• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EDT 22:07
CEST 04:07
KST 11:07
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
Code S RO12 Preview: Maru, Trigger, Rogue, NightMare12Code S RO12 Preview: Cure, sOs, Reynor, Solar15[ASL19] Ro8 Preview: Unyielding3Official Ladder Map Pool Update (April 28, 2025)17[ASL19] Ro8 Preview: Rejuvenation8
Community News
Code S Season 1 - RO12 Group A Results (2025)4$1,250 WardiTV May [May 6th-May 18th]4Clem wins PiG Sty Festival #66Weekly Cups (April 28-May 4): ByuN & Astrea break through1Nexon wins bid to develop StarCraft IP content, distribute Overwatch mobile game29
StarCraft 2
General
BTC ETH & USDT RECOVERY EXPERT HIRE CHAINDIGGER RE How does the number of casters affect your enjoyment of esports? Code S Season 1 - RO12 Group A Results (2025) Code S RO12 Preview: Maru, Trigger, Rogue, NightMare Nexon wins bid to develop StarCraft IP content, distribute Overwatch mobile game
Tourneys
[GSL 2025] Code S:Season 1 - RO12 - Group A INu's Battles#12 < ByuN vs herO > [GSL 2025] Code S:Season 1 - RO12 - Group B GSL 2025 details announced - 2 seasons pre-EWC 2025 GSL Season 2 (Qualifiers)
Strategy
[G] PvT Cheese: 13 Gate Proxy Robo Simple Questions Simple Answers
Custom Maps
[UMS] Zillion Zerglings
External Content
Mutation # 472 Dead Heat Mutation # 471 Delivery Guaranteed Mutation # 470 Certain Demise Mutation # 469 Frostbite
Brood War
General
Preserving Battlereports.com OGN to release AI-upscaled StarLeague from Feb 24 Battlenet Game Lobby Simulator [G] GenAI subtitles for Korean BW content BGH auto balance -> http://bghmmr.eu/
Tourneys
[ASL19] Ro8 Day 4 [BSL20] RO32 Group F - Saturday 20:00 CET [BSL20] RO32 Group E - Sunday 20:00 CET [CSLPRO] $1000 Spring is Here!
Strategy
[G] How to get started on ladder as a new Z player Creating a full chart of Zerg builds [G] Mineral Boosting
Other Games
General Games
Stormgate/Frost Giant Megathread What do you want from future RTS games? Nintendo Switch Thread Grand Theft Auto VI Battle Aces/David Kim RTS Megathread
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
LiquidLegends to reintegrate into TL.net
Heroes of the Storm
Simple Questions, Simple Answers
Hearthstone
Heroes of StarCraft mini-set
TL Mafia
Vanilla Mini Mafia TL Mafia Community Thread TL Mafia Plays: Diplomacy TL Mafia: Generative Agents Showdown Survivor II: The Amazon
Community
General
Ask and answer stupid questions here! Russo-Ukrainian War Thread US Politics Mega-thread Elon Musk's lies, propaganda, etc. UK Politics Mega-thread
Fan Clubs
Serral Fan Club
Media & Entertainment
Movie Discussion! Anime Discussion Thread [Books] Wool by Hugh Howey Surprisingly good films/Hidden Gems
Sports
2024 - 2025 Football Thread NHL Playoffs 2024 NBA General Discussion Formula 1 Discussion
World Cup 2022
Tech Support
Computer Build, Upgrade & Buying Resource Thread Cleaning My Mechanical Keyboard How to clean a TTe Thermaltake keyboard?
TL Community
BLinD-RawR 50K Post Watch Party The Automated Ban List TL.net Ten Commandments
Blogs
Info SLEgma_12
SLEgma_12
SECOND COMMING
XenOsky
What High-Performing Teams (…
TrAiDoS
WombaT’s Old BW Terran Theme …
WombaT
Heero Yuy & the Tax…
KrillinFromwales
BW PvZ Balance hypothetic…
Vasoline73
Test Entry for subject
xumakis
Customize Sidebar...

