PDA

View Full Version : exploner.exe is not detected by NOD32 (!)


mahmoodn
November 9th, 2008, 03:20 AM
Hello,
recently my system is infected with a virus but nod32 with latest update and all settings (potentialy unwanted and so on...) can not find it.??? >:(

The symptons are:
"exploner.exe" in the temp folder
"autoplay.exe" in flash dirves
"lsass.exe" which is 473KB and it is in c:\windows.

"lsass" is really fake because it is a user process and not system process which is in system32 folder.

Why NOD32 does not detect it????????>:( >:(

risl
November 9th, 2008, 04:28 AM
Because they don't have a signature for it yet?

You should pack the files to password protected archive and send to ESET, and you'll receive a "cure."

mahmoodn
November 9th, 2008, 04:51 AM
So.... NOD32 is sleep!!!

How should I send to eset? will they reply me?

funkydude
November 9th, 2008, 05:27 AM
You zip the files with the password infected and send them to samples("at")eset.com with this threads URL in the subject.

mahmoodn
November 9th, 2008, 06:27 AM
Ok, I will try this one:)

If you see this page (http://forum.processlibrary.com/showthread.php?t=30915&page=1&pp=10), it is reported 2 month ago!!! eset radar is pointing somewhere else I think....

mahmoodn
November 9th, 2008, 06:45 AM
An interesting thing is that online kaspersky file scanner ALSO DID NOT FIND ANY THREAT:dry: :dry: :ouch:
http://i35.tinypic.com/2pynfie.png

mahmoodn
November 24th, 2008, 02:43 AM
Although eset has not replied me yet, but it seems that they found the threat because yesterday I checked the file with latest update and it alert a threat Win32/AutoRun.Delf.J

the signature is added to update 2008 11 13 http://forums.cnet.com/5208-6132_102-0.html?forumID=32&threadID=316144&messageID=2906424