Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 9th, 2005, 09:58 AM
profhsg profhsg is offline
Regular Poster
 
Join Date: May 2004
Posts: 145
Default Does NOD32 Detect JPEG virus?

Over at the DSL Broadband Security forum they have a thread which indicates that 22 out of 23 antivirus programs were unable to detect the jpeg based virus discovered 6 months ago. NOD32 was among those that missed the virus. In response a number of contributors to that forum posted images indicating that their antivirus now detected the threat. NOD32 was not among those either.

Does NOD32 detect that threat? If it doesn't shouldn't it? If it does shouldn't somebody respond so that NOD32 doesn't get a "bad rap?"

Here is a link to the thread on the other forum:

http://www.dslreports.com/forum/rema...flat~days=9999
  #2  
Old March 9th, 2005, 10:46 AM
JimIT's Avatar
JimIT JimIT is offline
Very Frequent Poster
 
Join Date: Jan 2003
Location: Denton, Texas
Posts: 1,035
Default Re: Does NOD32 Detect JPEG virus?

Quote:
Originally Posted by profhsg
Does NOD32 detect that threat? If it doesn't shouldn't it? If it does shouldn't somebody respond so that NOD32 doesn't get a "bad rap?"
[/url]

There is some debate over whether AV's should detect this particular piece of code. The author has stated that it isn't malicious code or viral, and does not compromise a system. (I quoted the author on this in the thread you reference, and my post has pretty much been ignored.) It appears to be more of a POC or "test" than anything else.

I'm sure it will be detected by all AV's pretty soon--just to quiet the "hysteria", but as of right now the code referenced is about as "harmful" as an eicar test file.
__________________
www.gremiss.com
  #3  
Old March 9th, 2005, 05:30 PM
MAL11
 
Posts: n/a
Default Re: Does NOD32 Detect JPEG virus?

I just downloaded that test file and right away even before i could save it imon detected the zip file as win32/exploit.roxo.a trojan, i let it download neways and extracted the jpg then scanned it and again it detected the win32/exploit.roxo.a in the jpeg file... so it appears that NOD32 DOES infact detect this "exploit"/ code.

Keep up the good work Eset
Marc.
  #4  
Old March 10th, 2005, 01:43 AM
nameless's Avatar
nameless nameless is offline
Very Frequent Poster
 
Join Date: Feb 2003
Posts: 1,122
Exclamation Re: Does NOD32 Detect JPEG virus?

Same here. Would have been nice for the "Delete" button to be enabled, though! What's that all about? "Yeah, there's a trojan... I think I'll just 'leave' it."
Attached Images
 
__________________
They say the only totally secure PC is one that is turned off. So, I showed my PC a photo of my wife! [ba-dum-bum-tsss]
  #5  
Old March 10th, 2005, 01:57 AM
NAMOR's Avatar
NAMOR NAMOR is offline
Very Frequent Poster
 
Join Date: May 2004
Location: Arkham Asylum
Posts: 1,525
Default Re: Does NOD32 Detect JPEG virus?

1. IMON stops it dead in it's tracks before you DL it.
2. NOD will give you the option to Leave, Rename, and Delete if you unzip the file and run a scan.

http://img.photobucket.com/albums/v219/NAMOR/NOD.jpg
  #6  
Old March 10th, 2005, 02:02 AM
nameless's Avatar
nameless nameless is offline
Very Frequent Poster
 
Join Date: Feb 2003
Posts: 1,122
Default Re: Does NOD32 Detect JPEG virus?

Not here. IMON presented the dialog you see above. My only option was to "Leave" it.

Since I don't have two hours per day to devote to NOD32 beta testing, I use the default IMON setting, which is to use compatibility mode exclusively--hence, IMON does not stop it "dead in it's tracks before you DL it" [sic].

And my point is that I don't want to have to unzip it and run a scan. (Actually, you can just scan the ZIP directly.) Why should I have to? If I am downloading a trojan, let me delete it, now!
__________________
They say the only totally secure PC is one that is turned off. So, I showed my PC a photo of my wife! [ba-dum-bum-tsss]
  #7  
Old March 10th, 2005, 02:08 AM
NAMOR's Avatar
NAMOR NAMOR is offline
Very Frequent Poster
 
Join Date: May 2004
Location: Arkham Asylum
Posts: 1,525
Default Re: Does NOD32 Detect JPEG virus?

Well with Blackspear's setup IMON gave me the option to terminate and when unzipping the file AMON gave me the options to Rename and Delete.
http://img.photobucket.com/albums/v219/NAMOR/IMON.jpg


http://img.photobucket.com/albums/v219/NAMOR/AMON.jpg
  #8  
Old March 10th, 2005, 02:09 AM
BourgePD's Avatar
BourgePD BourgePD is offline
Regular Poster
 
Join Date: Sep 2004
Posts: 75
Default Re: Does NOD32 Detect JPEG virus?

When I attempted to dl the *.zip, IMON detected the trojan and terminated the connection. No possibility of infection.
  #9  
Old March 10th, 2005, 02:10 AM
nameless's Avatar
nameless nameless is offline
Very Frequent Poster
 
Join Date: Feb 2003
Posts: 1,122
Default Re: Does NOD32 Detect JPEG virus?

Wow, you found the "HTTP" tab under IMON Setup. Congratulations.
__________________
They say the only totally secure PC is one that is turned off. So, I showed my PC a photo of my wife! [ba-dum-bum-tsss]
  #10  
Old March 10th, 2005, 02:12 AM
NAMOR's Avatar
NAMOR NAMOR is offline
Very Frequent Poster
 
Join Date: May 2004
Location: Arkham Asylum
Posts: 1,525
Default Re: Does NOD32 Detect JPEG virus?

Quote:
Wow, you found the "HTTP" tab under IMON Setup. Congratulations.


Maybe I missed something. What does the HTTP tab have to do with it? I haven't changed any setting under that tab. Only changes settings under the Misc tab.

Last edited by NAMOR : March 10th, 2005 at 02:25 AM.
  #11  
Old March 10th, 2005, 02:37 AM
nameless's Avatar
nameless nameless is offline
Very Frequent Poster
 
Join Date: Feb 2003
Posts: 1,122
Default Re: Does NOD32 Detect JPEG virus?

You can have the download automatically denied on the HTTP tab.

But regarding my original post... Mea culpa. It wasn't IMON at all that caught the trojan; it was the post-download scan that GetRight passed to nod32.exe. You have to use compatibility mode with download managers.
__________________
They say the only totally secure PC is one that is turned off. So, I showed my PC a photo of my wife! [ba-dum-bum-tsss]
  #12  
Old March 10th, 2005, 02:46 AM
BourgePD's Avatar
BourgePD BourgePD is offline
Regular Poster
 
Join Date: Sep 2004
Posts: 75
Default Re: Does NOD32 Detect JPEG virus?

Quote:
Originally Posted by nameless
Wow, you found the "HTTP" tab under IMON Setup. Congratulations.

Heh. Not as if NOD is difficult to use...
  #13  
Old March 10th, 2005, 02:54 AM
NAMOR's Avatar
NAMOR NAMOR is offline
Very Frequent Poster
 
Join Date: May 2004
Location: Arkham Asylum
Posts: 1,525
Default Re: Does NOD32 Detect JPEG virus?

Quote:
it was the post-download scan that GetRight passed to nod32.exe. You have to use compatibility mode with download managers.


Gotcha now I see what you mean. Never used a DL manager before, so I can't comment on it.
  #14  
Old March 10th, 2005, 07:31 AM
FanJ
 
Posts: n/a
Default Re: Does NOD32 Detect JPEG virus?

http://www.nod32.com/scriptless/support/info.htm

NOD32 - v.1.1022 (20050309)

one of the defs included was: Win32/Exploit.Roxo.A
  #15  
Old March 10th, 2005, 08:28 AM
MAL111
 
Posts: n/a
Default Re: Does NOD32 Detect JPEG virus?

I have everything setup in the compatibility for http to higher compatibility, all thats changed is the deep heuristics etc etc.. still detected for me...

Marc.
  #16  
Old March 10th, 2005, 04:47 PM
NAMOR's Avatar
NAMOR NAMOR is offline
Very Frequent Poster
 
Join Date: May 2004
Location: Arkham Asylum
Posts: 1,525
Default Re: Does NOD32 Detect JPEG virus?

I think the problem is that he is using a download manger? Maybe because the DL manager donwloads files in chunk as seperate download?
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:08 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums