View Full Version : New
testg
October 16th, 2003, 01:25 PM
Norton found it but nothing else did.
it's in c:\winnt\system32 it's updatewiz.exe
LowWaterMark
October 16th, 2003, 01:28 PM
What did Norton say it is? (What malware?)
testg
October 16th, 2003, 02:01 PM
I believe it was trojan.adclicker or something like that. I forgot it, plus am not at my home pc. But I did send a sample to the Eset, nsclean and tds.
It was running in my memory and takeing up ~30mb of space.
LowWaterMark
October 16th, 2003, 02:14 PM
-{ Quote: " quoting: testg link=board=39;threadid=15029;start=0#msg94075 date=1066327300]But I did send a sample to the Eset, nsclean and tds." }-
Ah, very good. Thanks.
GuruGuy
October 16th, 2003, 03:49 PM
http://securityresponse.symantec.com/avcenter/venc/data/trojan.adclicker.html
This was discovered on Sep 12, 2003!
Are you using the current version of NOD32 with the latest updates? If so, why isn't this detected by NOD32?????
sir_carew
October 16th, 2003, 04:04 PM
Hello,
None AntiVirus detect the 100 % of the viruses, trojans, worms, etc. NAV can detect viruses that NOD not, and NOD can detect viruses that also NAV not detect.
It's relative.
testg
October 16th, 2003, 10:24 PM
Yes I am using the newest reference files 1.535 with /ah flag.
I am not exactly sure of the trojan name but that is what I recall the name being. And the trojan was detected by Symanted in Sept 12, 2002, updated in July of 2003.
NSClean didn't detect it, neither did TDS-3 nor Kaspersky, NOR bitdefender so You might as well exuse NOD32, but was amazed that Norton did, I've tried sending it through yahoo which didn't let me since Norton picked it up again so I had to compress it.
sir_carew
October 16th, 2003, 10:52 PM
Hello,
If possible, compress it with password.
Don't forgive if you send it, put the password in the message :D
And if you want, send me it via MSN, or ICQ and I send it to the AV companies that you want. :)
testg
October 18th, 2003, 07:26 PM
Any news from the Eset team?
Paul Wilders
October 19th, 2003, 07:11 AM
-{ Quote: " quoting: testg link=board=39;threadid=15029;start=0#msg94075 date=1066327300]
I believe it was trojan.adclicker or something like that. I forgot it, plus am not at my home pc. But I did send a sample to the Eset, nsclean and tds.
It was running in my memory and takeing up ~30mb of space.
" }-
Doesn't look like adclicker to me; did you notice [i]winpup32.exe" on your system?
As for Eset: in case this one turns out to be a real new nastie, it will be added to the database. Sure looks like it, since you did mention BOClean, TDS3 and KAV not detecting it.
regards.
paul
testg
October 21st, 2003, 12:37 PM
So I guess it was adclicker.
it was added in the oct 20th upate.
Win32/AdClicker.B
4 months late but at least it's there. :)
sig
October 21st, 2003, 04:58 PM
"4 months late?" NOD already detected at least one version of adclicker weeks ago.
As for this version.....how do you figure 4 months? Or did you mean to say 4 weeks from the time Symantec added this? ;)
Q Section
October 21st, 2003, 05:12 PM
Who claimed NOD32 is supposed to catch trojans now? It is known that some are caught by NOD32 but since it is an anti-virus program it seems very good to even catch any trojans.
sig
October 21st, 2003, 10:23 PM
"Who claimed NOD32 is supposed to catch trojans now?"
Well, ESET does: "Viruses, worms, trojans and other malware are kept out of striking distance of your valuable data. Advanced detection methods implemented in the software even provide protection against the future threats from most of the new worms and viruses. " http://www.nod32.com/products/products.htm
Additionally from their site regarding the Checkmark certification:
"The Checkmark certification of NOD32 for Windows 2003 to AV [Anti-Virus] Levels 1,2 and Trojan, is the hallmark of a company whose philosophy is to be a cutting-edge AV developer," commented Chris Thomas, Operations Director of West Coast Labs, in a statement announcing the results.
“West Coast Labs’ certification process represents the true test of an antivirus product’s capability to detect viruses, worms, and Trojans. http://www.nod32.com/news/awards.htm
Perhaps they should change the language to "most common trojans." But ESET does indeed claim to provide protection against Trojans....
Q Section
October 22nd, 2003, 10:17 AM
It certainly seems beneficial to pay attention to the actual product description page! :-[
Best wishes
hayc59
October 22nd, 2003, 10:18 AM
-{ Quote: " quoting: QSection link=board=39;threadid=15029;start=0#msg95388 date=1066832228]
It certainly seems beneficial to pay attention to the actual product description page! :-[
Best wishes
" }-
Q you da man!! ;D
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums