Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old February 28th, 2009, 11:02 AM
Tetranitrocubane Tetranitrocubane is offline
Infrequent Poster
 
Join Date: Nov 2007
Posts: 11
Default NOD32 not allowing actions on detected threats

Hi everyone. Please bear with me on this, as I've no idea what's going on.

I was browsing the web with Opera, and hit upon a site that's usually trusted. For some reason, though, it popped up an AMON Threat detection. The site also tired to redirect me to another website, but I think that either my HOSTS file blocked it, or I closed the page before it loaded. I'm not sure.

The Alert details are as follows:

----

File: C:\Documents and Settings\{My username}\Local Settings\Application Data\Opera\Opera...\op0XS46

Threat: SWF/TrojanDownloader.Agent.NAJ trojan

Comment:
Event occurred on a file modified by the application: C:\Program Files\Opera\opera.exe. This file was moved to quarantine. You may close this window.

----

(The actual file path was: C:\Documents and Settings\{My username}\Local Settings\Application Data\Opera\Opera\profile\cache4\op0XS46 )

The options to Copy to Quarantine, Submit for analysis, clean, delete, and rename are all greyed out. I can only check the 'Display warning window' button, and close the threat detection window.

I'm a little disturbed by this. I suppose it's possible that this site I was checking had been hijacked and infused with something malicious. The more pressing issue, though, is that I don't know why NOD won't let me clear or delete this file! There's no record of it in the control center Threat log, either. The file looks like it's in quarantine, but I'm wondering what the best course of action is now.

Did NOD catch this before it became a problem? Or should I take some more serious measures? A scan didn't come up with anything subsequent, but I don't know if the infection compromised NOD, seeing as I couldn't clean or delete the file after it was detected - I could only dismiss the Threat Detection window.

Any help would be appreciated. Thanks!
  #2  
Old February 28th, 2009, 01:56 PM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,192
Default Re: NOD32 not allowing actions on detected threats

You can install EAV v3 and switch the cleaning mode to No cleaning so that you're always prompted for an action when a threat is found.
  #3  
Old February 28th, 2009, 08:54 PM
Tetranitrocubane Tetranitrocubane is offline
Infrequent Poster
 
Join Date: Nov 2007
Posts: 11
Default Re: NOD32 not allowing actions on detected threats

Quote:
Originally Posted by Marcos
You can install EAV v3 and switch the cleaning mode to No cleaning so that you're always prompted for an action when a threat is found.

After a bit of investigation, it seems that this particular virus is actually just a malicious SWF file that's intended to be scareware. It doesn't install anything on it's own, so the only files that were infected seemed to be in the cache. I guess that's why there wouldn't be a 'fix' option, and NOD automatically must have quarantined the file. From what I saw, I thought it just found the file and wouldn't allow me to take an action, but I guess it was automatic!

I've also been meaning to look into v3 for a while now. Thanks for the advice.
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:39 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums