Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 16th, 2010, 02:14 PM
nosferatupc nosferatupc is offline
Infrequent Poster
 
Join Date: Mar 2010
Posts: 4
Exclamation New NOD32 v4.2 Trojan In Registry!

After install nod32 antivirus v4.2 downloaded from www.eset.eu, malwarebytes antimalware and spyware doctor also found trojan in windows registry keys.Is this fake or real?I dont know,please help!Old version nod32 v4.0 has been clean.

Malwarebytes' Anti-Malware 1.44
Database version: 3510
Windows 6.1.7600
Internet Explorer 8.0.7600.16385

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe (Security.Hijack)HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe (Security.Hijack)

Last edited by nosferatupc : March 16th, 2010 at 02:46 PM. Reason: High Fonts In Title
  #2  
Old March 16th, 2010, 02:23 PM
Thankful Thankful is offline
Very Frequent Poster
 
Join Date: Feb 2005
Location: New York City
Posts: 2,407
Default Re: new nod32 v4.2 trojan in registry!

More detail here:
http://www.wilderssecurity.com/showthread.php?t=267595
Funny though, I've never received an alert from Malwarebytes on this issue.
  #3  
Old March 16th, 2010, 02:40 PM
nosferatupc nosferatupc is offline
Infrequent Poster
 
Join Date: Mar 2010
Posts: 4
Post Re: NEW NOD32 v4.2 TROJAN IN REGISTRY!

Thanks for fast reply!This is first time in v4.2 that found this.Before installation I checked whole HD and computer has been clean from spyware trojan etc.After setup I scan again and trojan found.Seems this is false positive alert between nod antivirus and anti spyware software.Im not sure?!
  #4  
Old March 16th, 2010, 03:42 PM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,193
Default Re: NEW NOD32 v4.2 TROJAN IN REGISTRY!

Unless the "Debugger" value under that key is not flagged, you can consider it FP. The references to qgui.exe and ekrn.exe in the aforementioned registry key are indeed created by ESET.
  #5  
Old March 16th, 2010, 04:18 PM
nosferatupc nosferatupc is offline
Infrequent Poster
 
Join Date: Mar 2010
Posts: 4
Default Re: NEW NOD32 v4.2 TROJAN IN REGISTRY!

I deleted this registry keys but I want to know is this two keys important for nod32 software functioning?For which purpose is this?Is it better leave or remove?

Last edited by nosferatupc : March 16th, 2010 at 06:33 PM.
  #6  
Old March 19th, 2010, 04:35 PM
Thankful Thankful is offline
Very Frequent Poster
 
Join Date: Feb 2005
Location: New York City
Posts: 2,407
Default Re: New NOD32 v4.2 Trojan In Registry!

http://www.wilderssecurity.com/showp...4&postcount=13
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 04:11 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums