Full Disclosure mailing list archives

Re: Re: Av issues


From: Thierry Zoller <Thierry () sniff-em com>
Date: Wed, 16 Mar 2005 16:58:54 +0100


Dear List,

Results gathered with http://virusscan.jotti.org

Fake CRC Value
--------------------
Failed: Avast, NOD32

Passed : AVG Antivirus, BitDefender,ClamAV
Dr.Web, F-Prot Antivirus,Fortinet
Kaspersky Anti-Virus, mks_vir,AntiVir,
Norman Virus Control

POC http://www.geocities.com/visitbipin/crc.zip


Long Archive Comment
---------------------
Passed :
AntiVir ,BitDefender, ClamAV,Dr.Web,F-Prot Antivirus,Fortinet
Kaspersky Anti-Virus,mks_vir,NOD32,Norman Virus Control

Failed :
Avast, AVG Antivirus

POC http://www.geocities.com/visitbipin/long_coment.zip


Fake compressed size and uncompressed size
-------------------------------------------
Failed : AntiVir,Avast,BitDefender,Dr.Web,Fortinet
,mks_vir,NOD32,Norman Virus Control

Passed: AVG Antivirus Kaspersky Anti-Virus
F-Prot Antivirus, ClamAV

POC http://www.geocities.com/visitbipin/Antigen.zip


-- 
Thierry Zoller
Secure-It: http://www.sniff-em.com/secureit.shtml
Harden-It: http://www.sniff-em.com/hardenit.shtml


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://www.secunia.com/


Current thread: