![]() |
|
#1
|
||||
|
||||
|
How many packers does the current version of NOD support?
Will this improve in new version 3? Also, the same question on archives. Thanks in advance.
__________________
http://www.eff.org/ `snip ` snip |
|
#2
|
||||
|
||||
|
hope they will, they are not supporting 7z and ace archives and many packers.... see here: http://avtest.mycity.co.yu/modules/n...php?storyid=29
__________________
--------------------------------------------------- My security apps: Avira AntiVir Premium * Comodo Firewall PRO * Malwarebytes Anti-Malware * Firefox with Adblock and NoScript |
|
#3
|
|||
|
|||
|
Heh, you are refering to a 1-year old test. AH uses a generic unpacker which they didn't mention !
|
|
#4
|
|||
|
|||
|
Does NOD32 support PPMd and bzip2 compression? Winzip 10 has this feature and it scares me that NOD32 tells me it's an unknown compression format.
|
|
#5
|
||||
|
||||
|
Quote:
Does the NOD AH generic unpacker now or will support these packers/crypters and the plethora of other/newer ones? NOD32 2.12.4 - May 2005 (the old test) "missed 23/30 tested" "armprotector, cexe, codesrypt, lamecrypt, mew11, mslrh, nfo, noodlecrypt, packman, pe-crypt, pecompact2, ped, pelocknt, perkypt4, pepack, peshield,pespin,pex, upack, vgcrypt, wwpack32, yodacrypt, yodaprotect." http://avtest.mycity.co.yu/fajlovi/u...tabela_en.html
__________________
http://www.eff.org/ `snip ` snip |
|
#6
|
|||
|
|||
|
Maybe not so important (since archives themselves aren't really any threat), but even if the test is a bit old, 7z and ACE archive support is still missing in NOD.
|
|
#7
|
||||
|
||||
|
Quote:
Of course you have AH with generic unpacker but that doesn't solve everything. I have some files packed and NOD can't unpack them. And about .ACE archive support this is a very common archive type and also 7z started to be. Can't you update the archive support module to solve this issue? ![]()
__________________
--------------------------------------------------- My security apps: Avira AntiVir Premium * Comodo Firewall PRO * Malwarebytes Anti-Malware * Firefox with Adblock and NoScript |
|
#8
|
|||
|
|||
|
Yes, we will do so in the future. Or you want us to postpone the development of v3? :-)
|
|
#9
|
||||
|
||||
|
no, no....I just want some screen-shots
![]()
__________________
--------------------------------------------------- My security apps: Avira AntiVir Premium * Comodo Firewall PRO * Malwarebytes Anti-Malware * Firefox with Adblock and NoScript |
|
#10
|
|||
|
|||
|
It's not up to me, I've seen it only once anyway.
|
|
#11
|
||||
|
||||
|
From CSA, NOD32 Authorised Partner (http://www.nod32-av.com):
Quote:
I don't think this is a complete list, however, as many more packers should be supported via the generic unpack engine. You can also see this page for a test from CheckVir about NOD32's archive support (Jan. 2006): http://www.checkvir.com/index.php?CN=30.3.46.7&CIE=0 However, NOD32 seems not to support self-extracting ZIP or ACE files.
__________________
Last edited by Radu : Today, at 5:32 AM. Reason: Found new malicious code |
|
#12
|
||||
|
||||
|
Quote:
__________________
kiss my pig |
|
#13
|
||||
|
||||
|
Thank you Firecat =)
Quote:
__________________
http://www.eff.org/ `snip ` snip |
|
#14
|
|||
|
|||
|
Er.. what about the 2 kinds of compression by Winzip 10?
|
|
#15
|
||||
|
||||
|
WinZIP is just "rebranded" crap with few useless compressions.
If you want powerful compression you go with PAQ/RAR/LZMA(7-zip->7z), if you want compatibility you go with standard ZIP (Deflate). Those stupid Deflate64 are mostly useless. Just a bit better compression than standard Deflate and 64bit extension support (longer filenames, over 2GB support etc). If you want alround archiving you use RAR or LZMA (7z). PPMd is also supported in 7-zip and is much better than the one in WinZip 10. Not to mention 7-zip is free and WinZip 10 is not. A bit offtopic though...
__________________
RejZoR's Little Secrets |
|
#16
|
||||
|
||||
|
My opinion is : these packed files, if malware (and also if legit, but it's not really the topic) must be extracted / unpacked / decrypted, before they can be run.
If any antivirus catches the malware on unpacking before it runs, then the computer is protected, regardless of the number of unpackers it supports. That is for real time protection. Now I agree that for on-demand scanning it can be useful to support more formats, just for, say, enhanced security purposes, and to check you don't send an infected file to someone, for example.
__________________
IcePanther Laptop : Asus G51Vx | T9600@2*2.8GHz | 8GB DDR2 800Mhz | GeForce GTX260M 1 GB | 2*240GB Vertex2 SSD| 1920*1080 15.6" screen OS : Windows 7 Professional x64 Resident security : ESS 5.0.84.0 (RC) |
|
#17
|
||||
|
||||
|
That doesn't apply for runtime packers though and these are the most important.
__________________
RejZoR's Little Secrets |
|
#18
|
||||
|
||||
|
Hi
I may not know what exaclty a runtime packer is, but I understand it as a compressed code that's uncompressed at runtime (when it is called / needed) by another part of the code, so it's hiden until the file unpacks it when running... I agree in this particular case, supporting the more (or having a generic detection way) packers would be a good thing, or allowing a code to load *in memory (necessarily unpacked to be run)* then scan/clean the memory, before allowing the code to be run. But this would be another thing, and probably would slow down the computer.
__________________
IcePanther Laptop : Asus G51Vx | T9600@2*2.8GHz | 8GB DDR2 800Mhz | GeForce GTX260M 1 GB | 2*240GB Vertex2 SSD| 1920*1080 15.6" screen OS : Windows 7 Professional x64 Resident security : ESS 5.0.84.0 (RC) |
|
#19
|
||||
|
||||
|
Quote:
__________________
AntiVir Premium ▪ FD-ISR Pro ▪ Firefox 3 ▪ Jetico 2 Firewall ASAP Member |
|
#20
|
||||
|
||||
|
Okay ^^ Thanks for the info, I had seen this UPX name numerous time when mentioning runtime packers indeed, i'll see on their site for more info and i'll test it on some software of my own to see by myself...
__________________
IcePanther Laptop : Asus G51Vx | T9600@2*2.8GHz | 8GB DDR2 800Mhz | GeForce GTX260M 1 GB | 2*240GB Vertex2 SSD| 1920*1080 15.6" screen OS : Windows 7 Professional x64 Resident security : ESS 5.0.84.0 (RC) |
|
#21
|
||||
|
||||
|
Also using UPX: http://nod32sse.hotserv.dk/scanwarning.php
![]()
__________________
AntiVir Premium ▪ FD-ISR Pro ▪ Firefox 3 ▪ Jetico 2 Firewall ASAP Member |
|
#22
|
||||
|
||||
|
Quote:
Quote:
__________________
1. What is right is always The Truth. 2. Every Truth is supported in agreement by every Truth. 3. If the facts would persuade you otherwise, see 1. ESET Reseller (Australia) |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|