Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-virus software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 20th, 2002, 11:03 AM
puff-m-d's Avatar
puff-m-d puff-m-d is online now
Massive Poster
 
Join Date: Feb 2002
Location: North Carolina, USA
Posts: 3,638
Default F-PROT for DOS

Hello all,

I use Eset NOD32 as my primary avp and was trying out F-PROT for DOS as a secondary or backup scanner. *The problem that I am having is no matter how I configure it, it only scans about 4000 files. *I have around 65,000 files on my system though. *I tell it to do a dumb scan (which supposedly means all file extensions?) and to scan all of my C drive. *Am I doing something wrong or will F-PROT for DOS not scan my entire hard drive?

Eagerly awaiting whatever I am missing,
Kent
__________________
Best regards,
Kent

AX64 Time Machine - Travel in Time
Current Version 1.1.0.996
  #2  
Old March 20th, 2002, 08:33 PM
Tinribs's Avatar
Tinribs Tinribs is offline
Frequent Poster
 
Join Date: Mar 2002
Location: England
Posts: 734
Default Re: F-PROT for DOS

I presume you've configured it to scan packed and archived files also?
__________________
A proud member of Wilders since March 2002
  #3  
Old March 20th, 2002, 08:42 PM
wizard's Avatar
wizard wizard is offline
Frequent Poster
 
Join Date: Feb 2002
Location: Europe - Germany - Duesseldorf
Posts: 818
Default Re: F-PROT for DOS

Which file system do you use? NTFS or FAT32?

There is a problem with NTFS when you try to scan your hard drive. Any folders you enter will be scanned correct but not the whole harddrive. I think it is not a F-Prot issue but a limitation of NTFS or Win2k, WinXP operating system. From my research I found the following solution:

If you have a Win9x computer or maybe one of your friends has one: format a diskette with the option to 'boot' the diskette. I think you need at least two maybe three diskettes to install F-Prot for DOS on them. Only the first diskette needs be formated as a 'boot diskette'. Install F-Prot for DOS and check documentation for how to do or ask me and I will look which files you need.

So now you can scan your computer with the help of that boot diskettes. This method has one advantage: If a virus is already active in your system it might can 'fool' your anti virus to find it. If you boot from clean diskettes the virus is inactive and can be recognized easier.

Then go to http://www.sysinternals.com They offer a free tool which allows to access NTFS files from MS DOS. Download it and put the files on the first diskette. Maybe you should create an autoexec.bat to start and put the ntfs command in it.

And there is a very good hint for F-Prot for DOS users: If you start F-Prot for DOS with the option /AI it actives a very strong heuristic feature for detecting Win32 viruses. I tested it yesterday with some Win32 viruses:
With this special heuristic you get more than the double detection rate as with the normal heuristic option on 'unknown' Win32 viruses. Before anybody gets concerned about undetected viruses: I used an old signature file to test the heuristic feature. Samples were detected with the latest signature file.

wizard

__________________
wizardRESEARCH - Malware Research & Analysis since 1989
  #4  
Old March 20th, 2002, 09:17 PM
puff-m-d's Avatar
puff-m-d puff-m-d is online now
Massive Poster
 
Join Date: Feb 2002
Location: North Carolina, USA
Posts: 3,638
Default Re: F-PROT for DOS

Hello all,

First of all I have the options checked as follows:
SEARCH: C:\*
ACTION: Report Only
FILES: "Dumb" scan of all files
Scan inside archives
Scan compressed executables
Scan subdirectories
Scan a normal system
List only infected files
Beep when a virus is found
Use hueristics

Secondly, I have Windows XP Home using FAT32.

I am beginning to think it is one of those obscure WinXP bugs?

Kent

__________________
Best regards,
Kent

AX64 Time Machine - Travel in Time
Current Version 1.1.0.996
  #5  
Old March 20th, 2002, 09:41 PM
wizard's Avatar
wizard wizard is offline
Frequent Poster
 
Join Date: Feb 2002
Location: Europe - Germany - Duesseldorf
Posts: 818
Default Re: F-PROT for DOS

Quote:
I am beginning to think it is one of those obscure WinXP bugs?

I do not have WinXP so I can not test it. Normaly also WinXP emulates a full ms dos. Also most of the old ms dos viruses still work in that command line inferface. So I see actually no problem why F-Prot does not work there. If viruses work an anti virus software should work too.

Can you test my tip with the diskettes? Leave the NTFS driver part out.

But your problem gives me an idea. I will do some research over the weekend and try to build an free alternative to create such boot diskettes without the need of Win9x and knowledge in creating such a boot diskette or writing a short tutorial for it. This should be based on an alternative MS DOS. There should be one or two available over the internet.

wizard

__________________
wizardRESEARCH - Malware Research & Analysis since 1989
  #6  
Old March 21st, 2002, 05:26 PM
puff-m-d's Avatar
puff-m-d puff-m-d is online now
Massive Poster
 
Join Date: Feb 2002
Location: North Carolina, USA
Posts: 3,638
Default Re: F-PROT for DOS

Wizard,

Sorry, but at current I have no access to a Win98 machine so I guess I will eagerlly await your response next week.

Thanks,
Kent
__________________
Best regards,
Kent

AX64 Time Machine - Travel in Time
Current Version 1.1.0.996
  #7  
Old March 28th, 2002, 05:05 PM
wizard's Avatar
wizard wizard is offline
Frequent Poster
 
Join Date: Feb 2002
Location: Europe - Germany - Duesseldorf
Posts: 818
Default Re: F-PROT for DOS

F-Prot for DOS works perfectly under FreeDOS scanning a NTFS (Win2k) partition. I will do tomorrow a test run on a WinXP computer. If that goes without problems I updload the disk image files somewhere.

wizard
__________________
wizardRESEARCH - Malware Research & Analysis since 1989
  #8  
Old March 28th, 2002, 05:52 PM
puff-m-d's Avatar
puff-m-d puff-m-d is online now
Massive Poster
 
Join Date: Feb 2002
Location: North Carolina, USA
Posts: 3,638
Default Re: F-PROT for DOS

Thanks for the reply and help....

I was beginning to think this was a dead thread. *In any case it seems I have a rare problem.

Kent
__________________
Best regards,
Kent

AX64 Time Machine - Travel in Time
Current Version 1.1.0.996
 

Wilders Security Forums > Security Products > other anti-virus software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 02:20 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums