Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > ESET Smart Security v3 Beta Forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #26  
Old April 8th, 2007, 08:31 AM
fosius's Avatar
fosius fosius is offline
Frequent Poster
 
Join Date: Oct 2004
Location: Partizanske, Slovakia
Posts: 479
Default Re: antivirus

Quote:
Originally Posted by cupez80
where ? i cant find it

Settings -> Antivirus protection -> Resident protection -> Run editor of extensions -> And Metods..

But I use Slovak version so the translation doesn't have to be the same..
__________________
Eset NOD32 Antivirus on Vista Business (UAC enabled)
  #27  
Old April 8th, 2007, 01:11 PM
Alith Alith is offline
Regular Poster
 
Join Date: Oct 2004
Posts: 69
Default Re: antivirus

Thanks for the link to Beta MNKid.
  #28  
Old April 8th, 2007, 01:13 PM
rogervernon's Avatar
rogervernon rogervernon is offline
Frequent Poster
 
Join Date: Jul 2006
Posts: 281
Default Re: antivirus

The anti-virus failed to detect this Eicar test file, sent as an attachment to an email from Panda. The event did not appear in the log files either.
Here is`a screen shot pf part of Panda's email to me, showing the test as a Word document as the attachment. When executed , Word opens & shows a small picture labeled "Eicar"
http://i115.photobucket.com/albums/n.../EicarTest.jpg
  #29  
Old April 8th, 2007, 09:22 PM
cupez80's Avatar
cupez80 cupez80 is offline
Frequent Poster
 
Join Date: Jun 2005
Location: Surabaya Indonesia
Posts: 594
Default Re: antivirus

Quote:
Originally Posted by fosius
Settings -> Antivirus protection -> Resident protection -> Run editor of extensions -> And Metods..

But I use Slovak version so the translation doesn't have to be the same..
that not what i mean. in version 2.x even you activated Advanced Heuristic it wont scan file on-execution. what im asking is AH enabled on-execution not only on-create and on-modification
  #30  
Old April 8th, 2007, 10:07 PM
Sjoeii's Avatar
Sjoeii Sjoeii is offline
Very Frequent Poster
 
Join Date: Aug 2006
Location: 52°18'51.59"N + 4°56'32.13"O
Posts: 1,240
Default Re: antivirus

Quote:
Originally Posted by rogervernon
The anti-virus failed to detect this Eicar test file, sent as an attachment to an email from Panda. The event did not appear in the log files either.
Here is`a screen shot pf part of Panda's email to me, showing the test as a Word document as the attachment. When executed , Word opens & shows a small picture labeled "Eicar"
http://i115.photobucket.com/albums/n.../EicarTest.jpg
Strange it was detected over here.
Can't confirm
  #31  
Old April 9th, 2007, 01:42 AM
lucas1985's Avatar
lucas1985 lucas1985 is offline
Global Moderator
 
Join Date: Nov 2006
Location: France, May 1968
Posts: 4,047
Default Re: antivirus

Quote:
Originally Posted by Firecat
The "cleaning" feature will become significant in future versions. I was told in brief about this back in 2005, and it looks very good on paper.
Are you allowed to share more info about this with us?
Thanks for this feedback
__________________
"Pouvoir ŕ l'Imagination. Power to the imagination. La imaginación al poder".

"Perfect is the enemy of good enough". Voltaire.
  #32  
Old April 9th, 2007, 02:43 AM
Brian N's Avatar
Brian N Brian N is offline
Very Frequent Poster
 
Join Date: Jul 2005
Location: Denmark
Posts: 2,150
Default Re: antivirus

Quote:
Originally Posted by rogervernon
The anti-virus failed to detect this Eicar test file, sent as an attachment to an email from Panda. The event did not appear in the log files either.
Here is`a screen shot pf part of Panda's email to me, showing the test as a Word document as the attachment. When executed , Word opens & shows a small picture labeled "Eicar"
Panda sends a doc file and if you take a look inside, the eicar code actually changes and so does the file size.
I've never been able to detect anything sent from Panda myself while using NOD32.
You need either a txt, com or an archive. You can also try this one instead: http://nod32sse.com/avtest.php
__________________
AntiVir PremiumFD-ISR ProFirefox 3Jetico 2 Firewall
ASAP Member
  #33  
Old April 9th, 2007, 03:23 AM
Firecat's Avatar
Firecat Firecat is offline
Incredibly Massive Poster
 
Join Date: Jan 2005
Location: The land of no identity :D
Posts: 7,672
Default Re: antivirus

Quote:
Originally Posted by lucas1985
Are you allowed to share more info about this with us?
Thanks for this feedback
I wasn't told too much about it anyway, but there was talk about a "special cleaning" mechanism, which would be able to at least partially remove even unknown malware (i.e. heuristic detections). Registry entries of even heuristic detections may be cleaned and perhaps other leftovers too.
__________________
Last edited by Radu : Today, at 5:32 AM. Reason: Found new malicious code

  #34  
Old April 9th, 2007, 04:59 PM
lucas1985's Avatar
lucas1985 lucas1985 is offline
Global Moderator
 
Join Date: Nov 2006
Location: France, May 1968
Posts: 4,047
Default Re: antivirus

Thanks Firecat
__________________
"Pouvoir ŕ l'Imagination. Power to the imagination. La imaginación al poder".

"Perfect is the enemy of good enough". Voltaire.
  #35  
Old April 9th, 2007, 05:04 PM
ASpace
 
Posts: n/a
Default Re: antivirus

Quote:
Originally Posted by Brian N
I've never been able to detect anything sent from Panda myself while using NOD32

Oh , no , I tried this test of theirs while I was using their products (Titanium and Platinum 2005/2006) . I always received the email and it never got detected by Panda . Which is very silly because they say "if your securiry products misses it then buy our products" ... and a loopback ... Tests on eicar.org always work with all AVs but in a DOC , the strings gets changed , I think
  #36  
Old April 9th, 2007, 05:27 PM
Doc Serenity Doc Serenity is offline
Regular Poster
 
Join Date: Apr 2007
Posts: 105
Default Re: antivirus

Quote:
Originally Posted by Brian N
Panda sends a doc file and if you take a look inside, the eicar code actually changes and so does the file size.
I've never been able to detect anything sent from Panda myself while using NOD32.
You need either a txt, com or an archive. You can also try this one instead: http://nod32sse.com/avtest.php

This could definitely mess with my serenity. If I unserstand you correctly, the av I'm using and really like has not been able to deal w/Panda's tests.
I'm suddenly feeling more than a little concerned.
Doc
  #37  
Old April 9th, 2007, 05:34 PM
Brian N's Avatar
Brian N Brian N is offline
Very Frequent Poster
 
Join Date: Jul 2005
Location: Denmark
Posts: 2,150
Default Re: antivirus

Quote:
Originally Posted by Doc Serenity
This could definitely mess with my serenity. If I unserstand you correctly, the av I'm using and really like has not been able to deal w/Panda's tests.
I'm suddenly feeling more than a little concerned.
Doc
It won't detect it because it's not an eicar test after it's been altered by the doc. If they made regular txt or archives, there wouldn't be a problem with their tests.

And there's no need to worry really - Normal eicar tests are detected by NOD32 just fine.
__________________
AntiVir PremiumFD-ISR ProFirefox 3Jetico 2 Firewall
ASAP Member
  #38  
Old April 9th, 2007, 10:06 PM
Doc Serenity Doc Serenity is offline
Regular Poster
 
Join Date: Apr 2007
Posts: 105
Default Re: antivirus

Thank you.
All better now.
Doc
  #39  
Old April 10th, 2007, 09:17 AM
rogervernon's Avatar
rogervernon rogervernon is offline
Frequent Poster
 
Join Date: Jul 2006
Posts: 281
Default Re: antivirus

I re-loaded AVG anti spyware and on a scan it found this:- Win32.Worm.Luder.
This had not been found by either ESS or KIS on regular scans.
Could it have been lurking in Sys Restore? Can ESS scan there?
Or is it a "falsie"?
  #40  
Old April 10th, 2007, 09:55 AM
ASpace
 
Posts: n/a
Default Re: antivirus

Quote:
Originally Posted by rogervernon
Could it have been lurking in Sys Restore? Can ESS scan there?
Don't know where it is , you only know . Yes , ESS can scan there.


Quote:
Originally Posted by rogetvernon
Or is it a "falsie"?
Have no idea , may be . VirusTotal knows more for sure . If it appears to real malware , send a copy of it to ESET Virus Lab to email samples @ eset . com
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > ESET Smart Security v3 Beta Forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 12:50 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums