Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old January 28th, 2008, 08:00 AM
ratboyJ ratboyJ is offline
Infrequent Poster
 
Join Date: Jan 2008
Posts: 6
Default Virus cant fix

1/28/2008 10:51:36 PM HTTP filter file hxxp://comdomen.com/ldr2.exe probably a variant of Win32/Statik application connection terminated - quarantined NT AUTHORITY\SYSTEM Threat was detected upon access to web by the application: C:\WINDOWS\system32\svchost.exe.

I get this ****, i get spammed like every 10 minutes with about 30 logs. Any way that i can fix this

Last edited by ronjor : January 28th, 2008 at 08:05 AM. Reason: Modify link
  #2  
Old January 28th, 2008, 08:11 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,185
Default Re: Virus cant fix

Please send a log from ESET SysInspector to support[at]eset.com with this thread's url enclosed. We'll analyse it and let you know how to remove the threat.
  #3  
Old January 28th, 2008, 08:28 AM
ratboyJ ratboyJ is offline
Infrequent Poster
 
Join Date: Jan 2008
Posts: 6
Default Re: Virus cant fix

Never mind
  #4  
Old January 28th, 2008, 08:42 AM
ratboyJ ratboyJ is offline
Infrequent Poster
 
Join Date: Jan 2008
Posts: 6
Default Re: Virus cant fix

Ok, i sent the file to :support@eset.com: so you can hopefully tell me how i fix this
  #5  
Old January 28th, 2008, 08:54 AM
flyrfan111 flyrfan111 is offline
Very Frequent Poster
 
Join Date: Jun 2004
Posts: 1,224
Default Re: Virus cant fix

Very strange, if you try to download the file you get the alert. If you turn off NOD, download it then scan it you don't get any alert.
  #6  
Old January 28th, 2008, 09:19 AM
Stijnson's Avatar
Stijnson Stijnson is offline
Frequent Poster
 
Join Date: Nov 2007
Location: Paranoia Heaven
Posts: 533
Default Re: Virus cant fix

Quote:
Originally Posted by flyrfan111
Very strange, if you try to download the file you get the alert. If you turn off NOD, download it then scan it you don't get any alert.

I can't find W32/Statik in the def files when searching here: http://www.eset.com/support/updates.php

It's rather strange indeed that you don't get any alert when first downloading the file (NOD32 turned off) and then scanning it manually. Can someone explain how this can be?
  #7  
Old January 28th, 2008, 09:25 AM
ratboyJ ratboyJ is offline
Infrequent Poster
 
Join Date: Jan 2008
Posts: 6
Default Re: Virus cant fix

I didnt go to any site and download this file, i was downloading music from limewire so that might be it.
But i turned on the computer the next day and then straight away i got the--bad file, terminated , then this file was put in quarenteen, then i get log attacks (about 20) every 10 minutes. If i delete the file from quarenteen then it is back in there when i get the attacks
  #8  
Old January 28th, 2008, 11:30 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,185
Default Re: Virus cant fix

Statik is new technology of heuristic detection which is currently being tuned up. Currently it's usually enabled only for IMON/web modules and further modules will follow as soon as the results are analysed and evaluated.
  #9  
Old January 28th, 2008, 11:34 AM
flyrfan111 flyrfan111 is offline
Very Frequent Poster
 
Join Date: Jun 2004
Posts: 1,224
Default Re: Virus cant fix

Ahhh, makes sense now, thanks for the clarification Marcos. So this was an FP, but the Allaple one in the other thread was not, correct?
  #10  
Old January 28th, 2008, 11:58 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,185
Default Re: Virus cant fix

Surely there was a threat listed in ratboyJ's log and the file ldr2.exe looks quite suspicious. I'll pass it to our vlab to make sure it wasn't FP.
  #11  
Old January 28th, 2008, 12:11 PM
Bubba's Avatar
Bubba Bubba is offline
Global Moderator
 
Join Date: Apr 2002
Posts: 11,279
Default Re: Virus cant fix

Quote:
Originally Posted by Marcos
the file ldr2.exe looks quite suspicious
appears so, especially on the un-stripped portion of the file. Sunbelt sandbox had an interesting read also.

What Nod does not like it appears to me as an un-trained analyzer, is the last few entries that it strips from the original as noted in an UltraCompare file comparison

Quote:
VQIY
69:t
J !4
!cMb
XVRWQ
üY_Z
GetStdHandle
kernel32.dll
  #12  
Old January 28th, 2008, 12:21 PM
lucas1985's Avatar
lucas1985 lucas1985 is offline
Global Moderator
 
Join Date: Nov 2006
Location: France, May 1968
Posts: 4,047
Default Re: Virus cant fix

Quote:
Originally Posted by Marcos
Statik is new technology of heuristic detection which is currently being tuned up.
Marcos, this is interesting. Could you elaborate on this a little more? Does NOD32 v2 have access to this heuristic?
Quote:
Originally Posted by Bubba
appears so, especially on the un-stripped portion of the file. Sunbelt sandbox had an interesting read also.

What Nod does not like it appears to me as an un-trained analyzer, is the last few entries that it strips from the original as noted in an UltraCompare file comparison
Do you want to work on a viruslab?
__________________
"Pouvoir à l'Imagination. Power to the imagination. La imaginación al poder".

"Perfect is the enemy of good enough". Voltaire.
  #13  
Old January 28th, 2008, 02:26 PM
ASpace
 
Posts: n/a
Default Re: Virus cant fix

Quote:
Originally Posted by lucas1985
Does NOD32 v2 have access to this heuristic?

I personally have seens this kind of detection (Statik) with v2 , too , so v2 has it , too
  #14  
Old January 28th, 2008, 04:34 PM
nodyforever's Avatar
nodyforever nodyforever is offline
Frequent Poster
 
Join Date: Oct 2007
Location: PT / Lisbon
Posts: 549
Post Re: Virus cant fix

interesting detection (Statik)

Marcos,

Quote:
Currently it's usually enabled only for IMON/web modules and further modules will follow as soon as the results are analysed and evaluated.

If really it is a tool what of more it forces to the modules of the antivirus I support unconditional



VT and Jotti nod32v2 database 2828 not detected virus file.


Detection exclusive antivirus module
__________________
Os: WindowsSeven
Firewall: Eset Personal Firewall
Browser: Google Chrome 13
Real-Time: ESS 5.0.93.0
On-Demand:
Others: ESET SysInspector / Beta Tester Eset / Collaboration website IT
  #15  
Old January 28th, 2008, 10:38 PM
ratboyJ ratboyJ is offline
Infrequent Poster
 
Join Date: Jan 2008
Posts: 6
Default Re: Virus cant fix

So how would i go about removing this virus from my computer

Is there a program that can do this for me or is there a list of files that i can remove from my computer that will fix the problem
  #16  
Old January 29th, 2008, 12:56 AM
ASpace
 
Posts: n/a
Default Re: Virus cant fix

Follow Marcos's advise and ESET representative will tell you what to do (post #2)
  #17  
Old January 29th, 2008, 06:47 AM
ratboyJ ratboyJ is offline
Infrequent Poster
 
Join Date: Jan 2008
Posts: 6
Default Re: Virus cant fix

I did a system restore back to the day that i know i didnt have any problems, and now the problem has been eliminated, Anyway thank you for your support..................PS --It wasnt the music i downloaded from limewire
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 07:09 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums