Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old January 30th, 2008, 05:01 AM
duijv023's Avatar
duijv023 duijv023 is offline
Frequent Poster
 
Join Date: Feb 2006
Location: Rijnsburg, Netherlands
Posts: 230
Question items detected, and quarantined, but not in threat log

On a server of one of my customers, i see the following odd thing:
three files are quarantined, they seem to be infected:

javavm.exe - a variant of Win32/ServU-Daemon application
server.exe »RAR »clearlogs.exe - Win32/HackTool.Clearlog.A trojan
win.exe »RAR »javavm.exe - a variant of Win32/ServU-Daemon application

I uploaded the files to virustotal.com, and indeed these files seem infected.
BUT (which I think is very, very strange): I see no Threat log items about this

They were quarantined 23-01-2008 at around 17.45 (Dutch time, UTC+1)

scan results were the same then and now (using NOD32 version 2834 (20080130) NT)

Greetings from a rainy Holland
  #2  
Old January 30th, 2008, 06:02 AM
duijv023's Avatar
duijv023 duijv023 is offline
Frequent Poster
 
Join Date: Feb 2006
Location: Rijnsburg, Netherlands
Posts: 230
Default Re: items detected, and quarantined, but not in threat log

In the mean time, I did an EICAR test, threat was logged tot threatlog as is should.
So the mechansim is working as it should

the password A hacktool was "detected, quarantined and deleted" earlier.
After that a full system scan (with all options on) was done and nothing found at that time.
Now a new (full system) scan is running (with defs 2835)
  #3  
Old January 30th, 2008, 07:56 AM
duijv023's Avatar
duijv023 duijv023 is offline
Frequent Poster
 
Join Date: Feb 2006
Location: Rijnsburg, Netherlands
Posts: 230
Default Re: items detected, and quarantined, but not in threat log

scan is still running, but ready with C: disk

c:\windows\temp\INF7988.tmp placed in quarantaine
reason: a variant of WIN32/ServU-Deamon application

no further infections found.

As I see that JavaVM was not the latest version, i upgraded JavaVM to the latest version.
  #4  
Old January 30th, 2008, 04:02 PM
duijv023's Avatar
duijv023 duijv023 is offline
Frequent Poster
 
Join Date: Feb 2006
Location: Rijnsburg, Netherlands
Posts: 230
Default Re: items detected, and quarantined, but not in threat log

after reboot, .tmp file (s) were deleted.
Additional scans did not show any infection anymore.

greetings from Holland
  #5  
Old January 30th, 2008, 04:33 PM
ASpace
 
Posts: n/a
Default Re: items detected, and quarantined, but not in threat log

What a great monologue !

Greetings!
  #6  
Old February 20th, 2008, 04:39 AM
duijv023's Avatar
duijv023 duijv023 is offline
Frequent Poster
 
Join Date: Feb 2006
Location: Rijnsburg, Netherlands
Posts: 230
Default Re: items detected, and quarantined, but not in threat log

Today again at customers; site:
nod23kernel service does not exist anymore

apparently there was an old virus active on the server before we installed NOD32.
I cannot see another explaination. I've installed hundreds of dekstops and numerous servers and never seen this before.

Well that's all for now; going to work, reinstall and hopefully kill the basterd
  #7  
Old February 20th, 2008, 09:15 AM
proactivelover's Avatar
proactivelover proactivelover is offline
Frequent Poster
 
Join Date: Apr 2006
Location: Near Wilders Forums
Posts: 832
Default Re: items detected, and quarantined, but not in threat log

Are You Need Any Help Or Just Telling Us Your Stories
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 03:30 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums