![]() |
|
#1
|
||||
|
||||
|
Hello!
My name is Roman Rasheskiy, I am from Russia. I use Eset Antivirus NOD32, version is 4.0.474. I have infected my computer with Sality, I want to check Eset on disinfection of this malware-sample. Eset deleted all files (and "good" file, e.g. documents, files of programms etc.), which was infected with Sality. I think this fact is not good, because Eset can delete very important user files, but others vendors can clean "good" files and cure infect computer. -- Best regards, Roman Rashevskiy. Last edited by Roman Rashevskiy : February 16th, 2010 at 08:56 AM. |
|
#2
|
||||
|
||||
|
Its a polymorphic virus that targets executable files.
http://www.2-spyware.com/remove-sality.html Once infected its hard to cure those viruses.
__________________
Windows 7 Home premium x64 WEBROOT Secure Anywhere Complete |
|
#3
|
||||
|
||||
|
once i was infected with Virut ( a ploymorphic virus)
It destroyed all my system files.My system crashed. Eset deleted that files but made my system unbootable.
__________________
Windows 7 Home premium x64 WEBROOT Secure Anywhere Complete |
|
#4
|
|||
|
|||
|
It sounds like you infected your computer intentionally so you actually didn't lose any important data. I'd suggest submitting a couple of such files to ESET per the instructions here.
Infected files that cannot be cleaned are NEVER deleted automatically, however, the user can choose to delete them if he's sure the files are not that important or that they can be replaced with a clean copy easily. At any rate, the original files are always stored in quarantine so it's possible to revert to them at a later time, if necessary. If the entire infected file comprises only of the virus itself, it's deleted automatically. |
|
#5
|
||||
|
||||
|
Quote:
But thank you for your help. ![]() I want to tell you, that other vendors realised special cure-procedure in their products and their products don't delete user's files, but cured it, i.e. delete "body" of virus from legitimate (user's files, system files etc.) files. But Eset's products just deletes files with virus, and it is very bad... Last edited by Roman Rashevskiy : February 16th, 2010 at 09:11 AM. |
|
#6
|
||||
|
||||
|
Quote:
![]() Quote:
Quote:
P.S. If you do not mind, I would like to discuss with you this problem in PersonalMessages or Skype. ![]() Last edited by Roman Rashevskiy : February 16th, 2010 at 09:21 AM. |
|
#7
|
||||
|
||||
|
discuss here. That will help us too
![]()
__________________
Windows 7 Home premium x64 WEBROOT Secure Anywhere Complete |
|
#8
|
|||
|
|||
|
Quote:
Are you saying that a backup copy of the original file was not put in quarantine before cleaning(deletion) took place? Quote:
Could you submit the files to ESET as I instructed you before so that we can take a look at them to see if they actually contain also usable code (previously clean file) and cleaning of the files actually fails ? Even if cleaning was not possible for whatever reason, such files should not be deleted automatically by EAV / ESS. |
|
#9
|
||||
|
||||
|
Quote:
Quote:
Quote:
![]() How can I submit files? P.S. What can you say about cured of TDL3? P.P.S. Every day I analyse a lot of malware-samples, which ESET's products not detected, but submit all these samples to ESET with help of standard form for submiting file - it is very inconvenient for me. How can I submit files directly to malware-analysts? |
|
#10
|
|||
|
|||
|
Please submit a couple of files that cannot be cleaned to ESET per the instructions here with this thread's url in the subject.
As for the TDS3 rootkit, we most likely detect it as Olmarik/Kryptik. I barely see files undetected by all protection layers that ESET uses. However, if you come across one feel free to submit it for perusal. |
|
#11
|
||||
|
||||
|
Quote:
Quote:
![]() In my question I mean - "When will ESET's products can remove active TDL3 from computer?" Quote:
![]() |
|
#12
|
|||
|
|||
|
In order to keep discussion on the thread subject and to allow others to participate in the ongoing discussion about the Olmarik/TDL3 rootkit, we've split the thread and created a new one dealing with Olmarik/TDL3. Please continue discussing it here.
|
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|