Opera Virus

Ask other users about problems encountered with portable apps or help by posting solutions to existing problems.
Message
Author
User avatar
Queue
Posts: 197
Joined: Mon Oct 08, 2007 2:41 am
Contact:

#16 Post by Queue »

Ok, it makes sense that ClamAV isn't an active scanner since it's portable, but I don't understand how it's preventing OperaUSB from running if it's just an on-demand scanner. Couldn't you just not scan your Opera folder or not let it automatically cripple files (ask for confirmation first)? And what is it doing: is it deleting the suspicious file, renaming it, altering it?

I know these questions seem silly, but I use on-demand scanners set up to simply alert me of the results and to not take any actions, I don't even know what actions they take if I let them. A decade ago it was f-prot, but in recent times I've been largely relying on web-based multi scanners so I get a good perspective on the non-behavioral detection rates of malware I'm researching. =/

Queue

User avatar
Checker
Posts: 1628
Joined: Wed Jun 20, 2007 1:00 pm
Location: Ingolstadt [DE]

#17 Post by Checker »

@ m^(2): Fine work!

But I still think it's not our work to change programs to make them "ClamAV-compatible".
Why not simply use another AV-scanner?
There is a lot of good (free and portable) AV-software available.

User avatar
Checker
Posts: 1628
Joined: Wed Jun 20, 2007 1:00 pm
Location: Ingolstadt [DE]

#18 Post by Checker »

@ Queue:
ClamWin Portable simply passivly scans the files and gives an alert (false positive) like this:
Scan Started Tue Apr 15 20:59:20 2008
-------------------------------------------------------------------------------


h:\PortableApps\Opera927de\operausb.exe: Trojan.QQPass-737 FOUND
----------- SCAN SUMMARY -----------
Known viruses: 251966
Engine version: 0.92
Scanned directories: 38
Scanned files: 112
Skipped non-executable files: 1
Infected files: 1
Data scanned: 18.04 MB
Time: 115.900 sec (1 m 55 s)

--------------------------------------
Completed
--------------------------------------
Nothing else ... no deletion of files etc.

User avatar
m^(2)
Posts: 890
Joined: Sat Mar 31, 2007 2:38 am
Location: Kce,PL
Contact:

#19 Post by m^(2) »

Checker wrote:There is a lot of good (free and portable) AV-software available.
Can you give some examples?
The only other I know is AVZ.

User avatar
Checker
Posts: 1628
Joined: Wed Jun 20, 2007 1:00 pm
Location: Ingolstadt [DE]

#20 Post by Checker »

I dont want to start a discussion if they are better or not than ClamAV.
Try it for yourself.

- Dr. Web CureIt is a free antivirus and antispyware utility based on Dr.Web antivirus scanner which can scan quickly and cure any infected system. You can run CureIt immediately after download, no installation required.

http://www.techsnack.net/drweb-cureit-f ... -antivirus

Download: http://freedrweb.com/


- Multi Virus Cleaner
Download: http://www.viruskeeper.com/us/mvc.htm

They both didn't show a "false positive" on operausb.exe
Last edited by Checker on Tue Apr 15, 2008 10:16 pm, edited 1 time in total.

User avatar
m^(2)
Posts: 890
Joined: Sat Mar 31, 2007 2:38 am
Location: Kce,PL
Contact:

#21 Post by m^(2) »

Thanks, I'll use them both. The more the better :)

User avatar
Checker
Posts: 1628
Joined: Wed Jun 20, 2007 1:00 pm
Location: Ingolstadt [DE]

#22 Post by Checker »

By the way:
New version of ClamWin (0.93) still shows a false positive on Opera@USB.

lajjal
Posts: 82
Joined: Sun Apr 13, 2008 12:18 pm

#23 Post by lajjal »

What is strange is that apparently they same guy reponsible for Operausb is also involved in the UPX program development and, as suggested in this thread, the UPX treatment fixes the problem. Why wouldn't he use his own tool? Very odd.

opsimathic
Posts: 50
Joined: Sun Feb 25, 2007 12:12 pm
Location: Uganda

#24 Post by opsimathic »

[quote="Dr. Web CureIt is a free antivirus and antispyware utility based on Dr.Web antivirus scanner which can scan quickly and cure any infected system. You can run CureIt immediately after download, no installation required.

http://www.techsnack.net/drweb-cureit-f ... -antivirus"[/quote]

Thanks for this heads-up - I will download Dr. Web CureIT later today when I have time to properly look at it.

I note it is not in the TPFC database - do you know if it is truly portable - preferably stealthy as well?

If it is a well behaved portable application, we should submit it so the wider community can use it.


Thanks again!
/opsimathic

lajjal
Posts: 82
Joined: Sun Apr 13, 2008 12:18 pm

#25 Post by lajjal »

Cureit is nagware and requires downloading the whole app new each time it is used if you want the latest database. Pendriveapps has listed it for sometime now but their standards are pretty low.

opsimathic
Posts: 50
Joined: Sun Feb 25, 2007 12:12 pm
Location: Uganda

#26 Post by opsimathic »

lajjal wrote:Cureit is nagware and requires downloading the whole app new each time it is used if you want the latest database."
Thanks for explanation - much appreciated.
/opsimathic

Post Reply