<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
	<title>dotTech - Topic: What do these antivirus scan results mean to you?</title>
	<link>http://dottech.org/forums/gen-tech/what-do-these-antivirus-scan-results-mean-to-you/</link>
	<description><![CDATA[Professional Technologians]]></description>
	<generator>Simple:Press Version 5.2.6</generator>
	<atom:link href="http://dottech.org/forums/gen-tech/what-do-these-antivirus-scan-results-mean-to-you/rss/" rel="self" type="application/rss+xml" />
        <item>
        	<title>sean on What do these antivirus scan results mean to you?</title>
        	<link>http://dottech.org/forums/gen-tech/what-do-these-antivirus-scan-results-mean-to-you/page-2/#p3145</link>
        	<category>Gen-Tech</category>
        	<guid isPermaLink="true">http://dottech.org/forums/gen-tech/what-do-these-antivirus-scan-results-mean-to-you/page-2/#p3145</guid>
        	        	<description><![CDATA[<p>heh, sorry about that XD, i've been really busy with work, but when I get home, i'll post it straight away.</p>
<p>ETA: 7 hours</p>
]]></description>
        	        	<pubDate>Sun, 21 Feb 2010 15:05:26 -0800</pubDate>
        </item>
        <item>
        	<title>Ramesh Kumar on What do these antivirus scan results mean to you?</title>
        	<link>http://dottech.org/forums/gen-tech/what-do-these-antivirus-scan-results-mean-to-you/#p3129</link>
        	<category>Gen-Tech</category>
        	<guid isPermaLink="true">http://dottech.org/forums/gen-tech/what-do-these-antivirus-scan-results-mean-to-you/#p3129</guid>
        	        	<description><![CDATA[<p>Hi sean! <img title="Smile" src="/wp-content/forum-smileys/sf-smile.gif" alt="Smile" /></p>
<p>Friend I see you are online. <img title="Smile" src="/wp-content/forum-smileys/sf-smile.gif" alt="Smile" /> You said in this thread you&#39;ll send the Avira scan report. Grateful if you could do so.</p>
<p>Ramesh<img title="Smile" src="/wp-content/forum-smileys/sf-smile.gif" alt="Smile" /></p>
]]></description>
        	        	<pubDate>Sat, 20 Feb 2010 23:29:56 -0800</pubDate>
        </item>
        <item>
        	<title>Ramesh Kumar on What do these antivirus scan results mean to you?</title>
        	<link>http://dottech.org/forums/gen-tech/what-do-these-antivirus-scan-results-mean-to-you/#p3128</link>
        	<category>Gen-Tech</category>
        	<guid isPermaLink="true">http://dottech.org/forums/gen-tech/what-do-these-antivirus-scan-results-mean-to-you/#p3128</guid>
        	        	<description><![CDATA[<p>Hi Karen &#38; Pwnana! <img title="Smile" src="/wp-content/forum-smileys/sf-smile.gif" alt="Smile" /> Wow you guys rock. Thanks!</p>
<p>Karen - I must confess to my stupidity. It hadn&#39;t struck me to inform Cnet. Right after I read your suggestion I rushed to Cnet but they had already moved this app to version 1.1 (I have version 1.0). I tried to find their tech support but as far as I could see they only have user comments. Feeling that a belated gripe about version 1.0 might even give a wrong impression that my gripe has an axe to grind (i.e. they might think I am a competitor) I came away.............for the moment</p>
<p>Pwnana - Bulleye! It might well be a false positive. I&#39;ll inform Avast since such feedback may help Avast &#38; through Avast indirectly help others too.</p>
<p>I am unable to answer the excellent pointer you gave - *Examine file size difference between the installer &#38; the installation* Wow! Unfortunately I feel queasy checking it for now in case it has a payload within its coding &#38; the payload is "explode now". Just because it did not explode earlier does not mean that it won&#39;t explode now. My "escape" may just have been a matter of chance. Therefore I&#39;ll delete the 1.0 installer as well. I&#39;ve already uninstalled the installation as soon as I read the scan report. I&#39;ll apply this "installer versus installed file size differential" as a matter of course from now onwards not just from version 1.1 which I&#39;ll take from Cnet but also for every app.</p>
<p>Besides in this case as soon as I take 1.1 I&#39;ll scan with my AV right away.</p>
<p>Thanks!</p>
<p>Ramesh<img title="Smile" src="/wp-content/forum-smileys/sf-smile.gif" alt="Smile" /></p>
]]></description>
        	        	<pubDate>Sat, 20 Feb 2010 23:26:19 -0800</pubDate>
        </item>
        <item>
        	<title>Pwnana on What do these antivirus scan results mean to you?</title>
        	<link>http://dottech.org/forums/gen-tech/what-do-these-antivirus-scan-results-mean-to-you/#p3124</link>
        	<category>Gen-Tech</category>
        	<guid isPermaLink="true">http://dottech.org/forums/gen-tech/what-do-these-antivirus-scan-results-mean-to-you/#p3124</guid>
        	        	<description><![CDATA[<p>Wait, so it installs the program, but it's also a bomb?  If it was a bomb then when you installed the program your computer should have slowed to a halt and then BSOD'd, or some other crashery.  Therefore' I think that this was a false positive on Avast's part, in which case you should contact Avast.  Or try downloading the same installer from the <a href="http://www.todo-backup.com/" rel="nofollow" target="_blank">official site</a> and see if Avast still reports a bomb.  If so then contact CNET.</p>
<p>A bomb is just what it sounds like: as soon as you try to extract it it "explodes" (sometimes fast sometimes slowly) and causes a crash, either to a certain program or the whole system, so if installing the application once caused no ill effects, then it is not a bomb and is safe to keep installed.</p>
<p>Avast may have reported it as a bomb because it may be highly compressed.  How much bigger is the installation than the installer?</p>
]]></description>
        	        	<pubDate>Sat, 20 Feb 2010 18:46:07 -0800</pubDate>
        </item>
        <item>
        	<title>karen on What do these antivirus scan results mean to you?</title>
        	<link>http://dottech.org/forums/gen-tech/what-do-these-antivirus-scan-results-mean-to-you/#p3104</link>
        	<category>Gen-Tech</category>
        	<guid isPermaLink="true">http://dottech.org/forums/gen-tech/what-do-these-antivirus-scan-results-mean-to-you/#p3104</guid>
        	        	<description><![CDATA[<p>If you downloaded it from cnet, then maybe you should try emailing their tech support because cnet is supposed to be a clean site.  As far as I know, they scan all the software that they post.</p>
]]></description>
        	        	<pubDate>Sat, 20 Feb 2010 05:08:06 -0800</pubDate>
        </item>
        <item>
        	<title>Ramesh Kumar on What do these antivirus scan results mean to you?</title>
        	<link>http://dottech.org/forums/gen-tech/what-do-these-antivirus-scan-results-mean-to-you/#p3079</link>
        	<category>Gen-Tech</category>
        	<guid isPermaLink="true">http://dottech.org/forums/gen-tech/what-do-these-antivirus-scan-results-mean-to-you/#p3079</guid>
        	        	<description><![CDATA[<p>Sorry, I forgot to add.</p>
<p><strong>My decompression bomb not only installs the app but is a bomb as well</strong> <img title="Cry" src="/wp-content/forum-smileys/sf-cry.gif" alt="Cry" />. I had downloaded it from cnet. The tragedy is I used the app successfully but it is still a bomb. <strong>Btw that&#39;s why I uninstalled the app &#38; reinstall it only when I need it</strong>. <strong>I therefore wish Easeus had the knack to "bomb proof" his exe or at least improve his vigilance level on cnet &#38; other sites just so no hacker shafts him (I meant Easeus, not Cnet)</strong>.</p>
<p>Thanks Pwnana</p>
<p>Ramesh<img title="Smile" src="/wp-content/forum-smileys/sf-smile.gif" alt="Smile" /></p>
]]></description>
        	        	<pubDate>Fri, 19 Feb 2010 19:48:19 -0800</pubDate>
        </item>
        <item>
        	<title>Ramesh Kumar on What do these antivirus scan results mean to you?</title>
        	<link>http://dottech.org/forums/gen-tech/what-do-these-antivirus-scan-results-mean-to-you/#p3078</link>
        	<category>Gen-Tech</category>
        	<guid isPermaLink="true">http://dottech.org/forums/gen-tech/what-do-these-antivirus-scan-results-mean-to-you/#p3078</guid>
        	        	<description><![CDATA[<p>@Pwnana - *Wow &#38; Thanks several times over!*&#160; <img title="Smile" src="/wp-content/forum-smileys/sf-smile.gif" alt="Smile" /> Both for answering queries&#160; about "decompression bomb" &#38; this "zip on zip" issue.</p>
<p>Friends when you use your antivirus next just read its scan report regarding Easeus applications.</p>
<p>If it says decompression bomb then you&#39;d know (like Pwnana says) that the exe is infected. It might have been hacked into by a hacker - perhaps even by a jealous competitor.</p>
<p>Thanks Pwnana</p>
<p>Ramesh<img title="Smile" src="/wp-content/forum-smileys/sf-smile.gif" alt="Smile" /></p></p>
]]></description>
        	        	<pubDate>Fri, 19 Feb 2010 19:40:47 -0800</pubDate>
        </item>
        <item>
        	<title>Pwnana on What do these antivirus scan results mean to you?</title>
        	<link>http://dottech.org/forums/gen-tech/what-do-these-antivirus-scan-results-mean-to-you/#p3059</link>
        	<category>Gen-Tech</category>
        	<guid isPermaLink="true">http://dottech.org/forums/gen-tech/what-do-these-antivirus-scan-results-mean-to-you/#p3059</guid>
        	        	<description><![CDATA[<p>A compression bomb is just like a virus, it only has malicious intentions.  SO:</p>
<p>1) Because they want to hurt you <img src="http://dottech.org/wp-content/forum-smileys/sf-frown.gif" title="Frown" alt="Frown" />  Developers don't make them, hackers do.</p>
<p>2)If its a real developer then they wont make compression bombs.  As you can see from that article, you have to actually TRY really hard to make a compression bomb.  If your Easeus installation was a bomb then it wasn't the real file, it was a hacker.</p>
<p>3)Again, yes <img src="http://dottech.org/wp-content/forum-smileys/sf-frown.gif" title="Frown" alt="Frown" /></p>
<p>4)Compression bombs don't install apps, so if the "installer" is a bomb, then its obviously not the real installer.  So a decompression bomb is always avoidable.</p>
<p>@Sean</p>
<p>Probably a combination.  You can only compress zip files with more zips to a certain point, at which time you would switch to a tar or rar compression to compress in a different way.  Or as I understand it from the post, they took the 4.5 petabytes and split it into 16 zip files.  Then the split THAT zip into 16 pieces and nested them into another zip file.  Then they kept doing that until the 4,947,802,324,992 KB had become only 42 KB.  4.5 petabytes is a little bigger than 400GB<img src="http://dottech.org/wp-content/forum-smileys/sf-embarassed.gif" title="Embarassed" alt="Embarassed" />...</p>
]]></description>
        	        	<pubDate>Fri, 19 Feb 2010 14:32:04 -0800</pubDate>
        </item>
        <item>
        	<title>Ramesh Kumar on What do these antivirus scan results mean to you?</title>
        	<link>http://dottech.org/forums/gen-tech/what-do-these-antivirus-scan-results-mean-to-you/#p3011</link>
        	<category>Gen-Tech</category>
        	<guid isPermaLink="true">http://dottech.org/forums/gen-tech/what-do-these-antivirus-scan-results-mean-to-you/#p3011</guid>
        	        	<description><![CDATA[<p>Guys when you P2P in torrent (not so much an issue if you use Ares Galaxy as a client - I do) many seeders &#38; leechers in the P2P swarm send you zipped files rather than non-zipped files.</p>
<p>This technique is used by some of the swarm members because they want to improve share ratio which they cannot do if zips are not used. (Veracity can be proven)</p>
<p>Friends just be extra careful when you leech a zip</p>
<p>LOL</p>
<p>Ramesh<img title="Smile" src="/wp-content/forum-smileys/sf-smile.gif" alt="Smile" /></p>
]]></description>
        	        	<pubDate>Thu, 18 Feb 2010 22:15:57 -0800</pubDate>
        </item>
        <item>
        	<title>Ramesh Kumar on What do these antivirus scan results mean to you?</title>
        	<link>http://dottech.org/forums/gen-tech/what-do-these-antivirus-scan-results-mean-to-you/#p3009</link>
        	<category>Gen-Tech</category>
        	<guid isPermaLink="true">http://dottech.org/forums/gen-tech/what-do-these-antivirus-scan-results-mean-to-you/#p3009</guid>
        	        	<description><![CDATA[<p>That is why I am again asking someone knowledgeable to answer these questions for me:-<img title="Smile" src="/wp-content/forum-smileys/sf-smile.gif" alt="Smile" /></p>
<p>1)Why would an app developer develop an exe which is a decompression bomb? <img title="Surprised" src="/wp-content/forum-smileys/sf-surprised.gif" alt="Surprised" /></p>
<p>2)Can the developer avoid developing an installer exe which is not a decompression bomb?<img title="Confused" src="/wp-content/forum-smileys/sf-confused.gif" alt="Confused" /></p>
<p>3)Is the developer actually being wicked? <img title="Surprised" src="/wp-content/forum-smileys/sf-surprised.gif" alt="Surprised" /></p>
<p>4)For certain types of apps is a decompression bomb installer unavoidable?&#160;<img title="Smile" src="/wp-content/forum-smileys/sf-smile.gif" alt="Smile" /></p>
</p>
<p>Answering these 4 questions could tell us if my fears are justified or unwarranted.<img title="Smile" src="/wp-content/forum-smileys/sf-smile.gif" alt="Smile" /></p>
<p>Ramesh</p>
<p>/ Sean:- I have IZArc, QuickZip, AlZip &#38; PowerZip. I understood your question as to whether compounded zipping means only e.g. PowerZip on Powerzip on powerzip or if it means PowerZip on QuickZip on IZArc. I could neither find the answer anywhere nor answer this myself.</p>
<p>I hope our forum readers can help both of us find the answer<img title="Smile" src="/wp-content/forum-smileys/sf-smile.gif" alt="Smile" /></p></p>
]]></description>
        	        	<pubDate>Thu, 18 Feb 2010 22:10:22 -0800</pubDate>
        </item>
        <item>
        	<title>Ramesh Kumar on What do these antivirus scan results mean to you?</title>
        	<link>http://dottech.org/forums/gen-tech/what-do-these-antivirus-scan-results-mean-to-you/#p3008</link>
        	<category>Gen-Tech</category>
        	<guid isPermaLink="true">http://dottech.org/forums/gen-tech/what-do-these-antivirus-scan-results-mean-to-you/#p3008</guid>
        	        	<description><![CDATA[<p><strong>Hi Sean! </strong><img title="Smile" src="/wp-content/forum-smileys/sf-smile.gif" alt="Smile" /> <strong>I cannot possibly explain it better than this - <a href="http://en.wikipedia.org/wiki/Zip_bomb" rel="nofollow" target="_blank">http://en.wikipedia.org/wiki/Zip_bomb</a>. This quote is from the html &#38; is therefore within quotation marks.</strong></p>
<p>"A <strong>zip bomb</strong>, also known as a <strong>Zip of Death</strong> or <strong>decompression bomb</strong>, is a malicious <a title="File archiver" href="http://en.wikipedia.org/wiki/File_archiver" rel="nofollow" target="_blank">archive</a> <a title="Computer file" href="http://en.wikipedia.org/wiki/Computer_file" rel="nofollow" target="_blank">file</a> designed to crash or render useless the program or system reading it. It is often employed to disable <a title="Antivirus software" href="http://en.wikipedia.org/wiki/Antivirus_software" rel="nofollow" target="_blank">antivirus software</a>, so that a more traditional virus sent afterwards could get through undetected.</p>
<p>Rather than hijacking the normal operation of the program, a zip bomb allows the program to work as intended, but the archive is carefully crafted so that unpacking it (e.g. by a virus scanner in order to scan for viruses) requires inordinate amounts of time, disk space or memory.</p>
<p>A zip bomb is usually a small file (up to a few hundred <a title="Kilobyte" href="http://en.wikipedia.org/wiki/Kilobyte" rel="nofollow" target="_blank">kilobytes</a>) for ease of transport and to avoid suspicion. However, when the file is unpacked its contents are more than the system can handle.</p>
<p>The technique has been used on dialup <a title="Bulletin board system" href="http://en.wikipedia.org/wiki/Bulletin_board_system" rel="nofollow" target="_blank">bulletin board systems</a> at least as long as compressing data archive programs have been around.<sup class="Template-Fact" title="This claim needs references to reliable sources from March 2008">[<em><a title="Wikipedia:Citation needed" href="http://en.wikipedia.org/wiki/Wikipedia:Citation_needed" rel="nofollow" target="_blank">citation needed</a></em>]</sup></p>
<p>Today, most antivirus programs can detect whether a file is a zip bomb and so avoid unpacking it.</p>
<p>One example of a Zip bomb was the file "42.zip" which was 42 <a title="Kilobyte" href="http://en.wikipedia.org/wiki/Kilobyte" rel="nofollow" target="_blank">kilobytes</a> of compressed data, containing six layers of nested zip files in sets of 16, each bottom layer archive containing a 4.2 <a title="Gigabyte" href="http://en.wikipedia.org/wiki/Gigabyte" rel="nofollow" target="_blank">gigabyte</a> file for a total of 4.5 <a title="Petabyte" href="http://en.wikipedia.org/wiki/Petabyte" rel="nofollow" target="_blank">petabytes</a> of uncompressed data. This file is still available for download on various websites across the internet."</p>
</p>
<p><strong>My app from Easeus is a decompression bomb. So I only install it when I need to use it. I might be stupid because when I downloaded that app it said that it is from Korea. I am not sure North or South. That point only worsened matters for me.</strong><img title="Surprised" src="/wp-content/forum-smileys/sf-surprised.gif" alt="Surprised" /></p>
<p><strong>However, since this post is already long - read the immediately following post as well before jumping to any conclusion</strong></p>
<p>Ramesh</p>
]]></description>
        	        	<pubDate>Thu, 18 Feb 2010 21:59:10 -0800</pubDate>
        </item>
        <item>
        	<title>sean on What do these antivirus scan results mean to you?</title>
        	<link>http://dottech.org/forums/gen-tech/what-do-these-antivirus-scan-results-mean-to-you/#p2825</link>
        	<category>Gen-Tech</category>
        	<guid isPermaLink="true">http://dottech.org/forums/gen-tech/what-do-these-antivirus-scan-results-mean-to-you/#p2825</guid>
        	        	<description><![CDATA[<p>Thanks for that ramesh, I hadn't heard of a de-compression file, but I love the analogy that you gave. That said, i've got 400GB free, so it shouldn't be a problem. </p>
<p>De-compression bombs, are they multiple compressions of the same format (ie. a .zipped.zip) or of different formats (ie a .rar of a .zip?)</p>
<p>I'm at school atm, but when I get home i'll do a scan with avria and post the resaults for you.</p>
]]></description>
        	        	<pubDate>Wed, 17 Feb 2010 15:11:16 -0800</pubDate>
        </item>
        <item>
        	<title>Ashraf on What do these antivirus scan results mean to you?</title>
        	<link>http://dottech.org/forums/gen-tech/what-do-these-antivirus-scan-results-mean-to-you/#p2823</link>
        	<category>Gen-Tech</category>
        	<guid isPermaLink="true">http://dottech.org/forums/gen-tech/what-do-these-antivirus-scan-results-mean-to-you/#p2823</guid>
        	        	<description><![CDATA[<blockquote><p>Ramesh Kumar said:</p>
<p>Thanks Ashraf. Indeed the problem is solved so there is no need for me to rewrite. I wrote this long sentence just to reconfirm yet again - yes text is now wrapping well.</p>
<p>Ramesh<img title="Smile" src="/wp-content/forum-smileys/sf-smile.gif" alt="Smile" /></p>
</blockquote>
<hr />
<p>For future reference, just be sure to puts spaces between really long words/URLs/etc. - that is what caused the problem here.</p>
]]></description>
        	        	<pubDate>Wed, 17 Feb 2010 12:57:04 -0800</pubDate>
        </item>
        <item>
        	<title>Ramesh Kumar on What do these antivirus scan results mean to you?</title>
        	<link>http://dottech.org/forums/gen-tech/what-do-these-antivirus-scan-results-mean-to-you/#p2822</link>
        	<category>Gen-Tech</category>
        	<guid isPermaLink="true">http://dottech.org/forums/gen-tech/what-do-these-antivirus-scan-results-mean-to-you/#p2822</guid>
        	        	<description><![CDATA[<p>Thanks Ashraf. Indeed the problem is solved so there is no need for me to rewrite. I wrote this long sentence just to reconfirm yet again - yes text is now wrapping well.</p>
<p>Ramesh<img title="Smile" src="/wp-content/forum-smileys/sf-smile.gif" alt="Smile" /></p>
]]></description>
        	        	<pubDate>Wed, 17 Feb 2010 12:01:29 -0800</pubDate>
        </item>
        <item>
        	<title>Ashraf on What do these antivirus scan results mean to you?</title>
        	<link>http://dottech.org/forums/gen-tech/what-do-these-antivirus-scan-results-mean-to-you/#p2821</link>
        	<category>Gen-Tech</category>
        	<guid isPermaLink="true">http://dottech.org/forums/gen-tech/what-do-these-antivirus-scan-results-mean-to-you/#p2821</guid>
        	        	<description><![CDATA[<blockquote><p>Ramesh Kumar said:</p>
<p>I&#39;ll stop trying for the present since text is getting cut off</p>
<p>Ramesh</p>
</blockquote>
<hr />
<p>Page width has been fixed =).</p>
]]></description>
        	        	<pubDate>Wed, 17 Feb 2010 11:42:42 -0800</pubDate>
        </item>
</channel>
</rss>