Account Options

  1. Sign in
The old Google Groups will be going away soon, but your browser is incompatible with the new version.
Google Groups Home
« Groups Home
worm Win32/Orbina!rts in win32forth from sourceforge
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  8 messages - Collapse all  -  Translate all to Translated (View all originals)
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
Michael  
View profile   Translate to Translated (View Original)
 More options May 17 2011, 5:04 pm
Newsgroups: comp.lang.forth
From: Michael <michael.ka...@onlinehome.de>
Date: Tue, 17 May 2011 14:04:16 -0700 (PDT)
Local: Tues, May 17 2011 5:04 pm
Subject: worm Win32/Orbina!rts in win32forth from sourceforge
Hi.

Tryed to get win32forth today from sourceforge, and Microsoft Security
Essentials found
Worm: Win32/Orbina!rts - details below. Sorry that it is in German,
but I guess you get the essentials.

I got no message by MSE downloading W32for42.exe  (10-Oct-2000 13:18
1.5M) here:
http://www.complang.tuwien.ac.at/forth/win32forth/

Michael

Worm: Win32/Orbina!rts

Kategorie: Wurm

Beschreibung: Dieses Programm ist gefährlich. Es verbreitet sich
selbst über eine Netzwerkverbindung.

Empfohlene Aktion: Lassen Sie dieses entdeckte Element nur zu, wenn
Sie dem Programm oder dem Softwareherausgeber vertrauen.

Security Essentials hat Programme erkannt, die Ihre Privatsphäre
gefährden oder Ihren Computer beschädigen könnten. Sie können auf die
von diesen Programmen verwendeten Dateien weiterhin zugreifen, ohne
sie zu entfernen (nicht empfohlen). Wählen Sie zum Zugreifen auf diese
Dateien die Aktion "Zulassen" aus, und klicken Sie dann auf "Aktionen
anwenden". Wenn diese Option nicht verfügbar ist, melden Sie sich als
Administrator an, oder bitten Sie den Sicherheitsadministrator um
Unterstützung.

Elemente:
containerfile:C:\Dokumente und Einstellungen\Michael\Eigene Dateien
\w32f61200.exe
file:C:\Dokumente und Einstellungen\Michael\Eigene Dateien
\w32f61200.exe->(nsis-3-fkernel.exe)
webfile:c:\Dokumente und Einstellungen\All Users\Anwendungsdaten
\Microsoft\Microsoft Antimalware\LocalCopy\{66A50D87-3169-4DE2-A80D-
B32924E041DF}-w32f61200.exe|http://heanet.dl.sourceforge.net/project/
win32forth/Win32Forth%20-%20stable%20release/Win32forth%20V6.12.00/
w32f61200.exe
webfile:C:\Dokumente und Einstellungen\Michael\Eigene Dateien
\w32f61200.exe|http://heanet.dl.sourceforge.net/project/win32forth/
Win32Forth%20-%20stable%20release/Win32forth%20V6.12.00/w32f61200.exe


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Alex McDonald  
View profile   Translate to Translated (View Original)
 More options May 17 2011, 7:20 pm
Newsgroups: comp.lang.forth
From: Alex McDonald <b...@rivadpm.com>
Date: Tue, 17 May 2011 16:20:56 -0700 (PDT)
Local: Tues, May 17 2011 7:20 pm
Subject: Re: worm Win32/Orbina!rts in win32forth from sourceforge
On May 17, 10:04 pm, Michael <michael.ka...@onlinehome.de> wrote:

It's common to get hits due to the nature of the executable code; it's
perfectly safe, however.

 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Bluebee  
View profile  
 More options May 19 2011, 1:02 am
Newsgroups: comp.lang.forth
From: Bluebee <visualfo...@rocketmail.com>
Date: Wed, 18 May 2011 22:02:21 -0700 (PDT)
Local: Thurs, May 19 2011 1:02 am
Subject: Re: worm Win32/Orbina!rts in win32forth from sourceforge
On 17 Mai, 19:20, Alex McDonald <b...@rivadpm.com> wrote:

> On May 17, 10:04 pm, Michael <michael.ka...@onlinehome.de> wrote:

> > Tryed to get win32forth today from sourceforge, and Microsoft Security
> > Essentials found
> > Worm: Win32/Orbina!rts - details below.

> It's common to get hits due to the nature of the executable code; it's
> perfectly safe, however.

It's interesting: Win32Forth version 6.12 gets complaints from various
anti-virus software.
Until I excluded the Win32Forth (version 6.12) folder from searching,
my avast anti-virus snatched away and pinched Win32for.exe every time
- but not so with Win32Forth version 6.14: there are no complaints
about version 6.14 - and no complaints about version 4.2 neither.

