Trojan Zlob

Discussion in 'NOD32 version 2 Forum' started by ugly, May 27, 2006.

Thread Status:
Not open for further replies.
  1. steve1955

    steve1955 Registered Member

    Joined:
    Feb 7, 2004
    Posts:
    1,384
    Location:
    Sunny(in my dreams)Manchester,England
    Isn't the point(or at least the main one!) of using AH that Nod should detect malware without updates
     
  2. TonyKlein

    TonyKlein Security Expert

    Joined:
    Feb 9, 2002
    Posts:
    4,361
    Location:
    The Netherlands
    It certainly is, and Nod32 does (and admirably so, I might add), but no heuristics are able to catch ALL new malware....
     
  3. steve1955

    steve1955 Registered Member

    Joined:
    Feb 7, 2004
    Posts:
    1,384
    Location:
    Sunny(in my dreams)Manchester,England
    I know and to be honest I dont think they ever will,unfortunately we will always need sig updates to protect us,and to be honest I doubt the AV vendors want to develop"the perfect" av,after all how then could they sell us "a new improved version" lol
     
  4. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,456
    If heuristics was to catch all new Zlobs you'd better leave it disabled coz it would catch many clean files.
     
  5. steve1955

    steve1955 Registered Member

    Joined:
    Feb 7, 2004
    Posts:
    1,384
    Location:
    Sunny(in my dreams)Manchester,England
    Thought the technology was supposed to differentiate between clean(safe!) and malware by behaviour or something?,it seems in some ways to becoming more of a marketing tool than an av tool(lol)
     
  6. VikingStorm

    VikingStorm Registered Member

    Joined:
    Jun 7, 2003
    Posts:
    387
    I think here, you mistakenly made the mistake of thinking heuristics is magic. Heuristics can only carry it to the point where it can be sure a certain behavior is utilized by malware and only malware. Once it acts more like a normal program, but is malicious in intent, it is ultimately up to signatures and the user.

    Which is why I think Eset should add an IDS module to NOD32 IMO, which can be separate or an extension of AH (get a prompt to allow running a program if it hits two or more danger criteria).
     
  7. ugly

    ugly Registered Member

    Joined:
    Mar 21, 2005
    Posts:
    276
    Location:
    Romania
    New one.
    Sent it.

    zlob.JPG
     
  8. steve1955

    steve1955 Registered Member

    Joined:
    Feb 7, 2004
    Posts:
    1,384
    Location:
    Sunny(in my dreams)Manchester,England
    No in fact I do realise the limitations of this technology,the problem is in the way it is "hyped" by eset and by some users on this forum as a magic bullet!,in a recent test(using old sigs)and therefore relying on AH technology only 58% of malware was detected AND some of those probably were detected by the old sigs,so as an extra form of defence it provides some but very little protection,42% getting through isn't what I would call satisfactory
     
  9. Blackspear

    Blackspear Global Moderator

    Joined:
    Dec 2, 2002
    Posts:
    15,115
    Location:
    Gold Coast, Queensland, Australia
    As this was the head of the class you would prefer to have something lower than this :blink: I don't think so.

    Cheers :D
     
  10. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,456
    ThreatSense is improved on a daily basis so NOD32 would score much better these days.
     
  11. steve1955

    steve1955 Registered Member

    Joined:
    Feb 7, 2004
    Posts:
    1,384
    Location:
    Sunny(in my dreams)Manchester,England
    I know it is the best but still not good enough to rely on for protection:-I want something better if possible!(don't you?)
     
  12. steve1955

    steve1955 Registered Member

    Joined:
    Feb 7, 2004
    Posts:
    1,384
    Location:
    Sunny(in my dreams)Manchester,England
    So its working more like a sig based AV? thats not really the idea is it?
    How will V3 work?
     
  13. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,456
    ThreatSense is part of the engine plus there is a stand-alone module for Advanced heuristics which is constantly being developed as well.
     
