Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old September 23rd, 2009, 11:36 AM
Anonymous696's Avatar
Anonymous696 Anonymous696 is offline
Infrequent Poster
 
Join Date: May 2009
Posts: 16
Question 'Exact Audio Copy' detected as- variant of Win32/Adware.ADON

Why does NOD32 detect the installer (eac-0.99pb5.exe; MD5:b20c5add30b64f09fffacf010c4d3f15) of the latest version of 'Exact Audio Copy' (V0.99 prebeta 5) as a variant of Win32/Adware.ADON?

Snip: Link to adware removed. Marcos

Last edited by Marcos : September 23rd, 2009 at 11:50 AM.
  #2  
Old September 23rd, 2009, 11:52 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,195
Default Re: 'Exact Audio Copy' detected as- variant of Win32/Adware.ADON

The package contains the file ebayshortcuts.exe which is currently classified as adware but actually has a more trojan-like behavior as it doesn't inform the user about redirection to ebay through a 3rd party site.
  #3  
Old September 23rd, 2009, 12:58 PM
Anonymous696's Avatar
Anonymous696 Anonymous696 is offline
Infrequent Poster
 
Join Date: May 2009
Posts: 16
Default Re: 'Exact Audio Copy' detected as- variant of Win32/Adware.ADON

Thanks Marcos.

Last edited by Anonymous696 : September 23rd, 2009 at 03:25 PM. Reason: Removed misinformation; read my next post.
  #4  
Old September 23rd, 2009, 03:15 PM
Anonymous696's Avatar
Anonymous696 Anonymous696 is offline
Infrequent Poster
 
Join Date: May 2009
Posts: 16
Default Re: 'Exact Audio Copy' detected as- variant of Win32/Adware.ADON

Me again.

After finding out the installer for EAC(Exact Audio Copy) 0.99 prebeta 4 is also detected by NOD32 as a variant of Win32/Adware.ADON, I did some testing (using Sandboxie and CIS(COMODO Internet Security)'s D+).

[EAC 0.99 prebeta 4]
During installation, there's an option box for 'eBay Icon', which is pre-checked. If (and only if) user leaves this option checked, eBayShortcuts.exe is installed to the newly created directory of, "%APPDATA%\AD ON Multimedia\eBay Shortcuts\".

[EAC 0.99 prebeta 5]
During installation, there's an option box for 'eBay Icon', which is pre-checked. If (and only if) user leaves this option checked, eBayShortcuts.exe is installed to the newly created directory of, "%APPDATA%\Desktopicon\".

In conclusion, if the user un-checks the option box for 'eBay Icon' during installation, eBayShortcuts.exe isn't installed.

PS. I also tested EAC 0.99 prebeta 3's installer, and found it not to have this 'eBay Icon' (eBayShortcuts.exe). NOD32 (correctly) doesn't detect EAC 0.99 prebeta 3's installer as a positive.
  #5  
Old September 23rd, 2009, 03:21 PM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,195
Default Re: 'Exact Audio Copy' detected as- variant of Win32/Adware.ADON

Yes, you can disable protection for a while, install the program and evenually delete ebayshortcuts.exe after installation.
  #6  
Old September 23rd, 2009, 03:35 PM
Anonymous696's Avatar
Anonymous696 Anonymous696 is offline
Infrequent Poster
 
Join Date: May 2009
Posts: 16
Default Re: 'Exact Audio Copy' detected as- variant of Win32/Adware.ADON

Thanks again, Marcos.

Quote:
Originally Posted by Marcos
...delete ebayshortcuts.exe after installation.

This part isn't needed, if...

Quote:
Originally Posted by Anonymous696
...if the user un-checks the option box for 'eBay Icon' during installation, eBayShortcuts.exe isn't installed.
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:37 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums