Notices

Water Fountain General Chit/Chat

Reply
 
LinkBack Thread Tools
Old 04-29-04, 10:25 PM   #1 (permalink)
Aximsite Minor League
 
ironman00818's Avatar
Member
 
Join Date: Mar 2004
Location: east coast
Posts: 161
Thanked 0 Times in 0 Posts
trojan horse with a .cab ext?

Anyone run into one of these before? My virus program caught it tonight while I was surfing for freeware for my Ax. Thought .cab extentions only worked on PPCs. Makes you wonder.
ironman00818 is offline   Reply With Quote
Sponsor Ads
Old 04-29-04, 10:26 PM   #2 (permalink)
Aximsite Legend
 
Howard2k's Avatar
Addicted Member
 
Join Date: Jun 2003
Location: Toronto, Canada
Posts: 13,721
Thanked 4 Times in 4 Posts

Awards Showcase
Aximsite Active Silver Member Moderator Medal Silver Poster 
Total Awards: 3

Could be a false positive?
__________________
Always read stuff that will make you look good if you die in the middle of it.
Howard2k is offline   Reply With Quote
Old 04-29-04, 11:08 PM   #3 (permalink)
gbm85
Guest
 
Posts: n/a
Nope, cab has been aroud since before PPCs. Stick a Windows 95 or 98 disc in your CD drive and search for *.cab. You'll see tons of them. A cab file is not much more then a compressed file. However it also includes instructions which the OS uses to know what to put where and what registry entries to add.
  Reply With Quote
Old 04-30-04, 11:57 PM   #4 (permalink)
Aximsite Minor League
 
ironman00818's Avatar
Member
 
Join Date: Mar 2004
Location: east coast
Posts: 161
Thanked 0 Times in 0 Posts
Afraid I was using Apple computers in the Windows 95-98 days. Thanks for the info. Thought I had run into one of the first trojan horse targeted for PPCs.
ironman00818 is offline   Reply With Quote
Old 05-01-04, 12:32 AM   #5 (permalink)
Aximsite Veteran
 
HighTymes's Avatar
Uber Member
 
Join Date: Dec 2003
Posts: 2,078
Thanked 0 Times in 0 Posts
What program is it so we know not to download it.


Thankz
__________________
X30High :)
Boxwave Screen Protector
512MB Kingston SD Card
512MB PNY SD Card
Mugen 2000mAh Battery
Dell Foldable Keyboard
i.Trek Bluetooth GPS
HighTymes is offline   Reply With Quote
Old 05-01-04, 12:43 AM   #6 (permalink)
Aximsite Minor League
 
ironman00818's Avatar
Member
 
Join Date: Mar 2004
Location: east coast
Posts: 161
Thanked 0 Times in 0 Posts
I was surfing links for a animation program. Had about 4 or 5 windows open (funny thing is it installed as I was backing up through pages using history) I could not tell exactly which site it was that tried to infect my computer. Just that they were all PPC sites.
ironman00818 is offline   Reply With Quote
Old 05-01-04, 03:55 PM   #7 (permalink)
Gerard Samija
Guest
 
Posts: n/a
It is really easy to make a malicious CAB file aimed at PPCs, though it seems your case was not that at all. So far, there is no way for PC- or PPC-based AV program to detect such malware, as it has never yet surfaced in the wild and so developers haven't prepared for it. I know AirScanner is working on the problem, among lots of other potential threats to PPC users, because I wrote a book chapter for them on one such instance... a little something I cooked up on my iPAQ, which proved easily distributable under any number of names, and 100% fatal to main memory on any ARM-based PPC. NDA prohibits my going into this further, and frankly I'd rather not see it ever come to pass that we face risks such as this when downloading CAB files, ZIP compressed or not. Seems so bizarre that people attack others at random, just for kicks. Anyway, I'm just saying one should always tap No to the 'open file after download?' question in Pocket IE, when it's a CAB file, and further we should all be making very frequent backups one way or another.
  Reply With Quote
Old 05-01-04, 04:27 PM   #8 (permalink)
Aximsite Minor League
 
ironman00818's Avatar
Member
 
Join Date: Mar 2004
Location: east coast
Posts: 161
Thanked 0 Times in 0 Posts
That is one of the strange things about this instance. I had not downloaded anything. As soon as the page loaded in the browser the virus warning came up. The thing was still in my internet temp file. It loaded in with the web page. Does not give me a warm feeling that it was on a PPC site. As Gerard stated I hope that anti-virus programming start to address this kind of thing and not wait around for the s%#* to hit the fan.
ironman00818 is offline   Reply With Quote
Old 05-01-04, 05:17 PM   #9 (permalink)
Aximsite Veteran
 
gsteinb88's Avatar
Uber Member
 
Join Date: Sep 2003
Location: Boston, MA
Posts: 1,887
Thanked 0 Times in 0 Posts
Well, pc-cillin makes a virus scanner for the ppc and there are a few others out there, i think you can get one of them in the downloads section of this site. Might want to check those out if you are afraid of things like this happening to your ppc...
-g
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.


To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
to save lives!
gsteinb88 is offline   Reply With Quote
Old 05-01-04, 06:58 PM   #10 (permalink)
Aximsite Minor League
 
ironman00818's Avatar
Member
 
Join Date: Mar 2004
Location: east coast
Posts: 161
Thanked 0 Times in 0 Posts
Actually I run McAfee virus scan for PDA. The problem is since there are no recorded viruses for the PPC "on the loose" how good is it? It probably checks for basic stuff but at this point in time that is most likely it
ironman00818 is offline   Reply With Quote
Reply

Sponsor Ads

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 08:52 PM.
Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.3.0
Copyright © 2003-09 LeckMedia, LLC