Despite Win32Forth version 6.14 being better off, it is irritating
that it says on sourceforge:

Looking for the latest version? Download Win32Forth V6.14.00 (5.9 MB)
but:
Win32Forth - stable release: Win32forth V6.12.00  2007-07-14
etc.

I am reading this text in a way that version 6.14. is not a stable
release, and other people may do so, too, and get in trouble with
their av-software when loading and/or using version 6.12.
Strange somehow.


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Rod Pemberton  
View profile  
 More options May 19 2011, 5:44 am
Newsgroups: comp.lang.forth
From: "Rod Pemberton" <do_not_h...@noavailemail.cmm>
Date: Thu, 19 May 2011 05:44:50 -0400
Local: Thurs, May 19 2011 5:44 am
Subject: Re: worm Win32/Orbina!rts in win32forth from sourceforge
"Bluebee" <visualfo...@rocketmail.com> wrote in message

news:f236a4a1-02c3-4618-b28a-c392a4c9d4a1@w36g2000vbi.googlegroups.com...

> On 17 Mai, 19:20, Alex McDonald <b...@rivadpm.com> wrote:
> > On May 17, 10:04 pm, Michael <michael.ka...@onlinehome.de> wrote:
> > > Tryed to get win32forth today from sourceforge, and Microsoft Security
> > > Essentials found
> > > Worm: Win32/Orbina!rts - details below.

> > It's common to get hits due to the nature of the executable code;
> > it's perfectly safe, however.

> It's interesting: Win32Forth version 6.12 gets complaints from various
> anti-virus software.

Personally, I've never gotten a false positive from anti-virus scanner no
matter how strict the scan.  If doesn't pass your virus scanner, don't use
it.  I think I'm going to re-run some on Win32Forth 6.12...

Rod Pemberton


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Alex McDonald  
View profile  
 More options May 19 2011, 9:35 am
Newsgroups: comp.lang.forth
From: Alex McDonald <b...@rivadpm.com>
Date: Thu, 19 May 2011 06:35:14 -0700 (PDT)
Local: Thurs, May 19 2011 9:35 am
Subject: Re: worm Win32/Orbina!rts in win32forth from sourceforge
On May 19, 10:44 am, "Rod Pemberton" <do_not_h...@noavailemail.cmm>
wrote:

The problem is the PE header built by 6.12, and the way the code
section is declared in it with a length descriptor that contains a
value that far exceeds the actual length of the section. It was
addressed in 6.14.

 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Coos Haak  
View profile  
 More options May 19 2011, 10:11 am
Newsgroups: comp.lang.forth
From: Coos Haak <htro...@gmail.com>
Date: Thu, 19 May 2011 07:11:51 -0700 (PDT)
Local: Thurs, May 19 2011 10:11 am
Subject: Re: worm Win32/Orbina!rts in win32forth from sourceforge
On 19 mei, 11:44, "Rod Pemberton" <do_not_h...@noavailemail.cmm>
wrote:

Then you have never used Panda AV or AVG
They complain with Win32Forth 6.12 and 6.14 on Windows XP, Vista and
7.

groetjes Coos


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
rickman  
View profile  
 More options May 19 2011, 10:17 am
Newsgroups: comp.lang.forth
From: rickman <gnu...@gmail.com>
Date: Thu, 19 May 2011 07:17:04 -0700 (PDT)
Local: Thurs, May 19 2011 10:17 am
Subject: Re: worm Win32/Orbina!rts in win32forth from sourceforge
On May 19, 9:35 am, Alex McDonald <b...@rivadpm.com> wrote:

I get AV flags on version 6.14 from SuperAntiSpyware (with current
updates).  I forget the exact messsage, but it is something about a
Trojan and I think a name Haoge or similar.  I was just running a scan
but it won't let me go back to see the report.  First I have to reboot
the computer and by the time that is done I'll likely not remember
what Forth is much less this thread... life with no memory is a
pita.

Rick


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Alex McDonald  
View profile  
 More options May 19 2011, 8:31 pm
Newsgroups: comp.lang.forth
From: Alex McDonald <b...@rivadpm.com>
Date: Thu, 19 May 2011 17:31:14 -0700 (PDT)
Local: Thurs, May 19 2011 8:31 pm
Subject: Re: worm Win32/Orbina!rts in win32forth from sourceforge
On May 19, 3:11 pm, Coos Haak <htro...@gmail.com> wrote:

I'd be interested to know why that's the case. Macafee makes no
complaint about either version.

 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
End of messages
« Back to Discussions « Newer topic     Older topic »