O
optikl
Are you insane?Bob said:When people find out that WinME is just rebranded Mac OS, they will
sing a different tune.
Are you insane?Bob said:When people find out that WinME is just rebranded Mac OS, they will
sing a different tune.
Actually, that's likely planned, to reduce the overhead of scanning
compressed files. You might want to review this writeup from Virus
Bulletin (see section on near misses). It describes the issue:
Huh? Could you be more specific how it's a rebranded Mac OS? You
perked my curiosity.
Are you insane?
What's in a Name? said:lol@bob+heather
I am going to have to write those down.
lmao
Bob said:Unfortunately it did not perk your humor.
Nevermind - this is not an issue that lends itself to attempts at
subtle humor.
Bob said:Did you perform all the tests?
I did all of them and eTrust missed some on download. Here are the
results I got.
* eicar.com - detected before downloading.
* eicar.com.text - not detected but loaded into browser.
* eicar.com.zip - not detected but downloaded. Detected when manually
scanned unzipped.
* eicarcom2.zip - not detected but downloaded. Detected when manually
scanned unzipped.
That's not so good, is it.
That might explain most of his remarks!! (G)
Actually that "is" good. Other results could be termed false positives
for EICAR. )
Bob said:I am disappointed in CA AV for not at least trying to imitate McAfee,
which allows the user to select which kinds of files to scan
automatically.
With a 2.4 GHz machine and ATA133 drives, I can afford a little
"overhead" in scanning *everything* (except the pagefile).
Maybe eTrust users need to bring this glaring defect to the attention
of CA.
It's possible to configure an exclusions list with both the real-time
and on-demand scanners. It may take a bit more effort to exclude what
not to scan than to include what to scan, but it is an option if you
need or want selective scanning.
Bob said:Yes, I saw that and set it to exclude "pagefile.sys", although I do
not know if it would scan that if I did not exclude it.
But I want to make it scan *everything* except excluded files, which
includes non-executables which includes ZIP and other archive files. I
want that rule to be applied to real time and manual scans.
How do I do that?
It's necessary to create separate exclusion rules for the real-time and
on-demand scanners. Go into Scan Settings and under Exclusions, click
Modify for each scanner. Click Add, and if for example you want to
exclude all zip files, add the entry *.zip. Do the same for cab files
with *.cab, etc. As you've already seen with adding pagefile.sys to the
excludes list, you can also browse and add specific files, folders, or
partitions.
Bob said:Maybe eTrust users need to bring this glaring defect to the attention
of CA.
Bob said:I did that.
Now how do I make CA AV scan *everything* but exclusions?
As it is now, it won't scan ZIP files automatically.
AFAICT, the on-demand scanner scans everything, including zip files, and
excludes only what's in the excludes list. It appears that the
real-time scanner scans zip files when you attempt to extract the
contents. I downloaded the eicar zip files, which it allowed, but then
it flagged the contents (eicar.com) when I attempted to extract it. Why
do you think it doesn't scan zip files?
How is it a defect if the scanner is designed to function this way?
Bob said:I was expecting it to scan the zip file just like the executable,
namely, before I downloaded it. It is good to know that it will catch
it when I extract.
I like eTrust and I hope it works out. Thanks for your support.
Okay, I see now. Keep in mind that you always have the option to scan
the zip file before you extract the contents using the on-demand
scanner. For example, using the on-demand scanner, eTrust identifies
that the double zipped eicar is infected.