PDA

View Full Version : Does NOD32 Scan the Registry?


balbane
November 16th, 2003, 09:43 PM
Well, another spyware program found traces of the optix trojan in my registries. I was surprised NOD32 didn't. I was infected with Optix Pro a long time ago. I did it to myself, so I know. Anyway, does NOD32 scan the registries?

Acadia
November 16th, 2003, 09:52 PM
Don't know if NOD is one of them, but many AV do NOT do a good job with Trojans, even the AVs that are excellent with viruses. Yes, most spyware detectors will detect many things that AV do not.

Acadia

balbanebeoulve
November 16th, 2003, 09:54 PM
I know, I know, the old trojan thing. But NOD32 has anyway been able to locate Optix, but the registry entry was not located. That's sort of odd. When you find a virus, you expect all traces of it to be exterminated...=/

I don't know, but maybe I can get a copy of some of the registry entries to send to ESET...

Straight Shooter
November 17th, 2003, 12:57 AM
From my experience, KAV seems to be the best in terms of finding registry entries. I still think a dedicated AT like TrojanHunter is a better, safer bet... 8)

sig
November 17th, 2003, 02:44 AM
My understanding is that while various AV's detect various trojans, for some trojans not all AV's are effective at removing all traces. KAV may be better at this than others as SS noted but as he also mentioned typically AT's are often recommended as doing a better job overall at trojan removal (in addition to detection) than AV's in these instances.

anders
November 17th, 2003, 08:00 AM
NOD32 doesn't scan the registry for "left-overs", but, as far as I know (and have tested), NOD32 is doing a good job of removing the registry-autostart-values (etc) when it is removing the actual infected file. Then again, the best thing is to never get infected, by using up-to-date protection and OS updates, and being careful. :)

Best regards,
Anders

balbanebeoulve
November 17th, 2003, 01:00 PM
-{ Quote: " quoting: anders link=board=39;threadid=16450;start=0#msg102014 date=1069074014]
NOD32 doesn't scan the registry for "left-overs", but, as far as I know (and have tested), NOD32 is doing a good job of removing the registry-autostart-values (etc) when it is removing the actual infected file. Then again, the best thing is to never get infected, by using up-to-date protection and OS updates, and being careful. :)

Best regards,
Anders

" }-

Well, I think it would be great if NOD32 could start scanning the registry. And we wouldn't need virus scanners if we were all up-to-date and protected completely. But that would put eset and many companies out of business, wouldn't it? Anyway, do you think NOD32 will implement registry scanning?

anders
November 17th, 2003, 04:20 PM
I don't think scanning for "registry leftovers" will be added in a foreseeable future, and I personally think it's very low priority.

Best regards,
Anders

WilliamP
November 17th, 2003, 04:30 PM
What is high priority with NOD. Now don't get me wrong at the present time I wouldn't trade NOD for anything else. But I haven't seen anything fixed since June when Ver.2 came out.

balbane
November 17th, 2003, 06:01 PM
Well, I don't know, but...who would really want tons of registry entries of viruses that once crawled your system? And could it be suggested to the developers? I mean, I'm sure users would start exporting virus entries in their registry to help Eset if they knew it would be used...

MmM, It's just that I really want my system to be 100% clean and safe. I know registry entries alone can't do much, yet I still feel uncomfortable if they aren't being scanned...

Acadia
November 17th, 2003, 09:05 PM
-{ Quote: " quoting: WilliamP link=board=39;threadid=16450;start=0#msg102147 date=1069104619]
But I haven't seen anything fixed since June when Ver.2 came out.
" }-

Thank you, thank you, thank you.

Acadia

mrtwolman
November 18th, 2003, 01:59 AM
-{ Quote: " quoting: WilliamP link=board=39;threadid=16450;start=0#msg102147 date=1069104619]
But I haven't seen anything fixed since June when Ver.2 came out.
" }-
IMHO, unpacking engine has been improved, avd. heuristic has been improved ....
Soon IMON will get packed worm scanning ability ....

Phant0m
November 19th, 2003, 03:55 PM
I believe if an AV System going to deal with Trojans/worms they should go all-the-way to undo registry damages caused by the Trojans/worms Infections. This is actually one of the big problems with infected machines using AV System to remove their Trojans/worms infections, in most cases renders their systems quite useless such as executing executables for instance and making successful connection to their ISP. Another thing is you don’t want to keep the Systems Registry cluttered up otherwise you may experience system delays/freezes/errors/crashes… ;)

iNsuRRecTioN
December 14th, 2003, 04:49 PM
-{ Quote: "But I haven't seen anything fixed since June when Ver.2 came out.
" }-
There are updates and improvements, of course.

I think, that someone mean, that nothing really updatet is an misstake bye eset.

They should release an update history or so on their website!

bye

iNsuRRecTioN