Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 21st, 2008, 08:14 AM
niceTyp niceTyp is offline
Infrequent Poster
 
Join Date: Jul 2008
Posts: 11
Default The reason for these facts.

In the last week I have a problem with a virus and I was curios that NOD32 don't found this virus but over 50% of the Scanner in Virustotal found the virus.
I send a sample to samples@eset.com and it takes over 5 days that eset include the virus in the virus database of Nod32.
I try a similar thing few days ago. and send some rootkits to samples@eset.com 30% of the scanner found the rootkits. But I'm sure that eset needs again 5 or more day to include it in the database.
Why take this sooo many time?

Also this fact make me thing about the quality of Nod32.

http://mtc.sri.com/live_data/av_rankings/

and

http://www.av-comparatives.org

Edit: www.av-comparatives.org only allows posting links to their main website

Last edited by Marcos : July 21st, 2008 at 08:59 AM.
  #2  
Old July 21st, 2008, 08:58 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,185
Default Re: The reason for these facts.

I take liberty to inform you that ESET reserves the right to choose the appropriate priority to submitted samples. Taking into account that thousands of new threats are created on a daily basis, there must be certain priority assigned to each sample based on specific ciriteria. People who submit samples from their systems and enclose additional information are dealt with almost immediately and detection is usually added to one of the upcoming updates.

When refering to a certain test, you should always consider the methodology used. It's important to know the source (ie. samples from honeypots are often corrupt and thus non-functional), what settings were used for testing, what version was used for testing, etc. Each vendor should have a chance to test the samples their AV missed - this would allow us to analyse the files and count the number of non-functional files used in the test.

Last edited by Marcos : July 21st, 2008 at 09:03 AM.
  #3  
Old July 25th, 2008, 06:30 AM
niceTyp niceTyp is offline
Infrequent Poster
 
Join Date: Jul 2008
Posts: 11
Default Re: AV2009 infection?

undetected by Nod32, I have here also 9 rootkits since 5 days and 30% of the scanner detect this files except Nod32 because of the lower priority of such files that often change itself.
  #4  
Old July 25th, 2008, 10:42 AM
GAN GAN is offline
Frequent Poster
 
Join Date: Mar 2007
Posts: 355
Default Re: AV2009 infection?

Quote:
Originally Posted by niceTyp
undetected by Nod32, I have here also 9 rootkits since 5 days and 30% of the scanner detect this files except Nod32 because of the lower priority of such files that often change itself.
And you know for sure those files are infected? Virustotal doesn't always give the correct answer and i have seen a lot of false positives when using virustotal. If only 30% detect a threat i guess nod32 is not alone when not detecting the threat. Certain type of files is often detected as a threat even if that might not be the case.
I'm not necessarily saying those nine samples are clean, but how do you know for sure they are infected?
  #5  
Old July 25th, 2008, 11:21 AM
niceTyp niceTyp is offline
Infrequent Poster
 
Join Date: Jul 2008
Posts: 11
Default Re: The reason for these facts.

now are 15/35 (42.86%) I can send you the files if you want to try.
  #6  
Old July 25th, 2008, 11:28 AM
Bubba's Avatar
Bubba Bubba is offline
Global Moderator
 
Join Date: Apr 2002
Posts: 11,279
Default Re: The reason for these facts.

Quote:
Originally Posted by niceTyp
now are 15/35 (42.86%) I can send you the files if you want to try.
We do not share malware at this site and suggest you
re-read what Marcos wrote above. Also, Support in this forum is not about posting %'s on a daily basis of who's found what.
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 11:48 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums