PDA

View Full Version : serious cleaning problem in ess and eav


proactivelover
November 16th, 2007, 02:36 PM
when you extract any zip virus by winzip or winrar
after 15 sec thread found window show 3 or 4 time
when you click clean but it show again and again
i donot get this problem in v560
only on v563 and v566

proactivelover
November 16th, 2007, 03:15 PM
i think problem in
version: 1021 (20071101)
cleaner module build: 1021 (01.11.2007)

proactivelover
November 16th, 2007, 03:46 PM
now i explain it
1.a virus in zip file
2.extract it
3.threat found window show i cleck clean
4.again threat window show i click again
5.again

krokodil_bb
November 16th, 2007, 04:22 PM
Also this opposite options are possible, sent to eset as bug in 563 but 566 is the same:
smaller window - cleaned by deleting /file is deleted and moved to quarantine/
bigger window - asking what to do, now with non existing file /if choose leave, in nod log is error because file was moved to quarantine/
log:
16. 11. 2007 22:19:12 Real-time file system protection file C:\VIR\ERR\BOD9\test-fsg.exe probably a variant of Win32/Genetik trojan error while NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\UTILITY\Far\Far.exe.
195154

proactivelover
November 16th, 2007, 04:31 PM
krokodil_bb
please zip this virus and then extract it
please tell if you got same problem that i got

krokodil_bb
November 16th, 2007, 04:41 PM
no i haven't this problem, with my test virus- nod eav show alert only once and after cca 5seconds/ekrn.exe 100% cpu/ after file is extracted.

Maybe your file is detected while is not completely writed on disc, then deleted, winrar detects write error and try writing again?

proactivelover
November 16th, 2007, 04:55 PM
-{ Quote: "no i haven't this problem, with my test virus- nod eav show alert only once and after cca 5seconds/ekrn.exe 100% cpu/ after file is extracted.

Maybe your file is detected while is not completely writed on disc, then deleted, winrar detects write error and try writing again?" }-
i think you have you have choose The medium level automatically
please choose The first level and then extract it
then see three windows

krokodil_bb
November 16th, 2007, 05:13 PM
hi, i changed cleaning level from 1 to 0. but your problem with ess can't replicate in eav30566.
after clean nod show "error while cleaning" dialog, and this error is no more logged...
1.clean,2.error dialog,3.retry,4.end

195157

krokodil_bb
November 16th, 2007, 05:41 PM
so i tryed test your files, is it the same. error dialog is in background and if i ignore this dialog i can clicking to clean many times /20 or more /, each of alert window after "clean" generate new error dialog which is automatically closing after 120 seconds...:wacko:

log:16. 11. 2007 23:32:17 Real-time file system protection file C:\TEMP\love.scr Win32/Yaha.N worm error while (unable to clean) NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: D:\WIN2K\explorer.exe.

195158

proactivelover
November 16th, 2007, 05:45 PM
try to delete it at first then you see threat window again and again
i also have win2ksp4

proactivelover
November 16th, 2007, 05:48 PM
i did not got this error on v560
on v560 when you delete it at first no more window open
but on v563 and v566 when you delete it at first threat window came two time more

krokodil_bb
November 16th, 2007, 05:51 PM
cleaner module is buggy, they know it...

internal error still not fixed
http://www.wilderssecurity.com/showthread.php?t=189445

proactivelover
November 16th, 2007, 05:55 PM
i want to explain this problem from v563
no one beleive me

proactivelover
November 16th, 2007, 06:02 PM
please any admin explain this bug
or it's our job

proactivelover
November 16th, 2007, 06:07 PM
anyone who have cleanig problems like me can take a part in this thread
then i send this thread to eset support they will easily fix it
or forum admin can

Marcos
November 17th, 2007, 05:22 AM
We are investigating it. If a problem is confirmed it will be fixed with an automatic update.

proactivelover
November 17th, 2007, 05:31 PM
marcos i have 9 virus samples i sent to eset support 2 days ago but they did not response if you want samples i will send you

proactivelover
November 22nd, 2007, 02:51 AM
yesterday eset have update cleaner module 1022 (20071121)
but the bug still there

Marcos
November 22nd, 2007, 04:13 AM
It was only a partial fix released yesterday. We made a fix to the real-time protection module as well, it will be available in the future installers.

larryb52
November 22nd, 2007, 07:07 AM
good job on Eset's part, thanks Marcos...

proactivelover
November 22nd, 2007, 10:54 AM
thank marcos
for future fix

krokodil_bb
November 22nd, 2007, 12:23 PM
yesterday eset have update cleaner module 1022 (20071121)

updated ok, but can't find anything about component update in nod events log /log level diagnostics/

- "opposite options", now bigger window is not showed, only smaller but twice
1st "cleaned by deleting - quarantined"
2nd "cleaned by deleting" /now without any error in log file/
- cleaning onehalf virus internal error still not fixed

proactivelover
November 22nd, 2007, 06:24 PM
this day is my lucky
because Marcos and eset support team tell me that they will fix it in future release

ASpace
November 23rd, 2007, 05:24 AM
-{ Quote: "future release" }-


Business release is coming soon , may be new better release of the HE won't be late ::)

THE_BAD_BOY
November 23rd, 2007, 05:40 PM
-{ Quote: "marcos i have 9 virus samples i sent to eset support 2 days ago but they did not response if you want samples i will send you" }-
i been sending over 20 new samples to eset and to kaspersky lab,s every week att the same time .. here its the funny part kaspersky allways respond after 30 minutes confirming they fund malicious software on all sendit files and added to the detection databases very fast ..bot Eset NEVER respond and ONLY ADDED cople of the samples send it ... yeah i think thats really BAD>:(

ASpace
November 24th, 2007, 06:04 AM
http://www.wilderssecurity.com/showpost.php?p=198429&postcount=18