A
Art
Addendum:
After submitting another two infected installation packages, I received the
following feedback this AM....
"I understand your concern and will pass along your feedback to the Engine team.
In the meantime, On Access scanning provides protection against those components
carried within the installer as soon as they hit the disk independently (prior to
execution)."
craig_schmugar<at>avertlabs.com
Uh huh. So far, I've determined that KAV, NOD32 and Bit Defender have
the extraction capability and can alert to multiple malwares within
install files (at least in some cases) when used on-demand. The plot
thickens (as usual) because of the "at least in some cases" clause. I
don't yet know whether or not scanner x fails to alert at all because
it can't decompress a particular install or if it simply doesn't have
detection of the included malwares. And there's the issue that some
av will have a sig for the install file itself. So evaluation is
rather involved. But what else is new? That's the way it goes.
Art
http://home.epix.net/~artnpeg
Free antivirus:
http://www.ik-cs.com/programs/virtools/KASFX.EXE
http://www.claymania.com/KASFX.EXE
http://tinyurl.com/azzkc