Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old November 28th, 2006, 12:58 AM
acr1965's Avatar
acr1965 acr1965 is offline
Massive Poster
 
Join Date: Oct 2006
Posts: 4,432
Default Spyware issue causing concern

Yesterday evening my Counterspy active protection started popping up messages that my browser home page was attempting to be changed to some odd web sites. Then I got about 50 pop up messages saying sites were trying to be added to my "trusted list" on my browser. I use IE6, mainly because I had some issues with IE7 (Windows locked up). Anyway, I blocked all attempts.

So I scan with Counterspy, AVG Anti-Spyware and run NOD's scan. The results were very odd (to me, at least). Counterspy said I had iSearch.DesktopSearch (browser plug-in). I did not quaranteen at that time but instead ran AVG Anti-Spyware which said I had Not-A-Virus.Monitor.Win32.SpySweeper. I then ran NOD32 which said I had Win32/Adware.WBug.A application. NOD did not show any findings from the scan, though.

I quaranteened iSearch.DesktopSearch in Counterspy as well as quaranteened Not-A-Virus.Monitor.Win32.SpySweeper in AVG. NOD32 had Win32/Adware.WBug.A in quaranteen already.

Is it safe to keep all these quaranteened or should they try to be deleted? Also, should I send Win32/Adware.WBug.A to ESET for analysis? If so, how is that accomplished?

I find it kinda odd that Counterspy found spyware which it rated as "high risk" but it was not detected by NOD32. Could NOD32 have it as misread spyware?

Any other ideas or suggestions?

Thanks in advance.
  #2  
Old November 28th, 2006, 01:07 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,194
Default Re: Spyware issue causing concern

Please send a log from Hijackthis (http://www.merijn.org/files/hijackthis.zip) to support @ eset.com with a link to this thread.
  #3  
Old November 28th, 2006, 01:59 AM
acr1965's Avatar
acr1965 acr1965 is offline
Massive Poster
 
Join Date: Oct 2006
Posts: 4,432
Default Re: Spyware issue causing concern

Quote:
Originally Posted by Marcos
Please send a log from Hijackthis (http://www.merijn.org/files/hijackthis.zip) to support @ eset.com with a link to this thread.

Ok I'll do that. Do I save the log as a file and attach it to the email?
  #4  
Old November 28th, 2006, 02:03 AM
Blackspear's Avatar
Blackspear Blackspear is offline
Global Moderator
 
Join Date: Dec 2002
Location: Gold Coast, Queensland, Australia
Posts: 15,114
Default Re: Spyware issue causing concern

Quote:
Originally Posted by acr1965
Ok I'll do that. Do I save the log as a file and attach it to the email?
Correct.

Cheers
__________________
"Illegitimis non carborundum"
translation:
"Don't let the bastards grind you down"
U.S. General Joseph W. "Vinegar Joe" Stilwell (1883-1946)
Two Photographers
  #5  
Old November 28th, 2006, 02:17 AM
acr1965's Avatar
acr1965 acr1965 is offline
Massive Poster
 
Join Date: Oct 2006
Posts: 4,432
Default Re: Spyware issue causing concern

sent!!

thanks
  #6  
Old November 28th, 2006, 02:21 AM
ASpace
 
Posts: n/a
Default Re: Spyware issue causing concern

Quote:
Originally Posted by acr1965
sent!!

thanks

Please , keep us informed
  #7  
Old November 28th, 2006, 03:14 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,194
Default Re: Spyware issue causing concern

The log didn't reveal any suspicious file. I assume the adware was found in a file on the disk not registered in the registry (i.e. it wouldn't start with Windows). If AMON shows an alert window, it also tells you what process / application created it.
  #8  
Old November 28th, 2006, 01:52 PM
acr1965's Avatar
acr1965 acr1965 is offline
Massive Poster
 
Join Date: Oct 2006
Posts: 4,432
Default Re: Spyware issue causing concern

Quote:
Originally Posted by Marcos
The log didn't reveal any suspicious file. I assume the adware was found in a file on the disk not registered in the registry (i.e. it wouldn't start with Windows). If AMON shows an alert window, it also tells you what process / application created it.

I checked AMON but there was no alert window. I submitted the Win32/Adware.WBug.A and it appears to be an aim.exe. So maybe it was no big deal. I am concerned with NOD32 not detecting the high risk spyware though- iSearch.DesktopSearch (browser plug-in). I have NOD32 set to Blackspear's recommendations.

How did NOD32 completely miss the browser plug-in spyware? IIRC- it's not the first time NOD32 has allowed high risk spyware to get into my system.
  #9  
Old November 28th, 2006, 01:58 PM
ASpace
 
Posts: n/a
Default Re: Spyware issue causing concern

Quote:
Originally Posted by acr1965
I checked AMON but there was no alert window. I submitted the Win32/Adware.WBug.A and it appears to be an aim.exe. So maybe it was no big deal. I am concerned with NOD32 not detecting the high risk spyware though- iSearch.DesktopSearch (browser plug-in). I have NOD32 set to Blackspear's recommendations.

How did NOD32 completely miss the browser plug-in spyware? IIRC- it's not the first time NOD32 has allowed high risk spyware to get into my system.

Hi ! That's why you keep more than one security software , no one is perfect . NOD32 is one of the best .If you still have the iSearch.DesktopSearch in CounterSpy's quarantine , please submit it to ESET in email samples@eset.com or to support@eset.com , just in case . Thanks

Good luck and less viruses
  #10  
Old November 28th, 2006, 03:37 PM
ejr ejr is offline
Frequent Poster
 
Join Date: Nov 2005
Posts: 538
Default Re: Spyware issue causing concern

Quote:
Originally Posted by acr1965
Yesterday evening my Counterspy active protection started popping up messages that my browser home page was attempting to be changed to some odd web sites. Then I got about 50 pop up messages saying sites were trying to be added to my "trusted list" on my browser. I use IE6, mainly because I had some issues with IE7 (Windows locked up). Anyway, I blocked all attempts.

So I scan with Counterspy, AVG Anti-Spyware and run NOD's scan. The results were very odd (to me, at least). Counterspy said I had iSearch.DesktopSearch (browser plug-in). I did not quaranteen at that time but instead ran AVG Anti-Spyware which said I had Not-A-Virus.Monitor.Win32.SpySweeper. I then ran NOD32 which said I had Win32/Adware.WBug.A application. NOD did not show any findings from the scan, though.

I quaranteened iSearch.DesktopSearch in Counterspy as well as quaranteened Not-A-Virus.Monitor.Win32.SpySweeper in AVG. NOD32 had Win32/Adware.WBug.A in quaranteen already.

Is it safe to keep all these quaranteened or should they try to be deleted? Also, should I send Win32/Adware.WBug.A to ESET for analysis? If so, how is that accomplished?

I find it kinda odd that Counterspy found spyware which it rated as "high risk" but it was not detected by NOD32. Could NOD32 have it as misread spyware?

Any other ideas or suggestions?

Thanks in advance.

With the pace that spyware is evolving, you can't expect any one application to detect everything. NOD32 is a worldclass program, but you should also run at least one designated antispyware program with it.

At different points in time, I have used Spyware Doctor, Spysweeper, and Counterspy (as well as a number of others). I don't think you can go wrong with any of these 3.
  #11  
Old November 28th, 2006, 09:03 PM
acr1965's Avatar
acr1965 acr1965 is offline
Massive Poster
 
Join Date: Oct 2006
Posts: 4,432
Default Re: Spyware issue causing concern

Quote:
Originally Posted by HiTech_boy
Hi ! That's why you keep more than one security software , no one is perfect . NOD32 is one of the best .If you still have the iSearch.DesktopSearch in CounterSpy's quarantine , please submit it to ESET in email samples@eset.com or to support@eset.com , just in case . Thanks

Good luck and less viruses


How do I do that?
  #12  
Old November 29th, 2006, 01:14 AM
ASpace
 
Posts: n/a
Default Re: Spyware issue causing concern

Quote:
Originally Posted by acr1965
How do I do that?

If there is a file quatantined by CounterSpy , you can open its Quarantine section , choose to get out of quarantine , open your mailbox , compose new message , attach that suspected file and send it to samples@eset.com

You'd better first zip it and password-protect it but if you don't know how, don't worry Then you can quarantine it back again
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:11 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums