PDA

View Full Version : DOS based Trojan Scanners?


polo
May 18th, 2002, 05:01 PM
Just wondering since there's DOS based virus scanners such as F-PROT or McAfee for DOS is there similar things for dedicated trojan scanners?

Did trojan scanners exist in the DOS/Win 3.1x era?

Checkout
May 18th, 2002, 05:09 PM
Good questions - I'm also interested in authoratitive replies here. *Just goes to show that, no matter how sophisticated M$ Windows is, is still no more than a DOS upgrade.

DrSeltsam
May 19th, 2002, 09:41 AM
There is a DOS Version of the IF3 Engine of ANTS 2.0, but no one was interested in. If you want i will make a dos version of IF5 (ANTS 3.0 Engine) :o).

wizard
May 19th, 2002, 09:47 AM
DiamondCS had also plans for a DOS trojan scanner. I do not know what happend to theses plans.

wizard

Jooske
May 19th, 2002, 10:22 AM
They'll give opportunity in the meantime to test other's products patiently so when theirs come, we are all really convinced immediately DCS's is best. Spares bunches of comparing questions and we know what to test and look for, people might even have commented and posted wish lists.

Paul Wilders
May 19th, 2002, 02:28 PM
Andreas,

{QUOTE-> If you want i will make a dos version of IF5 (ANTS 3.0 Engine) <-QUOTE}

That would be nice indeed! "One-floppy-sized"?

Regards,

paul

snowman
May 19th, 2002, 05:03 PM
* * *just a FYI.....an don't expect much cause I am just waking up

* * * several weeks ago I opened a thread titled (other scanners) * its somewhere around the forums...maybe under software......hey..I"m working that first cup of coffee......

* * * anyway...there were several DOS scanners at the listed site......most were free.....some detect 30.000 to 37.000 sig's........one even claims to detect "morph"

* * * * * * * * * * * * * * * *snowman

snowman
May 19th, 2002, 05:09 PM
* * * *Question if I may....I was of the impression that DOS scanners would not work properly on w2k and XP...can someone please advise.....I am on w98 but still would like to know.......thank you.


* * * * * * * * * * * * snowman

wizard
May 20th, 2002, 09:13 AM
The problem with DOS scanners on Win2k, WinXP is the NTFS filesystem. When using FAT32 filesystem instead there are no problems with DOS scanners. When using NTFS there is a small tool that allows to access NTFS drives read only. It can be downloaded from
http://www.sysinternals.com . But using FAT32 is still the best solution.

wizard

snowman
May 20th, 2002, 12:24 PM
* * * * Wizard

* * * * * thank you for replieing.....appreciated.

* * * * * * * * * *snowman

DrSeltsam
May 20th, 2002, 04:46 PM
i think about 50 kb of size for the scanner itself. the problem will be the databases. if i only add the "backdoor", "trojans" and "worms" database, then it will be about 250 kb. with clients and server editors and 0190 dialers and so on about 1.5 MB :o).

DrSeltsam
May 20th, 2002, 04:52 PM
@Jooske:

Kings can be brought down ;o). I think it would be a very very interesting match - TDS-4 vs. ANTS 3.0 - this summer ;o).

Paul Wilders
May 20th, 2002, 06:08 PM
Andreas,

{QUOTE-> i think about 50 kb of size for the scanner itself. the problem will be the databases. <-QUOTE}

Guessed so.

{QUOTE-> if i only add the "backdoor", "trojans" and "worms" database, then it will be about 250 kb. with clients and server editors and 0190 dialers and so on about 1.5 MB :o). <-QUOTE}

Still looking forward to it.

{QUOTE-> I think it would be a very very interesting match - TDS-4 vs. ANTS 3.0 <-QUOTE}

Nothing wrong with a healthy competition *;)

regards.

paul *

UNICRON
May 20th, 2002, 06:17 PM
Almost as exciting as Olympic Hockey!

It would probably be more exciting than olympic hockey if Canada's olympic hockey teams (mens and womens) didn't kick so much @ss.


Guess that is why the boys earn a collective 250 million/ year workin at their day jobs ;)

wizard
May 20th, 2002, 07:48 PM
{QUOTE-> with clients and server editors and 0190 dialers and so on about 1.5 MB :o).
<-QUOTE}

Time to sort the garbage out. ;) Why is the database that big? This nearly the size of the F-Prot database and the F-Prot database include much more malware signatures.

wizard

Paul Wilders
May 20th, 2002, 07:54 PM
wizard,

{QUOTE-> Why is the database that big? <-QUOTE}

Let me guess: drop the clients (first) and the dailers - and see what happens *;).

regards.

paul

DrSeltsam
May 20th, 2002, 08:22 PM
About 70.000 signatures, Wizard :o). ANTS 3.0 detects about 200.000 Dialers for example :o).

ANTS 3.0 includes about 10.000 signatures of "real malware" (trojans, worms, backdoors and so on), 5.000 Malware Related Tools, 55.000 dialers and about 50.000 virus signatures :o).

The virus engine isn't dos compatible, so they are only the 70.000 "other" signatures :o). I think is i drop the malware related tools and the dialers the dos scanner has a size of about 250 kb :o).

Technodrome
May 22nd, 2002, 10:00 AM
I am really exciting about upcoming ANTS 3.0! Can't wait to get my hands on it!!! *8)

Still DOS version would be nice to have. Just in case !

Technodrome

DrSeltsam
May 22nd, 2002, 10:17 AM
Rokop is prepaering a new test. He will also test the ANTS 3.0 engine. Just by the way ;o). I am very interesting to see the results.

Paul Wilders
May 22nd, 2002, 11:33 AM
{QUOTE-> Rokop is prepaering a new test. He will also test the ANTS 3.0 engine. Just by the way ;o). I am very interesting to see the results. <-QUOTE}

Decided to let the world know after all, Andreas? *;D

Looking forward to the results as well.

regards.

paul