  14. i_kenefick

    i_kenefick Registered Member

    Joined:
    Nov 29, 2005
    Posts:
    135
    Location:
    Cork, Ireland.
    If I was able to do something really well I'd be sure to tell people about it too. www.av-comparatives.org
     
  15. steve1955

    steve1955 Registered Member

    Joined:
    Feb 7, 2004
    Posts:
    1,384
    Location:
    Sunny(in my dreams)Manchester,England
    That quote is cut to suit!It is more the users(and resellers!!??) that hype it more than Eset!You consider 58% detection adequate(or even really well!)?Like I have already said I know it is the best,but it is still not good enough to rely on!
    Heres a question for you:-actually how many threats has Nod been able to nulify without updates to the sig base? compared to ones dealt with by updates this number is tiny!
     
  16. i_kenefick

    i_kenefick Registered Member

    Joined:
    Nov 29, 2005
    Posts:
    135
    Location:
    Cork, Ireland.
    See here .
     
  17. steve1955

    steve1955 Registered Member

    Joined:
    Feb 7, 2004
    Posts:
    1,384
    Location:
    Sunny(in my dreams)Manchester,England
    And?why redirect me to my own post?
     
  18. i_kenefick

    i_kenefick Registered Member

    Joined:
    Nov 29, 2005
    Posts:
    135
    Location:
    Cork, Ireland.
    Can you not see your own contradiction?
     
  19. steve1955

    steve1955 Registered Member

    Joined:
    Feb 7, 2004
    Posts:
    1,384
    Location:
    Sunny(in my dreams)Manchester,England
    What contradiction
     
  20. i_kenefick

    i_kenefick Registered Member

    Joined:
    Nov 29, 2005
    Posts:
    135
    Location:
    Cork, Ireland.
    You say AH is Hyped by ESET and some users on this forum. Yet you say it's Hyped by more by the users and resellers in a previous statement. In both cases you are incorrect. The technology works and it's a compeditive advantage. AH works very well, it's more effective a solution when compared to other vendors. This isn't hype... this is a fact.

    Is it becasue the 'Zlobs' aren't all detected proactivly with Heuristics that you believe it's hype? There are many new modifications of bagle spammed this week. All of them detected by AH and Generic detection. No hype here.... just a job well done IMHO.
     
  21. steve1955

    steve1955 Registered Member

    Joined:
    Feb 7, 2004
    Posts:
    1,384
    Location:
    Sunny(in my dreams)Manchester,England
    Users hyping it no! your not doing that now are you!
    When AH was introduced figures of 90% detection on new malware were banded about(without the need for updates!)this figure has never been realised or likely to,so you decide has AH been hyped or not!
    PS I do like the extra protection AH offer,I just wish it was as good as promised initially:-the ref to resellers was a little(jokingly I add)go at Blackspear re his post
     
  22. i_kenefick

    i_kenefick Registered Member

    Joined:
    Nov 29, 2005
    Posts:
    135
    Location:
    Cork, Ireland.
    You're right. I am not hyping it. :shifty: I'm stating facts.

    Agreed. This is BS from certain resellers.

    Ah rite :eek: So it was BS also
     
  23. Blackspear

    Blackspear Global Moderator

    Joined:
    Dec 2, 2002
    Posts:
    15,115
    Location:
    Gold Coast, Queensland, Australia
    Completely missed me :rolleyes: Everyone knows I'm a Reseller so I don’t know what your point was, and if they don't it is plainly stated in my profile, however in saying this I do not want a single sale through Wilders because I have and always do encourage local purchase for local support, as well the day I'm a little late in getting a license to someone it would be posted to the world (for the record we generally only send out licenses once a week ~ eval/temp keys are supplied until the license comes through). From memory since joining Wilders I would have sold about 4 licenses to people that contacted me through here.

    Of the 11,000 odd posts that I have made, about 9,000 would have been in the NOD32 forum helping people, so I really don't see how you can relate 4 sales as a Reseller to 9,000 posts of support, that's a damn hard slog to get a sale if that was the case :blink: ;) :D

    So, now that we have that all cleared up I think it's time to move on about me being a Reseller and get back to the topic at hand.

    Cheers :D
     
    Last edited: Jun 17, 2006
  24. NOD32 user

    NOD32 user Registered Member

    Joined:
    Jan 23, 2005
    Posts:
    1,766
    Location:
    Australia
  25. TonyKlein

    TonyKlein Security Expert

    Joined:
    Feb 9, 2002
    Posts:
    4,361
    Location:
    The Netherlands
    When I try that I link, I get:

    ... which is odd, to say the least, as I don't recall even having seen that forum before... LOL!
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.