VOGONS


DOS antivirus , any left? (found F-PROT , latest virus definitions @ 2009)

Topic actions

  • This topic is locked. You cannot reply or edit posts.

First post, by keropi

User metadata
Rank l33t++
Rank
l33t++

Since my recent infection 😅 I started searching for a DOS antivirus... F-Prot has their own for free, with 2006 virus definitions (recent enough for ancient DOS usage) but has a "feature" that detects the 2010 date and does not let you run it.. You can manually set date back 4 years and it works but still... I don't like that solution that much 😊 since the virus defs will be from 2006 and there are no updates...

I have KAV purchased and it lets me download a rescue CD, will try that later and see if it actually works on a p200mmx with 64MB of ram
😁

In the meantime has anyone here any recommendation regarding a DOS only virus scanner? I am not looking for a tsr/realtime protection but something to manually scan files before I run them...

thanks for any info !! 😀

Last edited by keropi on 2010-12-27, 00:41. Edited 1 time in total.

🎵 🎧 PCMIDI MPU , OrpheusII , Action Rewind , Megacard and 🎶GoldLib soundcard website

Reply 3 of 28, by keropi

User metadata
Rank l33t++
Rank
l33t++

nice find Old Thrashbarg , let's hope that ClamAV works (freedos stuff are not always working 🤣)
valnar if ClamAV fails, I will get them

edit: bah, clamAV DOS version is a mess... a total unattractive unix-like mess

edit2: NOD32DOS works fine with the latest-today-released virus databases 😊 it's a keeper 😈

🎵 🎧 PCMIDI MPU , OrpheusII , Action Rewind , Megacard and 🎶GoldLib soundcard website

Reply 4 of 28, by keropi

User metadata
Rank l33t++
Rank
l33t++

here is how to get nod32dos and update it to latest version...

1. get the main dos files from a mirror here: http://www.filewatcher.com/m/noddosen.exe.5606742.0.0.html

2. extract it and delete from there the big nod32.000 file (the old virus database)

3. go here and get the latest version : ftp://ftp.isu.edu.tw/pub/Windows/Edskes/n/

4. run it on your windows setup, and just let it load... it's files are extracted to a temporary directory (I use task manager's "open file location" feature

5. in the temporary directory there is a bigger (16-17MB) NOD32.000 file, that is the latest database that we need, simply copy it to the DOS installation and it is ready to be used!

maybe there is a more simpler way to get the last database but that's what I found first 🤣

🎵 🎧 PCMIDI MPU , OrpheusII , Action Rewind , Megacard and 🎶GoldLib soundcard website

Reply 5 of 28, by HunterZ

User metadata
Rank l33t++
Rank
l33t++

Thanks for looking into this. I'm in the process of rescuing old files from floppy disks and am thinking I should probably run them through a virus scanner.

Questions:
1. Is there a more official link for nod32dos?
2. Is it free for personal use?
3. Can it scan inside of archive files (.ZIP etc.)?
4. Did you keep a copy of your DOS virus around to see if nod32dos could detect it?

Reply 6 of 28, by keropi

User metadata
Rank l33t++
Rank
l33t++

1. there are no "more official" links , ESET discontinued the dos version and naturally all traces to it except some VERY basic knowledge base questions are gone...
2. the first time you run the DOS version it states you must register after 25days if you use it. Ofcourse you can't nowdays , and from what it seems the demo does not expire ever...
3. Yep, it can scan inside common archive files , there is also a configuration option about that
4. unfortunatelly no... KAV cleaned my files before I keep one for testing... I don't see though why NOD32 would not detect a 1995ish virus... I will try to test it though with some other archive that has a virus

🎵 🎧 PCMIDI MPU , OrpheusII , Action Rewind , Megacard and 🎶GoldLib soundcard website

Reply 8 of 28, by keropi

User metadata
Rank l33t++
Rank
l33t++

did a test with what I have, both latest KAV 2011 antivirus (legal own purchased copy with up-to-date databases) and NOD32DOS detect the SAME viruses:

152i05e.jpg

KAV could clean the files but NOD32DOS wanted to delete them 😁 at least you get a warning

🎵 🎧 PCMIDI MPU , OrpheusII , Action Rewind , Megacard and 🎶GoldLib soundcard website

Reply 10 of 28, by keropi

User metadata
Rank l33t++
Rank
l33t++

well.... KAV cleaned them OK and the files run fine... I just tried F-PROT that is given freeware from the company but with 2006 databases... it did clean the infected files outside the .zip files 😁
TBH there is no point in having more recent databases than 2006 ones, since DOS was dead long ago and I don't see recent viruses to be 16bit dos ones...
what I hate is the nag on startup of F-PROT about the database being old... I will search for a workaround other than changing the date

ps. the KAV2011 rescue-cd that is actually some linux distro + KAV does not work on a p200mmx with 64MB of ram 😵

🎵 🎧 PCMIDI MPU , OrpheusII , Action Rewind , Megacard and 🎶GoldLib soundcard website

Reply 12 of 28, by keropi

User metadata
Rank l33t++
Rank
l33t++

it could but running a sensitive app like an antivirus through HX is not a good idea , unless you know for fact that the creators had this in mind or offer a compatible build

🎵 🎧 PCMIDI MPU , OrpheusII , Action Rewind , Megacard and 🎶GoldLib soundcard website

Reply 13 of 28, by Jorpho

User metadata
Rank l33t++
Rank
l33t++

"Sensitive" ? If it's not a real-time scanner, all it's doing is reading data off the hard drive and comparing it to its definitions, in which case I don't see why it would work any worse than any other program under HX DOS Extender, if it works at all. Granted, I'd be a little hesitant to trust a program in that situation to successfully clean infected files.

Reply 14 of 28, by keropi

User metadata
Rank l33t++
Rank
l33t++

you have answered your self the "sensitive" question, there is no trust in a program that writes data when it is running under some "emulation/wrapper/whatever" mode.

🎵 🎧 PCMIDI MPU , OrpheusII , Action Rewind , Megacard and 🎶GoldLib soundcard website

Reply 15 of 28, by DonutKing

User metadata
Rank Oldbie
Rank
Oldbie

Hah, the 'junkie' boot sector virus! I remember that. There was a bit of an epidemic of it around my area in the mid/late 90's. Most of the people around here didn't have internet until the 2000's (yay regional australia) so I suspect that one of the local computer repairmen was responsible. He used to pirate software with no qualms at all, if he was there to fix your computer you just had to ask him for something and he'd whack it on for you.
I remember another computer repairman saying that he was removing it from a lot of computers at the time.

If you are squeamish, don't prod the beach rubble.

Reply 18 of 28, by WolverineDK

User metadata
Rank Oldbie
Rank
Oldbie

hmmm would it be impossible to think, that some anti virus companies keeps the old viruses for dos and windows on a Linux box some where ? so they can examine the old viruses "safely" ? Cause I know certain states in the world does an extensive research on real life virus (under extreme safe conditions of course), to see what can make them find an antidote/cure against the virus.