Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old June 16th, 2009, 09:49 PM
MichaelG MichaelG is offline
Infrequent Poster
 
Join Date: Oct 2007
Posts: 11
Thumbs down NOD 32 v.4 completly missed a virus..

NOD 32 v.4 completely missed a virus..

Well its managed to miss Global.exe completely which arrived on a customers flash stick.. I now have a computer thats infected up to the eyeballs and now nod 32 has decided to clean all exe files on the said pc... after infection what use is that ??

what a mess, ive never had a problem with older versions of this software.. this is going into the bin if i have to reformat the drive.


regards

Michael
  #2  
Old June 17th, 2009, 02:32 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,191
Default Re: NOD 32 v.4 completly missed a virus..

Every AV program misses threats, that's a matter of fact. There's no solution that would detect 100% of all threats. Refere here for instructions how to submit unrecognized suspicious files to ESET for analysis.

As for formatting, it's not inevitable when malware is found running on a computer. Simply remove it either with assistence of ESET's customer care people or using free tools that are available on the Internet.
  #3  
Old June 17th, 2009, 04:56 AM
Eagle Creek's Avatar
Eagle Creek Eagle Creek is offline
Global Moderator
 
Join Date: Jul 2004
Location: The Netherlands
Posts: 726
Default Re: NOD 32 v.4 completly missed a virus..

Hi Michael,

I run NOD32 at my laptop and I got a infected USBstick from a colleague. My NOD32 detected this and prevented my laptop from getting infected.
Later I scanned the file with Kaspersky at home and it didn't find anything. In fact, when I uploaded it at Virustotal only 50% of the scanners found the virus, altough it really was one (I tested in a VM).

Like Marcos said; every scanner will miss a threat now and then. This time it was NOD32, previous time it was my Kaspersky.
__________________
Nucia, a safe place in an unsafe world
Because the best way to kill malware, is to kill it together.


When you encounter seemingly good advice that contradicts other seemingly good advice, ignore them both.
  #4  
Old June 17th, 2009, 09:44 AM
MichaelG MichaelG is offline
Infrequent Poster
 
Join Date: Oct 2007
Posts: 11
Default Re: NOD 32 v.4 completly missed a virus..

yes nod32 cleans usb autorun files quite well..

Marcos: Nod32 is supposed to catch all known threats and Global.exe isnt exacly a new threat..

But its not supposed to miss a well know virus like Global.exe and it decided to try and clean after its connected to the internet and downloaded a load of other infected exes... i had to reformat the drive every time it found an association with Global.exe and its many addons it removed them but the infection replaced itself instantly leaving me with nod32 just going into a loop.... even in safe mode... every program exe file on the pc became infected according to nod32..

in the bin it goes and paypal to Kaspersky
  #5  
Old June 17th, 2009, 09:48 AM
funkydude's Avatar
funkydude funkydude is offline
Massive Poster
 
Join Date: Apr 2004
Posts: 5,996
Default Re: NOD 32 v.4 completly missed a virus..

How are you quoting a filename as a popular virus? A virus can have any filename under the sun, and nod32 detects all viruses in the wild.
__________________
OpenDNS with DNSCrypt

SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs
HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere
  #6  
Old June 17th, 2009, 10:22 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,191
Default Re: NOD 32 v.4 completly missed a virus..

Global.exe can be anything from adware to a file infecting virus. A file name does not tell anything about what kind of malware it is.
  #7  
Old June 17th, 2009, 01:21 PM
kriebly's Avatar
kriebly kriebly is offline
Infrequent Poster
 
Join Date: Dec 2008
Location: Northern California
Posts: 41
Default Re: NOD 32 v.4 completly missed a virus..

Quote:
Originally Posted by MichaelG
NOD 32 v.4 completely missed a virus..

Well its managed to miss Global.exe completely which arrived on a customers flash stick..

Michael, is autorun still enabled on your system? If so, be sure to disable it. For xp:

http://antivirus.about.com/od/securi...ht/autorun.htm

For Vista:

http://antivirus.about.com/od/securi...ta_autorun.htm
  #8  
Old June 17th, 2009, 03:42 PM
Echofig Echofig is offline
Infrequent Poster
 
Join Date: Jun 2009
Posts: 10
Default Re: NOD 32 v.4 completly missed a virus..

You should check you advanced settings. You are able to disable real-time file system protection from Removable media.
  #9  
Old June 17th, 2009, 03:48 PM
steve1955's Avatar
steve1955 steve1955 is offline
Very Frequent Poster
 
Join Date: Feb 2004
Location: Sunny(in my dreams)Manchester,England
Posts: 1,237
Default Re: NOD 32 v.4 completly missed a virus..

NOD 32 v.4 completely missed a virus..
Is that worse than just "missed a virus":-I would have thought they were both the same!every AV misses things from time to time,its a fact of life and something we've all got to live with!
__________________
The part of a computer that causes most problems is the bit that holds the mouse!
  #10  
Old June 17th, 2009, 03:49 PM
SternMan SternMan is offline
Infrequent Poster
 
Join Date: Aug 2008
Posts: 31
Default Re: NOD 32 v.4 completly missed a virus..

Yesterday sent to the laboratory file
~VirusTotal link removed per forum Policy.~
, no response so far.

Help, all system is infected with them

Last edited by ronjor : June 17th, 2009 at 05:28 PM. Reason: Remove link
  #11  
Old June 17th, 2009, 04:20 PM
berryracer's Avatar
berryracer berryracer is offline
Very Frequent Poster
 
Join Date: Jan 2008
Location: Dubai, UAE
Posts: 1,640
Question Re: NOD 32 v.4 completly missed a virus..

have you applied the blackspear settings dude?
__________________
ASUS G75VW-T1086V
CPU: i7-3610QM 2.30/3.30 GHz.
Memory: 16 GB DDR3 1600 Mhz. RAM
Storage: 256GB SSD + 1TB HDD
Graphics: GeForce GTX 670M 3GB
Screen: 17.3' Full HD LED Screen
  #12  
Old June 17th, 2009, 05:29 PM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,191
Default Re: NOD 32 v.4 completly missed a virus..

Blackspear's settings are not recommended. Default settings provide best balance between protection and performance.
  #13  
Old June 17th, 2009, 05:30 PM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,191
Default Re: NOD 32 v.4 completly missed a virus..

Quote:
Originally Posted by SternMan
Yesterday sent to the laboratory file

Did you actually send it to samples[at]eset.com per the instructions here?
  #14  
Old June 17th, 2009, 06:46 PM
bradtech
 
Posts: n/a
Default Re: NOD 32 v.4 completly missed a virus..

Disabling Autorun is kind of a drastic action much like disabling vbs association back in the day when vbs worms spread.. A sound software restriction policy, non administrator rights, and NOD32 have proven to be very effective against autorun attacks. I am very happy with the detection rates, and prevention I see.. Only thing that has really got past is fake AVs which NOD32 added to their detection list in 48 hours after I submitted..
  #15  
Old June 17th, 2009, 06:58 PM
kriebly's Avatar
kriebly kriebly is offline
Infrequent Poster
 
Join Date: Dec 2008
Location: Northern California
Posts: 41
Default Re: NOD 32 v.4 completly missed a virus..

Quote:
Originally Posted by bradtech
Disabling Autorun is kind of a drastic action much like disabling vbs association back in the day when vbs worms spread..
How so? Is having to double-click on a program on the CD-ROM or USB-stick significantly harder than having the program Start menu pop up automatically?

Apple for its part had ditched autorun by the time OSX came out.

Quote:
A sound software restriction policy, non administrator rights, and NOD32 have proven to be very effective against autorun attacks.
I don't doubt that, but aren't the first two items you listed more complicated for the average user to implement than turning off autorun?
  #16  
Old June 18th, 2009, 02:27 AM
Eagle Creek's Avatar
Eagle Creek Eagle Creek is offline
Global Moderator
 
Join Date: Jul 2004
Location: The Netherlands
Posts: 726
Default Re: NOD 32 v.4 completly missed a virus..

Not sure if you could call Disabling Autorun drastic. I don't like it very much either, but it seems the best advice at the moment. Microsoft even has made several changes in Windows 7 causing USB not to autorun anymore, by default.

It's always usability vs security..
__________________
Nucia, a safe place in an unsafe world
Because the best way to kill malware, is to kill it together.


When you encounter seemingly good advice that contradicts other seemingly good advice, ignore them both.
  #17  
Old June 19th, 2009, 07:15 AM
lumpeh lumpeh is offline
Infrequent Poster
 
Join Date: Sep 2008
Posts: 13
Default Re: NOD 32 v.4 completly missed a virus..

I personally wouldn't have a desktop that has USB sticks going into it from unknown sources, running as admin
  #18  
Old June 19th, 2009, 06:08 PM
piranha's Avatar
piranha piranha is offline
Frequent Poster
 
Join Date: Mar 2005
Location: Laval, Québec, Canada
Posts: 623
Default Re: NOD 32 v.4 completly missed a virus..

Quote:
Originally Posted by Marcos
Blackspear's settings are not recommended. Default settings provide best balance between protection and performance.



BS tutorial (and settings included) is sticky, it looks very much like as recommended, may be you should add a warning
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 02:12 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums