Rocksolid Light

Welcome to Rocksolid Light

mail  files  register  newsreader  groups  login

Message-ID:  

"Never make any mistaeks." (Anonymous, in a mail discussion about to a kernel bug report.)


computers / microsoft.public.windowsxp.general / Virus Scanner

SubjectAuthor
* Virus ScannerMyName
+- Virus Scannerhardy
+- Virus ScannerVanguardLH
+- Virus ScannerPaul
+- Virus ScannerAmmammata
`* Virus ScannerMayayana
 `* Virus ScannerMyName
  `* Virus ScannerMayayana
   +* Virus ScannerMyName
   |`* Virus ScannerMayayana
   | `* Virus ScannerPaul
   |  `- Virus ScannerMayayana
   `- Virus ScannerSjouke Burry

1
Virus Scanner

<tj6ka3$3ug$1@gioia.aioe.org>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=3753&group=microsoft.public.windowsxp.general#3753

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!aioe.org!8ER4TMW3TSRnvS06aECo6g.user.46.165.242.91.POSTED!not-for-mail
From: MyName@NoSpam.com (MyName)
Newsgroups: microsoft.public.windowsxp.general
Subject: Virus Scanner
Date: Mon, 24 Oct 2022 11:08:05 -0700
Organization: Aioe.org NNTP Server
Message-ID: <tj6ka3$3ug$1@gioia.aioe.org>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Info: gioia.aioe.org; logging-data="4048"; posting-host="8ER4TMW3TSRnvS06aECo6g.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:52.0) Gecko/20100101 Firefox/52.0
SeaMonkey/2.49.5
X-Notice: Filtered by postfilter v. 0.9.2
X-Mozilla-News-Host: news://news.aioe.org:119
 by: MyName - Mon, 24 Oct 2022 18:08 UTC

Please advise on bet virus scanner for Win XP Pro SP3 32 bit.

I need to get this laptop working with some protection.

Please provide links.

I have tires some that say they are compatible but will not install
saying not compatible.

Thank you.

Re: Virus Scanner

<ahodlhtvp081756u5iq9bq25pjs6jklr6o@4ax.com>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=3755&group=microsoft.public.windowsxp.general#3755

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!feed1.usenet.blueworldhosting.com!peer03.iad!feed-me.highwinds-media.com!news.highwinds-media.com!fx12.iad.POSTED!not-for-mail
From: hardy@homerun.net
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: Virus Scanner
Message-ID: <ahodlhtvp081756u5iq9bq25pjs6jklr6o@4ax.com>
References: <tj6ka3$3ug$1@gioia.aioe.org>
X-Newsreader: Forte Agent 1.93/32.576 English (American)
X-No-Archive: yes
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Lines: 21
X-Complaints-To: https://www.astraweb.com/aup
NNTP-Posting-Date: Mon, 24 Oct 2022 19:10:00 UTC
Date: Mon, 24 Oct 2022 14:09:53 -0500
X-Received-Bytes: 1216
 by: hardy@homerun.net - Mon, 24 Oct 2022 19:09 UTC

On Mon, 24 Oct 2022 11:08:05 -0700, MyName <MyName@NoSpam.com> wrote:

>
>Please advise on bet virus scanner for Win XP Pro SP3 32 bit.
>
>I need to get this laptop working with some protection.
>
>Please provide links.
>
>I have tires some that say they are compatible but will not install
>saying not compatible.
>
>Thank you.

You might install this in the mean time until you get an AV.

I've used this program for years without any AV or other 'security
suite'. The only other security program I use on my XP is Sygate
Firewall to keep stuff from calling home.

https://www.toolwiz.com/lead/toolwiz_time_freeze/

Re: Virus Scanner

<n7y4hj6tp2lx.dlg@v.nguard.lh>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=3756&group=microsoft.public.windowsxp.general#3756

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!aioe.org!news.mixmin.net!news2.arglkargh.de!news.karotte.org!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: V@nguard.LH (VanguardLH)
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: Virus Scanner
Date: Mon, 24 Oct 2022 14:30:33 -0500
Lines: 24
Message-ID: <n7y4hj6tp2lx.dlg@v.nguard.lh>
References: <tj6ka3$3ug$1@gioia.aioe.org>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Trace: individual.net dI5YZ9PxVdONHwEYj4fbUgOna9xRiyEOTHAJxhQolgmovDyhWD
Cancel-Lock: sha1:pJ6hhRTS0N5En/f8OhBUTnyPfbc=
User-Agent: 40tude_Dialog/2.0.15.41
 by: VanguardLH - Mon, 24 Oct 2022 19:30 UTC

MyName <MyName@NoSpam.com> wrote:

> Please advise on bet virus scanner for Win XP Pro SP3 32 bit.
>
> I need to get this laptop working with some protection.
>
> Please provide links.
>
> I have tires some that say they are compatible but will not install
> saying not compatible.
>
> Thank you.

https://www.google.com/search?client=firefox-b-1-d&q=antivirus+windows+xp

Note: Avast acquired AVG.

Sorry, "some" doesn't say which you tried, so expect duplication of your
efforts to responses here. Typically using the standard download link
points to their latest version, not to one that works on older and
perhaps unsupported versions of the OS, and whose installer will reject
a too-old OS version. You may have to dig into their site to find older
version downloads that are XP compatible. Or you can see if an old
version that supports the old OS is available at oldversion.com.

Re: Virus Scanner

<tj8j8i$2036u$1@dont-email.me>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=3757&group=microsoft.public.windowsxp.general#3757

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: nospam@needed.invalid (Paul)
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: Virus Scanner
Date: Tue, 25 Oct 2022 08:02:27 -0400
Organization: A noiseless patient Spider
Lines: 69
Message-ID: <tj8j8i$2036u$1@dont-email.me>
References: <tj6ka3$3ug$1@gioia.aioe.org>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Tue, 25 Oct 2022 12:02:26 -0000 (UTC)
Injection-Info: reader01.eternal-september.org; posting-host="608e80e825d61598a0ded9502772485f";
logging-data="2100446"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19wFVMZIGXALC9vlUxNyjtmRKOnDjaZvRg="
User-Agent: Ratcatcher/2.0.0.25 (Windows/20130802)
Cancel-Lock: sha1:JKIkyqTXvWvVtBKSNSJUhT/oP/E=
In-Reply-To: <tj6ka3$3ug$1@gioia.aioe.org>
Content-Language: en-US
 by: Paul - Tue, 25 Oct 2022 12:02 UTC

On 10/24/2022 2:08 PM, MyName wrote:
>
> Please advise on bet virus scanner for Win XP Pro SP3 32 bit.
>
> I need to get this laptop working with some protection.
>
> Please provide links.
>
> I have tires some that say they are compatible but will not install saying not compatible.
>
> Thank you.

This article is three years old, and already you can see
the options are limited. It's possible none of these will
install any more.

https://appuals.com/the-5-best-antivirus-softwares-for-windows-xp/

Part of this is caused by staff getting new Visual Studio setups,
and those may be loading .NET into the executable, that WinXP
does not have. The .NET libraries, are just one of the
ways of "poisoning" programs against WinXP. There can also
be kernel checks, which when they detect WinXP, won't run.
The kernel checks can be in Microsoft code, not in the
application code.

Some products tell you right away, what the odds are.

https://support.eset.com/en/kb7292-microsoft-windows-support-policy-and-eset-products

As a Windows XP user, your ESET Windows home product has reached...

ESET NOD32 Antivirus, ESET Smart Security

Product version 9
End of Life date December 2019
Shutdown date September 28, 2022 [hidden protections like heuristics may stop]

The comments section in this article, tell you the situation is dire.
They probably have not updated the article, by trying to install these.

https://windowsreport.com/antivirus-windows-xp-service-pack-3/

While you can look at items like this, who has used this ???
Is it just ClamAV in disguise ?

https://www.totalav.com/

The free version of that, doesn't have realtime protection. The
free version is just an on-demand scanner. Like a ClamAV would be.

https://www.pcmag.com/reviews/totalav-essential-antivirus

ClamAV is hosted by Cisco Talos group. And is FOSS. The
definitions are things, that other AV companies would include
in their scanner. This would be an on-demand scanner, meaning
you can say "scan my C: drive", but it won't scan that dodgy
email attachment you just double-clicked. It does not provide
automatic real-time scanning of just-clicked EXE files.

https://www.clamav.net/

The cupboard is pretty bare. And the companies that might
support WinXP, may not be doing much more than ClamAV in
a sense. Unless AV-Comparatives makes a point of testing
Windows XP, we won't have a clue how good they are.

Paul

Re: Virus Scanner

<tj8jrd$v4l$1@solani.org>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=3758&group=microsoft.public.windowsxp.general#3758

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!reader5.news.weretis.net!news.solani.org!.POSTED!not-for-mail
From: ammammata@tiscali.it (Ammammata)
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: Virus Scanner
Date: Tue, 25 Oct 2022 14:12:28 +0200
Message-ID: <tj8jrd$v4l$1@solani.org>
References: <tj6ka3$3ug$1@gioia.aioe.org>
Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-15"; format=flowed
Content-Transfer-Encoding: 8bit
Injection-Date: Tue, 25 Oct 2022 12:12:29 -0000 (UTC)
Injection-Info: solani.org;
logging-data="31893"; mail-complaints-to="abuse@news.solani.org"
Cancel-Lock: sha1:KtWxRB4xT4UP7CJND/u+W+Dy+eo=
X-User-ID: eJwFwYkRwDAIA7CVHB5DxuFMs/8IldJ5qAomI1++YRvG17xeRCdq0pKyrnHsnFMDoyAFvo7QPcKVYfHt8gco2BSv
X-Newsreader: MesNews/1.08.06.00-gb
 by: Ammammata - Tue, 25 Oct 2022 12:12 UTC

MyName used his keyboard to write :
> Please advise on bet virus scanner for Win XP Pro SP3 32 bit.

well, on the last pc I had with windows xp, well after it was
discontinued, I installed Bitdefender
maybe the 32bit version is still available

--
/-\ /\/\ /\/\ /-\ /\/\ /\/\ /-\ T /-\
-=- -=- -=- -=- -=- -=- -=- -=- - -=-
............ [ al lavoro ] ...........

Re: Virus Scanner

<tj8ke5$20858$1@dont-email.me>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=3759&group=microsoft.public.windowsxp.general#3759

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: mayayana@invalid.nospam (Mayayana)
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: Virus Scanner
Date: Tue, 25 Oct 2022 08:21:17 -0400
Organization: A noiseless patient Spider
Lines: 14
Message-ID: <tj8ke5$20858$1@dont-email.me>
References: <tj6ka3$3ug$1@gioia.aioe.org>
Injection-Date: Tue, 25 Oct 2022 12:22:30 -0000 (UTC)
Injection-Info: reader01.eternal-september.org; posting-host="883da7f37b47a809bdc4fd2027e962c7";
logging-data="2105512"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+YY6oT6qVcdi1Ijl6Quc7Jc2bRgGjOxCk="
Cancel-Lock: sha1:JTrqBsTvRvNfKb6g0nWEs2FEOm8=
X-MSMail-Priority: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.5512
X-Newsreader: Microsoft Outlook Express 6.00.2900.5512
X-Priority: 3
 by: Mayayana - Tue, 25 Oct 2022 12:21 UTC

"MyName" <MyName@NoSpam.com> wrote
| | Please advise on bet virus scanner for Win XP Pro SP3 32 bit.
|

https://clamwin.com/

I also have some rootkit hunters and an MS malicious
software tool, but none are recent versions. Personally
I haven't used AV for about 20 years, except occasionally
when I get suspicious about something. So I don't know
about software that you leave running all the time.

Re: Virus Scanner

<tj9kac$9k5$1@gioia.aioe.org>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=3760&group=microsoft.public.windowsxp.general#3760

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!aioe.org!8ER4TMW3TSRnvS06aECo6g.user.46.165.242.91.POSTED!not-for-mail
From: MyName@NoSpam.com (MyName)
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: Virus Scanner
Date: Tue, 25 Oct 2022 14:26:36 -0700
Organization: Aioe.org NNTP Server
Message-ID: <tj9kac$9k5$1@gioia.aioe.org>
References: <tj6ka3$3ug$1@gioia.aioe.org> <tj8ke5$20858$1@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Info: gioia.aioe.org; logging-data="9861"; posting-host="8ER4TMW3TSRnvS06aECo6g.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:52.0) Gecko/20100101 Firefox/52.0
SeaMonkey/2.49.5
X-Notice: Filtered by postfilter v. 0.9.2
 by: MyName - Tue, 25 Oct 2022 21:26 UTC

So much for that.

I tried to download on two different PC and nothing happened when
clicking on download "Download the latest version here".

Mayayana wrote:
> "MyName" <MyName@NoSpam.com> wrote
> |
> | Please advise on bet virus scanner for Win XP Pro SP3 32 bit.
> |
>
> https://clamwin.com/
>
> I also have some rootkit hunters and an MS malicious
> software tool, but none are recent versions. Personally
> I haven't used AV for about 20 years, except occasionally
> when I get suspicious about something. So I don't know
> about software that you leave running all the time.
>
>

Re: Virus Scanner

<tj9rbv$28f16$1@dont-email.me>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=3761&group=microsoft.public.windowsxp.general#3761

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!aioe.org!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: mayayana@invalid.nospam (Mayayana)
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: Virus Scanner
Date: Tue, 25 Oct 2022 19:26:27 -0400
Organization: A noiseless patient Spider
Lines: 15
Message-ID: <tj9rbv$28f16$1@dont-email.me>
References: <tj6ka3$3ug$1@gioia.aioe.org> <tj8ke5$20858$1@dont-email.me> <tj9kac$9k5$1@gioia.aioe.org>
Injection-Date: Tue, 25 Oct 2022 23:26:55 -0000 (UTC)
Injection-Info: reader01.eternal-september.org; posting-host="909ab25c069b5dfd967926c3e45b7638";
logging-data="2374694"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19DuxKjMfVA718/C6o5Sx4Ac/1eBx5yyeQ="
Cancel-Lock: sha1:JGpCp28tgtyYMiz7HetotAohu6w=
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.5512
X-MSMail-Priority: Normal
X-Priority: 3
X-Newsreader: Microsoft Outlook Express 6.00.2900.5512
 by: Mayayana - Tue, 25 Oct 2022 23:26 UTC

"MyName" <MyName@NoSpam.com> wrote

| So much for that.
| | I tried to download on two different PC and nothing happened when
| clicking on download "Download the latest version here".
|

https://sourceforge.net/settings/mirror_choices?projectname=clamwin&filename=clamwin/0.103.2.1/clamwin-0.103.2.1-setup.exe&selected=cytranet

I don't even allow script and it works for me. I just clicked
the "Problem Downloading?" button where it says my download
has started. Then I clicked the "direct link" link near the top.

Re: Virus Scanner

<tjaldk$h26$1@gioia.aioe.org>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=3762&group=microsoft.public.windowsxp.general#3762

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!eternal-september.org!reader01.eternal-september.org!aioe.org!8ER4TMW3TSRnvS06aECo6g.user.46.165.242.91.POSTED!not-for-mail
From: MyName@NoSpam.com (MyName)
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: Virus Scanner
Date: Tue, 25 Oct 2022 23:51:23 -0700
Organization: Aioe.org NNTP Server
Message-ID: <tjaldk$h26$1@gioia.aioe.org>
References: <tj6ka3$3ug$1@gioia.aioe.org> <tj8ke5$20858$1@dont-email.me>
<tj9kac$9k5$1@gioia.aioe.org> <tj9rbv$28f16$1@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Info: gioia.aioe.org; logging-data="17478"; posting-host="8ER4TMW3TSRnvS06aECo6g.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:52.0) Gecko/20100101 Firefox/52.0
SeaMonkey/2.49.5
X-Notice: Filtered by postfilter v. 0.9.2
 by: MyName - Wed, 26 Oct 2022 06:51 UTC

Thanks.
Got it at the direct link.

Mayayana wrote:
> "MyName" <MyName@NoSpam.com> wrote
>
> | So much for that.
> |
> | I tried to download on two different PC and nothing happened when
> | clicking on download "Download the latest version here".
> |
>
> https://sourceforge.net/settings/mirror_choices?projectname=clamwin&filename=clamwin/0.103.2.1/clamwin-0.103.2.1-setup.exe&selected=cytranet
>
> I don't even allow script and it works for me. I just clicked
> the "Problem Downloading?" button where it says my download
> has started. Then I clicked the "direct link" link near the top.
>
>

Re: Virus Scanner

<nnd$122762a8$244cd333@878b46b016475057>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=3763&group=microsoft.public.windowsxp.general#3763

  copy link   Newsgroups: microsoft.public.windowsxp.general
Date: Wed, 26 Oct 2022 19:14:18 +0200
From: burrynulnulfour@ppllaanneett.nnll (Sjouke Burry)
User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:17.0) Gecko/20131118 Thunderbird/17.0.11
MIME-Version: 1.0
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: Virus Scanner
References: <tj6ka3$3ug$1@gioia.aioe.org> <tj8ke5$20858$1@dont-email.me> <tj9kac$9k5$1@gioia.aioe.org> <tj9rbv$28f16$1@dont-email.me>
In-Reply-To: <tj9rbv$28f16$1@dont-email.me>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Message-ID: <nnd$122762a8$244cd333@878b46b016475057>
Organization: KPN B.V.
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!newsreader4.netcologne.de!news.netcologne.de!peer03.ams1!peer.ams1.xlned.com!news.xlned.com!peer02.ams4!peer.am4.highwinds-media.com!news.highwinds-media.com!feed.abavia.com!abe004.abavia.com!abp002.abavia.com!news.kpn.nl!not-for-mail
Lines: 19
Injection-Date: Wed, 26 Oct 2022 19:14:20 +0200
Injection-Info: news.kpn.nl; mail-complaints-to="abuse@kpn.com"
X-Received-Bytes: 1555
 by: Sjouke Burry - Wed, 26 Oct 2022 17:14 UTC

On 26.10.22 1:26, Mayayana wrote:
> "MyName" <MyName@NoSpam.com> wrote
>
> | So much for that.
> |
> | I tried to download on two different PC and nothing happened when
> | clicking on download "Download the latest version here".
> |
>
> https://sourceforge.net/settings/mirror_choices?projectname=clamwin&filename=clamwin/0.103.2.1/clamwin-0.103.2.1-setup.exe&selected=cytranet
>
> I don't even allow script and it works for me. I just clicked
> the "Problem Downloading?" button where it says my download
> has started. Then I clicked the "direct link" link near the top.
>
>
downloaded it .
Thanks.

Re: Virus Scanner

<tje00b$2p9cq$1@dont-email.me>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=3764&group=microsoft.public.windowsxp.general#3764

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!aioe.org!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: mayayana@invalid.nospam (Mayayana)
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: Virus Scanner
Date: Thu, 27 Oct 2022 09:10:07 -0400
Organization: A noiseless patient Spider
Lines: 44
Message-ID: <tje00b$2p9cq$1@dont-email.me>
References: <tj6ka3$3ug$1@gioia.aioe.org> <tj8ke5$20858$1@dont-email.me> <tj9kac$9k5$1@gioia.aioe.org> <tj9rbv$28f16$1@dont-email.me> <tjaldk$h26$1@gioia.aioe.org>
Injection-Date: Thu, 27 Oct 2022 13:10:35 -0000 (UTC)
Injection-Info: reader01.eternal-september.org; posting-host="eb36856c685a56aa9d000c086d1284d8";
logging-data="2925978"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18brJEDF86yFvc1ATvVuGkGCiLJ9bVOthk="
Cancel-Lock: sha1:NeqKXAv8xeHjX1l8nl8TcTkFjwo=
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.5512
X-Priority: 3
X-Newsreader: Microsoft Outlook Express 6.00.2900.5512
X-MSMail-Priority: Normal
 by: Mayayana - Thu, 27 Oct 2022 13:10 UTC

"MyName" <MyName@NoSpam.com> wrote

| Thanks.
| Got it at the direct link.
|

A caution... I'm trying a run of the latest Clamwin
on XP. I got a warning from my firewall that it was
trying to go online, which was apparently triggered
by an alleged virus discovery. Clamwin never asked
nor informed me that it was going to go online.

The alleged virus is fontsub.dll, with "Win.Keylogger.Metel".
I copied that file, then compared it byte-by-byte to
a copy I took from a SP3 CAB. They're identical. And
this particular XP is on FAT32, so it can't be an ADS file.

This is one reason I avoid AV. I once tried MalwareBytes
and it found 10 bogus problems. One was my bootloader
EXE from BootIt! ...So if you run Clamwin just be careful
not to let it handle any issues by itself. You could end up
with a messed up system.

This kind of thing has been documented in VB6 groups, as
well. Karl Peterson, an MS MVP for VB, once wrote an
article about how he triggered virus false positives by
hardcoding an HKLM Registry address into an EXE. I've
had trouble myself with certain compile configurations.
I changed the compile options and cleared the false positive.
I only knew about it because a customer wrote to me. I
then tried to inform the AV company, only to find that there's
no one minding the store. You can report a virus but you
can't actually reach a human.

I think this highlights 3 widespread problems. One is that a false
positive is much better for ther reputation than missing real
malware. Another is a tech-wide problem: It's cheaper and
easier to automate as much as possible and eliminate humans.
And then there's just the simple fact that AV is out of date.
The idea of checking signatures started when signatures were
1 MB and came out once per month. Now they come out several
times per day and go into the 100s of MB.

Re: Virus Scanner

<tje3dn$2pkmk$1@dont-email.me>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=3765&group=microsoft.public.windowsxp.general#3765

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: nospam@needed.invalid (Paul)
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: Virus Scanner
Date: Thu, 27 Oct 2022 10:08:56 -0400
Organization: A noiseless patient Spider
Lines: 72
Message-ID: <tje3dn$2pkmk$1@dont-email.me>
References: <tj6ka3$3ug$1@gioia.aioe.org> <tj8ke5$20858$1@dont-email.me>
<tj9kac$9k5$1@gioia.aioe.org> <tj9rbv$28f16$1@dont-email.me>
<tjaldk$h26$1@gioia.aioe.org> <tje00b$2p9cq$1@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Thu, 27 Oct 2022 14:08:55 -0000 (UTC)
Injection-Info: reader01.eternal-september.org; posting-host="2641f460b5e8c60853497d470e2e360b";
logging-data="2937556"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+Yj6/JV/rDicAqX7aGT59x8Z7w+ZniuI4="
User-Agent: Ratcatcher/2.0.0.25 (Windows/20130802)
Cancel-Lock: sha1:uMIkxudRTFTlTFAKyEa9pf5SNnY=
Content-Language: en-US
In-Reply-To: <tje00b$2p9cq$1@dont-email.me>
 by: Paul - Thu, 27 Oct 2022 14:08 UTC

On 10/27/2022 9:10 AM, Mayayana wrote:
> "MyName" <MyName@NoSpam.com> wrote
>
> | Thanks.
> | Got it at the direct link.
> |
>
> A caution... I'm trying a run of the latest Clamwin
> on XP. I got a warning from my firewall that it was
> trying to go online, which was apparently triggered
> by an alleged virus discovery. Clamwin never asked
> nor informed me that it was going to go online.
>
> The alleged virus is fontsub.dll, with "Win.Keylogger.Metel".
> I copied that file, then compared it byte-by-byte to
> a copy I took from a SP3 CAB. They're identical. And
> this particular XP is on FAT32, so it can't be an ADS file.
>
> This is one reason I avoid AV. I once tried MalwareBytes
> and it found 10 bogus problems. One was my bootloader
> EXE from BootIt! ...So if you run Clamwin just be careful
> not to let it handle any issues by itself. You could end up
> with a messed up system.
>
> This kind of thing has been documented in VB6 groups, as
> well. Karl Peterson, an MS MVP for VB, once wrote an
> article about how he triggered virus false positives by
> hardcoding an HKLM Registry address into an EXE. I've
> had trouble myself with certain compile configurations.
> I changed the compile options and cleared the false positive.
> I only knew about it because a customer wrote to me. I
> then tried to inform the AV company, only to find that there's
> no one minding the store. You can report a virus but you
> can't actually reach a human.
>
> I think this highlights 3 widespread problems. One is that a false
> positive is much better for ther reputation than missing real
> malware. Another is a tech-wide problem: It's cheaper and
> easier to automate as much as possible and eliminate humans.
> And then there's just the simple fact that AV is out of date.
> The idea of checking signatures started when signatures were
> 1 MB and came out once per month. Now they come out several
> times per day and go into the 100s of MB.

You should have run the candidate file through Virustotal.

Using the 7ZIP context menu (the one that computes SHA1
or SHA256 for a file), you can compute one of those and
feed it to the virustotal.com "Search" function. If the file
exists, this takes little time to access the report for the file.

One other thing. When you have a rootkit on board, it can
"show you" an uninfected fontsub.dll , while the real one
is infected. Root kits are not common any more, but
that's just an illustration of how fallible human interaction
with the file system is. You can't trust anything the
computer tells you, when you are really infected.

If you boot a Linux LiveDVD and execute

sha256sum fontsub.dll

that will allow you to analyze the file-at-rest. Then,
from LInux, you can run a virustotal.com thing and enter
the sha256 sum in the search option. If the sha256 sum is
unknown, then you have to upload the file to have it
analyzed. (I avoid their upload, because it's so flaky.
Many times an upload fails, before it finishes.)

Paul

Re: Virus Scanner

<tjeev3$2qjgt$1@dont-email.me>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=3766&group=microsoft.public.windowsxp.general#3766

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!aioe.org!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: mayayana@invalid.nospam (Mayayana)
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: Virus Scanner
Date: Thu, 27 Oct 2022 13:25:26 -0400
Organization: A noiseless patient Spider
Lines: 14
Message-ID: <tjeev3$2qjgt$1@dont-email.me>
References: <tj6ka3$3ug$1@gioia.aioe.org> <tj8ke5$20858$1@dont-email.me> <tj9kac$9k5$1@gioia.aioe.org> <tj9rbv$28f16$1@dont-email.me> <tjaldk$h26$1@gioia.aioe.org> <tje00b$2p9cq$1@dont-email.me> <tje3dn$2pkmk$1@dont-email.me>
Injection-Date: Thu, 27 Oct 2022 17:25:55 -0000 (UTC)
Injection-Info: reader01.eternal-september.org; posting-host="eb36856c685a56aa9d000c086d1284d8";
logging-data="2969117"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18Z2wfkPg85oGwRGgHLIh5NJTYvnnQildA="
Cancel-Lock: sha1:HqKc3AcJ5KGAyR0zeJpt5cWqWIc=
X-Priority: 3
X-MSMail-Priority: Normal
X-Newsreader: Microsoft Outlook Express 6.00.2900.5512
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.5512
 by: Mayayana - Thu, 27 Oct 2022 17:25 UTC

"Paul" <nospam@needed.invalid> wrote

| You should have run the candidate file through Virustotal.
|

I'm not worried. Clamwin also flagged the copy of the file
I made, as well as the CAB and the extracted version from
my stored XP SP3 files.

It appears this particular bug is used to attack banks.
Ironically, it's not easy to find info because "keylooger"
turns up lniks to track your kids and spouse. :)

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor