![]() |
|
#26
|
|||
|
|||
|
Quote:
Actually that file Insurrection enclosed does indeed contain the eicar test file. I loaded my old anti virus program (which I will not name) and I clicked on the file he attached and it caught the eicar right away and quarantined it. Does this mean that for those of us who use Nod32 would have been infected if this was a real virus? I am confused. Is this a real problem? |
|
#27
|
|||
|
|||
|
Quote:
Same here - I have Win2000 + SP4 + latest updates. BTW, I'm running on administrator level, but that has nothing to do with the problem since other services such as my anti-Trojan kernel or firewall kernel CANNOT be shut down this way, even as an administrator. Only the nod32krn service can be terminated via the task manager (but it can be restarted using the SERVICES manager). There is no explanation to this, for even those who designed the software would not be able to provide any, so I'm not expecting anyone to be able to shed light on this complete mystery. I just wanted to let everyone know that this issue is far from being an isolated case. :'( |
|
#28
|
|||
|
|||
|
Quote:
|
|
#29
|
|||
|
|||
|
If you're running as an Admin, I don't see why process killing would be a valid concern of yours. Any malicious code could open up a command prompt and use "net stop" to disable Nod32. I don't know of any program that can protect itself from Service Manager.
Another reason to use a sandbox.. |
|
#30
|
|||
|
|||
|
Quote:
Fortunately KAV and Sygate are the two I am aware of. If you try to net stop them, you get an error message that the process can't be terminated (access denied). So it is possible, though I agree with the point that if a malicious code is already running, this is more of a second/third level defense. Definitely it makes job for virus writers harder, because it's not enough for them to just create a trojandropper with ability to terminate AVs and FWs and then download a known file.
__________________
pavel.penaz@gmail.com PGP key |
|
#31
|
|||
|
|||
|
Quote:
![]() |
|
#32
|
||||
|
||||
|
Process Guard by DCS. I use it for this and other things as well.
__________________
Asus P5Q PRO, Intel Q9650 Quad Core 3.0 Ghz GeForce 9800 GTX+, 4GB OCZ DDR 1200 Running Windows 7 x64 |
|
#33
|
|||
|
|||
|
Quote:
Anyway, I'm convinced that Eset will soon make it really difficult for script kiddies to terminate NOD32. |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|