View Full Version : A virus kill my NOD32
Galaxykiss
July 4th, 2007, 10:48 AM
I got a virus who kill my nod32.I tried to send the virus through Theatsense.net. But NOD32 still doesn't detect the virus. Some of my friends' NOD32 have been stopped for a week.PLease help us.
Just give me a Green Channel so that I can sent it to ESET.
PS:I found 3 rules to let the virus pass the NOD32 scanning, I'll tell you later.
Marcos
July 4th, 2007, 10:59 AM
{QUOTE-> I got a virus who kill my nod32.I tried to send the virus through Theatsense.net. But NOD32 still doesn't detect the virus. Some of my friends' NOD32 have been stopped for a week.PLease help us.
Just give me a Green Channel so that I can sent it to ESET.
<-QUOTE}
Just send the threats in an archive protected with the password "infected" to samples[at]eset.com with this thread's url in the subject.
{QUOTE-> PS:I found 3 rules to let the virus pass the NOD32 scanning, I'll tell you later. <-QUOTE}
It's not a secret:
1. disable AMON and run a threat
2. keep signatures outdated and run a new threat
3. uninstall NOD32
Galaxykiss
July 4th, 2007, 11:07 AM
I'm so glad that you're here.
Not that secre!
It'a a technical way , some virus maker told me.
Marcos
July 4th, 2007, 11:33 AM
{QUOTE-> I'm so glad that you're here.
Not that secre!
It'a a technical way , some virus maker told me. <-QUOTE}
Frankly, it's not a secret for antivirus companies; they all are aware of the means how to bypass their scanners.
Galaxykiss
July 4th, 2007, 08:34 PM
hello.
I just want you to Improve NOD32.Sorry for the delay.
To Pass the NOD32 scanning,firstly we pack the virus(using ASPack,PE-AMORE ect),then change the Package code(I don't know how to describe,They just told me do it like this).secondly,NOd32 will fail to unpack the virus and let the user wait more than 50 seconds in this progress.In the end, encrypt the imput and output list ,let NOD32 unpack error directly.
I dosn't good at English, do you know what I meant??
Don johnson
July 4th, 2007, 09:45 PM
{QUOTE-> hello.
I just want you to Improve NOD32.Sorry for the delay.
To Pass the NOD32 scanning,firstly we pack the virus(using ASPack,PE-AMORE ect),then change the Package code(I don't know how to describe,They just told me do it like this).secondly,NOd32 will fail to unpack the virus and let the user wait more than 50 seconds in this progress.In the end, encrypt the imput and output list ,let NOD32 unpack error directly.
I dosn't good at English, do you know what I meant?? <-QUOTE}
In these ways,every av can be bypass very easily.To a virus maker,bypass every av is a very easy thing.
Galaxykiss
July 4th, 2007, 11:15 PM
hi,
if you know how it bypass,So why don't eset improve their product,or just let it pass it?
Don johnson
July 4th, 2007, 11:37 PM
{QUOTE-> hi,
if you know how it bypass,So why don't eset improve their product,or just let it pass it? <-QUOTE}
Please know that,if you improve it,the virus maker also can bypass easily in another ways.This is a inevitable thing.
Galaxykiss
July 5th, 2007, 12:43 AM
future is future ,not now.
In my opinion , If the problem is here ,we shall face it.At least , this improvement can detect more virus from the wild without add another too many virus signerture into the database.I know nod32 is good at protect PC from virus ,but I think this is a good suggestion.
Galaxykiss
July 6th, 2007, 08:54 AM
I wonder how NOD32 officer think of this problem . And as far as I know , the graybird maker have changed the graybird's GEN ,Do you know that ?
The Hammer
July 6th, 2007, 11:56 PM
{QUOTE-> I wonder how NOD32 officer think of this problem . And as far as I know , the graybird maker have changed the graybird's GEN ,Do you know that ? <-QUOTE}Snore. Wake me up when this troll is done. :P
vBulletin® Copyright ©2000-2009, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2009, Wilders Security Forums