I hardly see anything in here about Avast Antivirus, even though it
seems to be a great program that I have had no trouble with.
I will give you 'one' example of why I like Avast!
I DL'd a free but suspicious file. Avast alerted to a trojan,
which actually was 'spyware', a commercial trojan, but still
something I do NOT want on my computer. The parasite was an exe
within an exe but it couldn't hide from Avast. I find Virus, worms,
trojans, etc, are not difficult to avoid if you understand Safehex.
Spyware is more of a problem because there are 'few' preventives.
AdAware will tell you AFTER spyware is installed, which is too late.
SpybotSD and others have 'immunize' and SpyBlaster is great, but
most other protection uses valuable resources. Avast will not catch
all spyware but it can help without adding 'another' protective
device. End of rant.
I also tested the infected file with:
EZtrust
F-Prot for DOS
AVG
on-line scanners,
Trend Micro HouseCall:
http://housecall.antivirus.com/pc_housecall/
and
RAV AntiVirus Online Virus Scan
http://www.ravantivirus.com/scan/
and none alerted. I'm guessing Avast's heuristic scan picked up
on something involving the installation method, as the trojans
are not identified by name. Hurrah for Avast.
Although this is not the intended purpose of AVs, it is a plus
I like. If anyone would like to test 'their' AV, here are my
findings. DO NOT INSTALL the screensaver, just test the SS.exe.
This free program was listed in the alt.comp.freeware NG and
appeared to be a normal message. It's homesite is
www.acez.com. Note the 'Z' in the url, it's a clue.
Acez screensavers contain the commercial trojan, Incredifind.
Their HauntedHouse SS, is identified below, but SkyWriter SS is a
smaller DL, and contains the same infections for testing purposes.
Both were DL'd and Avast alerted on both.
Snooper was used to find 'what' Avast had alerted. It could have
been, but was NOT a 'false alert'.
* Halloween Haunting ScreenSaver
SETUP_POWERSEARCH_KV.EXEPK <
SETUP_INCREDIFIND_ONLY.EXEPK <---
VB6INSTALL.HTMPK
HAUNTED HOUSE HORRORS.SCRPK
HAUNTEDHOUSEEMAIL.EXEPK
ACEZHAUNTEDHOUSE.INIPK
Present HOSTS file entries below, should prevent the INCREDIFIND
parasite from calling out but does not prevent the installation.
POWERSEARCH_KV is 'probably' a NEW commercial trojan. It could
not be found in 'any' HOSTS file so it would try to call out and
perform it's spying mission. It would then be up to your firewall
to stop it. AdAware/SpybotSD/SpyBlaster status for POWERSEARCH_KV
is unknown to me.
127.0.0.1 incredifind.com #[KeenValue/Incredifind]
127.0.0.1
www.incredifind.com
Avast's alert:
C:\Hold\HauntSS\hauntedhouse.exe\SETUP_INCREDIFIND_ONLY.EXE
[L] Win32:Trojan-gen. {Other} (0)
C:\Hold\SkyWrite\skywriter.exe\SETUP_INCREDIFIND_ONLY.EXE
[L] Win32:Trojan-gen. {Other} (0)
Infected files: 2
I selected the virus vault in Avast and rechecked the DL with
Snooper. BOTH Incredifind and PowerSearch exe's were now
missing from the screensaver executable. I had however, lost
all interest in installing the screensavers.
You'll find the reference to KeenValue and PowerSearch here:
http://www.doxdesk.com/parasite/KeenValue.html who provide
the infecting programs. Very educational reading.
www.acez.com is not in any domain restricted sites list for IE,
but that is not unusual since as there are 'thousands' of such
sites on the internet.
If anyone finds ANY program, AV or otherwise that will detects
this parasite, PRIOR to installation, I would be interested in
feedback.
PS. Snooper will pull text from any type of file. Other similar
programs are Peek, ArcPeek, etc. Search in Google if you want one.
Great for that final check when nothing alerts, but you are 'still'
suspicious.
Being suspicious of ALL downloads does not mean you are paranoid,
it means you practice SAFEHEX.
http://www.claymania.com/safe-hex.html
BoB
For the duration of Swen, my address is inoperative.