Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 1 Forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old May 4th, 2003, 07:34 AM
Antarctica's Avatar
Antarctica Antarctica is offline
Very Frequent Poster
 
Join Date: Feb 2003
Posts: 1,377
Default Nod32cc.exe Pack file

Hello,
When I scan my P.C. with TrojanHunter it gives me a report that I have a possible Trojan in C:\Windows\System32\NOD32cc.exe
(Suspicious WWPack32 packed file in Windows system)?
Is that a problem with my AV?
Thank you for your help
__________________
One for all/All for one
  #2  
Old May 4th, 2003, 08:13 AM
Tuulilapsi Tuulilapsi is offline
Regular Poster
 
Join Date: Dec 2002
Posts: 53
Default Re:Nod32cc.exe Pack file

Not so much a problem as a feature, I guess. My memory might be failing me, but I seem to recall NOD installing its control center (NOD32cc.exe) in that location. It's a packed executable, and a default Windows installation doesn't leave any packed executables in the System folder. Many malware programs do hide themselves in the System folder to look 'valid', and since trojans in particular are often packed with an exe packer, it's a good idea to warn about packed files in the System folder - which TrojanHunter does. The NOD file is of course legit and not a trojan, though I don't see why NOD needs to leave packed files in the System folder.
  #3  
Old May 4th, 2003, 09:06 AM
Antarctica's Avatar
Antarctica Antarctica is offline
Very Frequent Poster
 
Join Date: Feb 2003
Posts: 1,377
Default Re:Nod32cc.exe Pack file

Thank you Tuulilapsi for the information. So we will wait to see if some one from Eset can give us the information why NOD would live a packed file in the System Folder
__________________
One for all/All for one
  #4  
Old May 4th, 2003, 09:29 AM
doktor doktor is offline
Infrequent Poster
 
Join Date: Oct 2002
Posts: 2
Default Re:Nod32cc.exe Pack file

Imho, nod32cc.exe should be more likely in C:\Program Files\ESET\....
If you take a closer look on amon.exe, nod32.exe or nod32cc.exe, all are packed by wwpack32... just send the file to eset support to get answer if the file is okay. If they reply you it is okay, the the problem is with Trojan Hunter

Myne nod32cc.exe is 235008 byset long...

  #5  
Old May 4th, 2003, 10:15 AM
sig's Avatar
sig sig is offline
Frequent Poster
 
Join Date: Feb 2002
Posts: 716
Default Re:Nod32cc.exe Pack file

Just for info and comparison purposes, I also have nod32cc.exe in C:\WINDOWS\system32. 232KB.
  #6  
Old May 4th, 2003, 10:28 AM
Tuulilapsi Tuulilapsi is offline
Regular Poster
 
Join Date: Dec 2002
Posts: 53
Default Re:Nod32cc.exe Pack file

Thank you, Sig.

This is not a problem with TrojanHunter - TrojanHunter is doing what it is supposed to do by reporting any packed executables in the System folder. TH isn't saying the file is a trojan, TH is saying the file is suspicious because it is a packed exe file in a folder that does not normally contain packed exe files unless third-party programs have added such files there (a legitimate application like NOD could do it and apparently does, and most trojans do it).

I personally think it's a bad idea for legit programs to leave packed files in the System folder unless it is absolutely necessary. (And when exactly is it ever necessary?)
  #7  
Old May 5th, 2003, 08:36 AM
jan jan is offline
Former Eset Moderator
 
Join Date: Oct 2002
Posts: 804
Default Re:Nod32cc.exe Pack file

Hi Antarctica,

>When I scan my P.C. with TrojanHunter it gives me a report that I have a possible Trojan in C:\Windows\System32\NOD32cc.exe
(Suspicious WWPack32 packed file in Windows system)?
Is that a problem with my AV?

Yes, we used this packer for the current version of NOD32, but not in the v2 anymore. Anyway, it is not dangerous. You will get rid of that in the v2.

Cheers,

jan
  #8  
Old May 5th, 2003, 11:13 AM
Antarctica's Avatar
Antarctica Antarctica is offline
Very Frequent Poster
 
Join Date: Feb 2003
Posts: 1,377
Default Re:Nod32cc.exe Pack file

Thanks jan
__________________
One for all/All for one
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 1 Forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 07:47 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums