Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #26  
Old December 2nd, 2003, 08:42 AM
newnoduser
 
Posts: n/a
Default Re:no script checking??, false alarm?! and NO SELF PROTECTION! :(

Quote:
Vigy wrote---"The file you attached does not contain any virus-like code. Because it is interpreted by a web browser, all it does, is write a text on screen. Nothing else. (EICAR is a DOS program interpreted by cmd.exe or command.com)"


Actually that file Insurrection enclosed does indeed contain the eicar test file. I loaded my old anti virus program (which I will not name) and I clicked on the file he attached and it caught the eicar right away and quarantined it.

Does this mean that for those of us who use Nod32 would have been infected if this was a real virus? I am confused.
Is this a real problem?
  #27  
Old December 2nd, 2003, 03:11 PM
Morgoth
 
Posts: n/a
Default Re:no script checking??, false alarm?! and NO SELF PROTECTION! :(

Quote:
can kill both the krn and ui from the task manager...

Same here - I have Win2000 + SP4 + latest updates.

BTW, I'm running on administrator level, but that has nothing to do with the problem since other services such as my anti-Trojan kernel or firewall kernel CANNOT be shut down this way, even as an administrator. Only the nod32krn service can be terminated via the task manager (but it can be restarted using the SERVICES manager).

There is no explanation to this, for even those who designed the software would not be able to provide any, so I'm not expecting anyone to be able to shed light on this complete mystery. I just wanted to let everyone know that this issue is far from being an isolated case. :'(
  #28  
Old December 2nd, 2003, 03:31 PM
Buddel
 
Posts: n/a
Default Re:no script checking??, false alarm?! and NO SELF PROTECTION! :(

Quote:
quoting: puff-m-d link=board=39;threadid=13382;start=15#msg92396 date=1065647549]
... I can kill both the krn and ui from the task manager...
So can I (Windows ME): http://www.wilderssecurity.com/showthread.php?t=17122
  #29  
Old December 2nd, 2003, 10:33 PM
nostril_hair
 
Posts: n/a
Default Re:no script checking??, false alarm?! and NO SELF PROTECTION! :(

If you're running as an Admin, I don't see why process killing would be a valid concern of yours. Any malicious code could open up a command prompt and use "net stop" to disable Nod32. I don't know of any program that can protect itself from Service Manager.

Another reason to use a sandbox..
  #30  
Old December 3rd, 2003, 06:53 AM
Tablet Tablet is offline
Infrequent Poster
 
Join Date: May 2003
Posts: 2
Default Re:no script checking??, false alarm?! and NO SELF PROTECTION! :(

Quote:
I don't know of any program that can protect itself from Service Manager.

Fortunately KAV and Sygate are the two I am aware of. If you try to net stop them, you get an error message that the process can't be terminated (access denied). So it is possible, though I agree with the point that if a malicious code is already running, this is more of a second/third level defense. Definitely it makes job for virus writers harder, because it's not enough for them to just create a trojandropper with ability to terminate AVs and FWs and then download a known file.
__________________
pavel.penaz@gmail.com PGP key
  #31  
Old December 3rd, 2003, 09:07 AM
Buddel
 
Posts: n/a
Default Re:no script checking??, false alarm?! and NO SELF PROTECTION! :(

Quote:
quoting: Tablet link=board=39;threadid=13382;start=15#msg106388 date=1070452399]
Quote:
I don't know of any program that can protect itself from Service Manager.

... If you try to net stop them, you get an error message that the process can't be terminated (access denied). So it is possible, ...
Wouldn't it be great if this were possible for NOD32, too?
  #32  
Old December 3rd, 2003, 08:29 PM
Eliot's Avatar
Eliot Eliot is offline
Frequent Poster
 
Join Date: Aug 2003
Location: Arkansas, USA
Posts: 854
Default Re:no script checking??, false alarm?! and NO SELF PROTECTION! :(

Process Guard by DCS. I use it for this and other things as well.
__________________
Asus P5Q PRO, Intel Q9650 Quad Core 3.0 Ghz
GeForce 9800 GTX+, 4GB OCZ DDR 1200

Running Windows 7 x64
  #33  
Old December 4th, 2003, 02:33 AM
Buddel
 
Posts: n/a
Default Re:no script checking??, false alarm?! and NO SELF PROTECTION! :(

Quote:
quoting: Eliot link=board=39;threadid=13382;start=30#msg106632 date=1070501347]
Process Guard by DCS. I use it for this and other things as well.
This means that my old computer would have to cope with yet another app just to make sure that the NOD processes are not terminated by malware. Wouldn't it be easier if NOD32 itself took care of its running processes?

Anyway, I'm convinced that Eset will soon make it really difficult for script kiddies to terminate NOD32.
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:00 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums