Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-virus software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 28th, 2004, 02:59 PM
peakaboo peakaboo is offline
Frequent Poster
 
Join Date: Oct 2002
Posts: 377
Default McAfee failed Eicarcom2.zip

Not a big deal but surprised me that McAfee failed Eicarcom2.zip.

http://www.eicar.org/download/eicarcom2.zip

This is the one where eicar.com is zipped and then this zip is zipped.

I quess McAfee will unpack once but when it runs into a second zip it says nomas

Can anyone confirm this result for McAfee or is it just me?

[hr]

I ran another AV against this and it was able to catch Eicarcom2.zip and all other Eicar examples on their page:

http://www.eicar.org/anti_virus_test_file.htm

I'm deciding whether to completely dump Mcafee now, since my upgrade from 4160 scan engine to 4320 has a trial time limit (Console & Autodat updates no longer function, but right click Vscan works fine except as noted above.) I may just keep Mcafee around as an on demand Vscan backup.

  #2  
Old March 28th, 2004, 04:20 PM
Tinribs's Avatar
Tinribs Tinribs is offline
Frequent Poster
 
Join Date: Mar 2002
Location: England
Posts: 734
Default Re:McAfee failed Eicarcom2.zip

I dont run Mcafee but I fail to see the threat of a virus that is zipped up twice? To run (if it was real) this virus it would need you to uncompress the file twice ,at which Mcafee would've jumped in long ago.

To add these very deep scanning abilities could well hinder further development of the programme.
__________________
A proud member of Wilders since March 2002
  #3  
Old March 28th, 2004, 04:37 PM
peakaboo peakaboo is offline
Frequent Poster
 
Join Date: Oct 2002
Posts: 377
Default Re:McAfee failed Eicarcom2.zip

Appreciate your reply.

As I said no big deal.

I'm sure others who are more devious can figure a way to use a virus w/in an archive packed in an archive coupled with a Windows vulnerability and a process killer...

still like to know if anyone else using older or latest McAfee can confirm - just curious

[hr]

Also Tinribs, did your AV catch Eicarcom2.zip on scan? If not what AV are you using - if you want to PM me feel free.



  #4  
Old March 28th, 2004, 08:45 PM
VikingStorm VikingStorm is offline
Frequent Poster
 
Join Date: Jun 2003
Posts: 387
Default Re:McAfee failed Eicarcom2.zip

I use McAfee VS 7.1 Enterprise, it was detected after it was d/led into the internet temp folder (with that silly IE d/ling before you picking an option deal). So no problems here...
  #5  
Old March 28th, 2004, 09:33 PM
peakaboo peakaboo is offline
Frequent Poster
 
Join Date: Oct 2002
Posts: 377
Default Re:McAfee failed Eicarcom2.zip

thanks VikingStorm

sounds like your result was pretty good - since your Mcafee 7 had to unpack 2 archives to get to eicar.com and it did it real time in cache prior to your d/l option...

  #6  
Old March 29th, 2004, 05:11 AM
Mack Jones's Avatar
Mack Jones Mack Jones is offline
Regular Poster
 
Join Date: Jul 2003
Location: France
Posts: 174
Default Re:McAfee failed Eicarcom2.zip

McAfee 4.51 detected the files right after the DL box, and before it reaches my TEMP forlder.

http://nick.vallet.free.fr/samples/on-access.png

Please check if you scan "All Files" and "Compressed files" on-access.

http://nick.vallet.free.fr/samples/Config.png



  #7  
Old March 29th, 2004, 09:12 AM
notageek's Avatar
notageek notageek is offline
Very Frequent Poster
 
Join Date: Jun 2002
Location: Ohio
Posts: 1,597
Default Re:McAfee failed Eicarcom2.zip

Hi Peakaboo. My Mcafee found it. I'm running a download manager and McAfee set to scan after a download. I'm using McAfee 7.03 scan engine 4.3.20.
Attached Images
 
__________________
The mind is like a drunken monkey dancing on hot coals.
  #8  
Old March 29th, 2004, 11:10 AM
peakaboo peakaboo is offline
Frequent Poster
 
Join Date: Oct 2002
Posts: 377
Default Re:McAfee failed Eicarcom2.zip

Thanks all.

Well, I don't know why my version can't catch it, maybe due to the expiration of the trial on that new engine I upgraded to.

Right click VirusScan still enabled but system scan is disabled due to end of trial. Maybe the power lies in the stuff which is disabled.
Attached Images
 
  #9  
Old March 30th, 2004, 07:51 AM
bob_man_uk's Avatar
bob_man_uk bob_man_uk is offline
Regular Poster
 
Join Date: Jan 2004
Location: United Kingdom
Posts: 91
Default Re:McAfee failed Eicarcom2.zip

my MCAFEE product (V7 enterprise) doesnt pick it up at download but if I tried to open the zip it said I couldnt and brings up the box saying that it had found a virus.
  #10  
Old March 30th, 2004, 11:45 AM
peakaboo peakaboo is offline
Frequent Poster
 
Join Date: Oct 2002
Posts: 377
Default Re:McAfee failed Eicarcom2.zip

Quote:
quoting: bob_man_uk link=board=24;threadid=26044;start=0#msg152284 date=1080651096]
my MCAFEE product (V7 enterprise) doesnt pick it up at download but if I tried to open the zip it said I couldnt and brings up the box saying that it had found a virus.

bob_man_uk,

Thanks for this info.

If you get a chance dl eicarcom2.zip save it to a separate folder and right click the folder and select "Scan for Viruses"

see my gif above, scan and make sure "All files" is checked & "Compressed files" is checked.

Let me know if VirusScan catches this.
  #11  
Old April 1st, 2004, 07:55 AM
bob_man_uk's Avatar
bob_man_uk bob_man_uk is offline
Regular Poster
 
Join Date: Jan 2004
Location: United Kingdom
Posts: 91
Default Re:McAfee failed Eicarcom2.zip

yes it does
  #12  
Old April 1st, 2004, 11:21 AM
peakaboo peakaboo is offline
Frequent Poster
 
Join Date: Oct 2002
Posts: 377
Default Re:McAfee failed Eicarcom2.zip

Thank You for verifying.

maybe the problem is my 4320 engine... will check this out later.

seems more like an unpacking issue though, but maybe that is engine dependent also

  #13  
Old April 1st, 2004, 11:52 AM
bob_man_uk's Avatar
bob_man_uk bob_man_uk is offline
Regular Poster
 
Join Date: Jan 2004
Location: United Kingdom
Posts: 91
Default Re:McAfee failed Eicarcom2.zip

my engine is 4320 with the most up to date dat (Currently 4346) so i dunno whats up
  #14  
Old April 1st, 2004, 12:06 PM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,201
Default Re:McAfee failed Eicarcom2.zip

For what it is worth, F-Prot for Windows will detect this file when you try to download it before it is on your hard drive.
  #15  
Old April 1st, 2004, 12:31 PM
Randy_Bell's Avatar
Randy_Bell Randy_Bell is offline
Updates Team
 
Join Date: May 2002
Location: Santa Clara, CA
Posts: 3,053
Default Re:McAfee failed Eicarcom2.zip

Just saw this thread: screenshot is what happened here in Opera when I clicked on your link to the double-zipped eicar.
Attached Images
 
  #16  
Old April 1st, 2004, 04:06 PM
peakaboo peakaboo is offline
Frequent Poster
 
Join Date: Oct 2002
Posts: 377
Default Re:McAfee failed Eicarcom2.zip

Quote:
quoting: bob_man_uk link=board=24;threadid=26044;start=0#msg153728 date=1080838351]
my engine is 4320 with the most up to date dat (Currently 4346) so i dunno whats up

Interesting I just tried this test on a non timed out version of McAfee scan engine 4320 dat file was 4345 with the following result:

right click VirusScan (on demand scan) on folder with Eicarcom2.zip does not detect the eicar.com.

However using McAfee VirusScan Central console and scanning I get a detection, however when I go to delete it, it is unsuccessful (eventhough it says it is deleted). Trying again using quarantine same thing happens - successful quarantine message given, but checking with explorer I see the eicar.com still zipped. I wound up deleting using explorer.

This may dove tail into the latest VB100 bulletin and a weakness observed there:

http://www.wilderssecurity.com/showthread.php?t=26251;start=msg152429#msg152429

Sophos: No Support for On-Access scanning same happens to NAI including some archiv format problems


[hr]

thanks to all for your input

I maybe dumping this version of McAfee soon.
 

Wilders Security Forums > Security Products > other anti-virus software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 09:38 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums