PC Review


Reply
Thread Tools Rate Thread

Am I infected

 
 
Bart Bailey
Guest
Posts: n/a
 
      20th Jul 2003
Want to know if there are any exe or com infectors active on your
system?
Virus Trap 1.0 creates a set of two test files (exe & com) with known
crc values then executes them and compares the integrity before and
after to see if anything has attacked them.
The company that produced it (Diamond CS) no longer offers it on their
site for whatever reason, but it's available here:
http://teknoweb.asia-links.com/download/vtrap.exe
put it in a folder in your program files and create a link to it so you
can find it whenever you suspect something.

Another trick the miscreants use is to hijack your shell open command
for executables and have a seemingly innocent file be in fact an
executable.
There's an application that lists all file types that are registered
with executable extensions on your system, so you can see if there are
any "new" ones besides the usual ones (exe scr com bat pif)
It's called "List exe" and is available here:
http://www.misec.net/products/LExE.zip
Same as above, create folder and link.

Good luck

Bart
 
Reply With Quote
 
 
 
 
Zvi Netiv
Guest
Posts: n/a
 
      20th Jul 2003
Bart Bailey <(E-Mail Removed)> wrote:

> Want to know if there are any exe or com infectors active on your
> system?
> Virus Trap 1.0 creates a set of two test files (exe & com) with known
> crc values then executes them and compares the integrity before and
> after to see if anything has attacked them.


The concept is well known and was implemented in many AV products, Iris' and
Eliashim's eSafe, to mention two. One of the weak points of the above
implementation is the use of a static file and name, what makes it easy to avoid
by viruses. Many viruses now have a list of files to avoid.

> The company that produced it (Diamond CS) no longer offers it on their
> site for whatever reason, but it's available here:
> http://teknoweb.asia-links.com/download/vtrap.exe


The program isn't self contained. It requires the presence of a DLL
(MSVBVM60.DLL) not found on all systems.

Regards, Zvi
--
NetZ Computing Ltd. ISRAEL http://invircible.com (E-Mail Removed)
InVircible Virus Defense Solutions, ResQ and Data Recovery Utilities
E-mail sent in reply to this post will not be considered private and
will be answered in the newsgroup. Top posting is not appreciated!
 
Reply With Quote
 
Zvi Netiv
Guest
Posts: n/a
 
      20th Jul 2003
Frederic Bonroy <(E-Mail Removed)> wrote:

> Bart Bailey wrote:
>
> > Want to know if there are any exe or com infectors active on your
> > system?
> > Virus Trap 1.0 creates a set of two test files (exe & com) with known
> > crc values then executes them and compares the integrity before and
> > after to see if anything has attacked them.
> > The company that produced it (Diamond CS) no longer offers it on their
> > site for whatever reason [...]

>
> The reason could be that it's not particularly useful against stealth
> viruses,


Full stealth viruses, as we knew them for 16 bit DOS executables (e.g. Frodo),
do not exist for the more complex executable structures, such as NE (were used
under Windows 16 bit) and PE. It's impossible to conceal all the changes made
to a PE, when infecting it. At the time, CIH was claimed to use "stealth" as it
doesn't affect file size (it resides in the PE header, filling empty space), but
it isn't stealth at all and discloses its presence if you know where to look
for.

Regards, Zvi
--
NetZ Computing Ltd. ISRAEL http://invircible.com (E-Mail Removed)
InVircible Virus Defense Solutions, ResQ and Data Recovery Utilities
E-mail sent in reply to this post will not be considered private and
will be answered in the newsgroup. Top posting is not appreciated!
 
Reply With Quote
 
Bart Bailey
Guest
Posts: n/a
 
      20th Jul 2003
In Message-ID:<(E-Mail Removed)> posted on
Sun, 20 Jul 2003 17:57:48 +0300, Zvi Netiv wrote:

>Many viruses now have a list of files to avoid


Maybe that's why it always comes up negative ;-)

Bart
 
Reply With Quote
 
Bart Bailey
Guest
Posts: n/a
 
      20th Jul 2003
In Message-ID:<bfdor9$dhc7t$(E-Mail Removed)> posted on
Sun, 20 Jul 2003 11:53:54 +0200, Frederic Bonroy wrote:

>If you suspect a virus, use a virus scanner...


Of course!

Bart
 
Reply With Quote
 
Bart Bailey
Guest
Posts: n/a
 
      20th Jul 2003
In Message-ID:<bfdor9$dhc7t$(E-Mail Removed)> posted on
Sun, 20 Jul 2003 11:53:54 +0200, Frederic Bonroy wrote:

>> The company that produced it (Diamond CS) no longer offers it on their
>> site for whatever reason [...]

>
>The reason could be that it's not particularly useful against stealth
>viruses, viruses that avoid infecting goat files (I didn't look at these
>particular goat files, I'm just stating that such viruses exist),
>viruses that are not memory-resident and infect files only in the
>current
>directory or viruses that infect neither DOS .exe nor .com files...


Maybe that's why they no longer offer it,
gives a false sense of sterility?

Bart
 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Re: Can't find infected files, + Kazarr files infected, Can anyone please help Lanwench [MVP - Exchange] Windows XP General 2 13th Aug 2006 11:25 PM
Is my PC infected? feckit Security, Spyware and Viruses 13 1st Jun 2006 10:55 PM
Infected.... PotGuy Security, Spyware and Viruses 4 10th Dec 2005 12:49 PM
How to find out the(the first machine) source machine being infected of infected virus hon123456 Windows XP General 4 14th Jan 2005 02:52 PM
IE6 infected Eric Windows XP Internet Explorer 15 8th Dec 2004 06:53 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 07:36 AM.