?
|
| http://en.wikipedia.org/wiki/Zip_bomb
|
| http://www.sophos.com/security/analyses/malpacker.html
|
| --
|


Using the Sophos module it may declare a large ciompressed file such as a; ISO file, Ghost
file or PST as a "Zip Bomb", This is most likely a False detection.

Yep. that was a good quote and I affirm the quote on Sophos' gheuristic detection.
Keygenerators are malware.

I would say the "Zip Bomb" dection are mostly false. The Mal/packer detections may be
righteous detections.

Sophos now has a switch to disable the detection of "Zip Bombs" I al strongly considering
implementing it.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Reply With Quote
  #3  
Old 16-11-2006
p.mc
 
Posts: n/a
Re: zip bombs and virus"Mal/Packer"

"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:ensszCQCHHA.4740@TK2MSFTNGP03.phx.gbl...
> From: "p.mc" <nothanks.ok>
>
> | Hi there
> |
> | I've just used the "multi av" scanner on my PC and run all the vendors

with
> | the exception of Sophos reporting *14 viruses "Mal/Packer" which all

happen
> | to be keygens for one thing or another. I'm pretty sure these were all

false
> | positives although They were automatically deleted.
> |
> | (Copied and pasted from David H. Lipman a googled post)
> | "MAL/packer is Sophos' heuristic detection of Trojans using new

compression
> | agents known to
> | be used by malware. Sophos will use this Heuristic detection until the
> | Trojan is fully
> | identified and a signature is created."
> | So does this mean all keygens will give this response under Sophos?
> |
> | Also reported was 9 "Appears to be" zip bombs....(3) ".part" files (3)
> | ".iso" (1) ".rar" (1) ".bin" and (1) ".avi" From my understanding zip

bombs
> | are made for disruption for AV Prog's and don't run any code or damage

your
> | machine is that right?
> | I must determine whether or not these are false positives too, I

understand
> | extensions can be renamed to fool AV Progs, but I ran the .avi file,

which
> | indeed was a film so I'm sure that's a false positive, but for the rest

how
> | does one determine whether these are what Sophos reports as "Appears to

be"
> | zip bombs?
> |
> | http://en.wikipedia.org/wiki/Zip_bomb
> |
> | http://www.sophos.com/security/analyses/malpacker.html
> |
> | --
> |
>
>
> Using the Sophos module it may declare a large ciompressed file such as a;

ISO file, Ghost
> file or PST as a "Zip Bomb", This is most likely a False detection.
>
> Yep. that was a good quote and I affirm the quote on Sophos' gheuristic

detection.
> Keygenerators are malware.
>
> I would say the "Zip Bomb" dection are mostly false. The Mal/packer

detections may be
> righteous detections.
>
> Sophos now has a switch to disable the detection of "Zip Bombs" I al

strongly considering
> implementing it.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>


Thank's Dave

BTW I've responded in a.c.v too.

--


Regards
p.mc



Reply With Quote
Reply

  TechArena Community > Technical Support > Computer Help > Microsoft Windows Security > Security Virus


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Similar Threads for: "zip bombs and virus"Mal/Packer""
Thread Thread Starter Forum Replies Last Post
Power Mgt: "Turn off monitor" "Never" always reverts to "After 20 mins" OpaPiloot Windows XP Video 3 25-06-2009 04:49 AM
Vista not wotking with "My Computer" or "Control Panel", "Screen Saver" Platebanger Vista Help 6 05-02-2008 08:24 PM
Adding commands to "Folder Options/Edit File Type/Actions" grayed-out "Edit" & "Remove" Green_XP Customize XP 1 06-11-2007 02:18 PM
msiexec.exe Application Error "The instruction at "0x00f33fe8" referenced memory at "0x00f33fe8". The memory could not be "written"." Edward Ray Office Setup 5 28-07-2005 01:25 AM
KAV "Kaspersky Anti-Virus" Causes Blue Screen "no_more_irp_stack_locations" Brandon AntiVirus Software 6 16-03-2004 07:32 AM


All times are GMT +5.5. The time now is 05:30 AM.