Some of how F-Prot works

Straight_ManStraight_Man Geeky, in my own wayNaples, FL Icrontian
edited February 2007 in Spyware & Virus Removal
It has four modules:

The On-Demand Scanner, which is also scheduleable.
The Update Module, which can be scheduled or run from the main interface which has the On-Demand module's access also.
The scheduler module keeps track of time and runs what is scheduled and is set up from the main interface.
A live protection module called StopW, which has access to the definitions and heuristics that the On-Demand Scanner uses.

Given that, the On-Demand Scanner and StopW can scan Thunderbird archives, and prevent launch of .exes inside the Thunderbird archives for anything that even partly matches the virus definitions (or just because it is self-launching from within email)and is of .exe type, and hide the .exe archived in, (for example) the trash archive of a Thunderbird mail account, from users. It has a heuristics rule that .exes should not try to SELF-Launch from email. Even persistant ones. AND, it tells me the .exe's name and where it is.

I will not use F-Prot's virus names here-- they are unique to Authentium and Frisk Software, Inc's F-Prot. Instead I will tell you the file names of the two executable attachments that are .exes which act like Auto-Launching viruses(which the StopW module blocked from being launched by a user clicking on it AND kept from launching):

Flash Postcard.exe
Postcard.exe
Greeting Card.exe

Since F-Prot blocked the Launch of the viruses from the trash email archive, I simply emptied my trash for the email account that had them in it, and since they were blocked from running they vanished when I emptied the Trash since Thunderbird totally empties and deletes contents of Trash archives when they are emptied.

If anyone wants to try F-Prot as a fully working (including updates) 30-day trial, Frisk Software's website is at http://www.f-prot.com . Do not be surprised if you get updates 3-7 times a week, with updates sometimes as often as twice in one day. XP's Security Center knows F-Prot as a valid Anti-Virus also, and it will tell you when F-Prot has new Virus definitions available. I scheduled a daily check, and suggest the same for a computer that is either always-on or mostly-on.

Comments

  • KwitkoKwitko Sheriff of Banning (Retired) By the thing near the stuff Icrontian
    edited February 2007
    Kaspersky AV updates hourly. While F-Prot is a good product, I think Kaspersky is the top AV on the market at the moment.
Sign In or Register to comment.