Website Feedback

Closed Threads



Active: 13364 users

NOD antivirus and stuff

Blogs > BluzMan
Post a Reply
BluzMan
Profile Blog Joined April 2006
Russian Federation4235 Posts
February 01 2009 21:23 GMT
#1
Preface:

- Last monday, I left work somewhat early, and soon after my leave, my boss (the owner of our firm) was browsing the Internet and downloaded something that identified itself as "Windows XP 2008 Anti-Virus". Sure thing, it didn't function the way he expected and NOD (our corporate antivirus, take notice here!) threw some warning when the thing was launched.

Tuesday morning, I came to work and opened my email to send mails to several people I needed to contact. I sent the mail only to receive it back a few minutes later with a fun commentary: "Tada your mail is blacklisted by SpamCop!". Cool.

Apparently, our corporate external IP has been sending spam to some spam trap of spamcop. A quick inspection on the ISA server has shown a funny thing - random SMTP packets are being sent to all over the world from just one IP - the one the boss owns.

Well, cool, now I know we have a spambot in our system, I even know where it is exactly, so I setup an SMTP filter for that computer, delist from SpamCop to resolve the situation quickly, download CureIt and Kasper and go into his room armed and ready.

NOD, CureIt and Kaspersky find nothing. Well, no, they find some old stuff infected with some random worms, some shit that could be the bot's injector in Temporary Internet Files, but still not the bot itself. Even though three AV programs keep telling me that the machine is clean, it's definetely not as the ISA (it's a huge software firewall in case you didn't know) keeps denying a lot of spam from it.

The situation gets grim. Not that I'm an anti-virus expert, but in most cases, unless you can root the bugger out with some software, it spells doom and a need to reformat. However, there might be a slim chance to kill the virus manually unless it infects some system-critical executable you cannot replace (and even then you can sometimes resolve it just taking the HDD to another computer and copying the dead file from a healthy system). I decide to take chances and look for unknown processes. Nothing! Not a single process that is abnormal or unknown. Killing all theoretically killable processes (except the system-critical svchost and some other processes like NOD) didn't stop it.

Fearing the worst (infected svchost and some loader like winlogon), I launch CPorts (this app detects what networking ports are used by specific processes, it is very handy but often useless as processes can quite easily mask themselves to be invisible to it, being displayed as just Unknown), lookup 25 (SMTP) and... almost fall from my chair.

CPorts detected the spambot. It was in "ekrn.exe". What is ekrn? It's short for ESET Kernel, the kernel of NOD anti-virus. In short, this virus not only wasn't stopped by NOD, it has eaten NOD and sent spam using NOD itself. It was quicky apparent why DrWeb and Kasper didn't find it - as an untold convention, anti-viruses (being practically stuffed with unsafe code) generally restrain from scanning each other to prevent system damage. A masterful move by the injector writer, even though removing the spambot was exactly as easy as reinstalling NOD (unfortunately, we already paid for it, and there are no plans to switch to another, better software).

Now the morale of the story is very simple:

Don't use NOD. Ever.

****
You want 20 good men, but you need a bad pussy.
gm.tOSS
Profile Joined September 2005
Germany898 Posts
February 01 2009 21:31 GMT
#2
Nice read.
HuK HuK HuK | ¯\_(ツ)_/¯ | There is death in the hane.
paper
Profile Blog Joined September 2004
13196 Posts
February 01 2009 21:31 GMT
#3
hehe cool
Hates Fun🤔
KlaCkoN
Profile Blog Joined May 2007
Sweden1661 Posts
February 01 2009 21:40 GMT
#4
Lol nice :p
My brother downloaded the exact same virus once =p
I just forced him to reinstall the computer though.
"Voice or no voice the people can always be brought to the bidding of their leaders ... All you have to do is tell them they are being attacked and denounce the pacifists for lack of patriotism and exposing the country to danger."
jodogohoo
Profile Blog Joined March 2008
Canada2533 Posts
February 01 2009 21:41 GMT
#5
A legendary story. I shall pass this down to my children should they get their computers infected.
jimminy_kriket
Profile Blog Joined February 2007
Canada5490 Posts
February 01 2009 21:50 GMT
#6
haha fun story
life of lively to live to life of full life thx to shield battery
HeavOnEarth
Profile Blog Joined March 2008
United States7087 Posts
February 01 2009 21:58 GMT
#7
bwhaah awesome
"come korea next time... FXO house... 10 korean, 10 korean"
KizZBG
Profile Blog Joined November 2006
u gotta skate8152 Posts
February 01 2009 22:05 GMT
#8
lol nice story.
eSTRO for life | #2 Sea.Really fan! | #1 GosI[Flying] fan! | Clide - best SC2 terran!
Disregard
Profile Blog Joined March 2007
China10252 Posts
February 01 2009 22:22 GMT
#9
This rarely happens, I still use Nod32. More reliable than majority of the AVs' out there.
"If I had to take a drug in order to be free, I'm screwed. Freedom exists in the mind, otherwise it doesn't exist."
zer0das
Profile Blog Joined May 2007
United States8519 Posts
February 01 2009 22:48 GMT
#10
Or you could not download shady "virus protection" when you already have anti-virus installed...
BluzMan
Profile Blog Joined April 2006
Russian Federation4235 Posts
February 01 2009 23:23 GMT
#11
On February 02 2009 07:22 Disregard wrote:
This rarely happens, I still use Nod32. More reliable than majority of the AVs' out there.


Well, I've had some experience with it over the last half a year and I must say that I'm very unsatisfied. I still rely on it for resident protection, but when it comes to scanning, it's detection rate is not even in top 5, even though it's a huge commercial brand. I've seen stuff that even Avast roots out (being a freeware AV) that NOD doesn't, and DrWeb's CureIt and Kaspersky online are one step better. Besides, it's heuristic analysis is crap - try to compile asm code where you affect ECX register inside a loop (well, it's crap code, but not nearly a virus) and NOD will raise red alert and prompt you to send the newly-found "malware" to ESET labs for investigation.

At home I use Avast for resident protection, scanning the disks with CureIt about every month. Nothing so far, besides Avast is very gentle about "unsafe code" and has almost zero false alarms.
You want 20 good men, but you need a bad pussy.
Viledica
Profile Joined May 2008
Canada361 Posts
February 01 2009 23:40 GMT
#12
I use NOD32 myself and so far so good, not that I use my home PCs often enough to base whether it's a good Anti-Virus or not though.

Good read, but it won't veer me from sticking with NOD.
Thanks for the heads up.
TonyL2
Profile Blog Joined August 2007
England1953 Posts
February 02 2009 00:00 GMT
#13
Damn I have NOD...
ramen247
Profile Blog Joined June 2008
United States1256 Posts
February 02 2009 00:37 GMT
#14
wat are you talking about... NOD32 is the best AV there can be...
i hate this ugly firebat. i want a marine.
vnlegend
Profile Blog Joined December 2006
United States1389 Posts
February 02 2009 09:07 GMT
#15
On February 02 2009 09:37 ramen247 wrote:
wat are you talking about... NOD32 is the best AV there can be...

He's talking about exactly what he wrote in his blog post, which you just replied to w/o reading.

On another note..

Why did your boss download an anti-virus that calls itself "Windows XP 2008 Anti-Virus"? This is such an obvious fake name. Secondly, the company already has an anti-virus that it has paid for. Seems to me like he was doing something else.
Marines > everything
Please log in or register to reply.
Live Events Refresh
Next event in 1h 53m
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
PiGStarcraft415
RuFF_SC2 207
SteadfastSC 159
StarCraft: Brood War
NaDa 75
soO 48
Sexy 22
Icarus 5
Dota 2
LuMiX1
Counter-Strike
Fnx 838
Heroes of the Storm
Khaldor169
Other Games
FrodaN2092
shahzam582
JimRising 364
C9.Mang0248
Trikslyr50
PPMD39
Organizations
Other Games
gamesdonequick1500
StarCraft 2
ESL.tv112
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 19 non-featured ]
StarCraft 2
• Hupsaiya 81
• musti20045 42
• davetesta26
• HeavenSC 18
• Kozan
• Migwel
• AfreecaTV YouTube
• intothetv
• sooper7s
• IndyKCrew
• LaughNgamezSOOP
StarCraft: Brood War
• Azhi_Dahaki33
• HerbMon 33
• STPLYoutube
• ZZZeroYoutube
• BSLYoutube
Dota 2
• Ler54
League of Legends
• Doublelift4986
Other Games
• Scarra714
Upcoming Events
Online Event
1h 53m
ShoWTimE vs MaxPax
SHIN vs herO
Clem vs Cure
SHIN vs Clem
ShoWTimE vs SHIN
SOOP
6h 53m
DongRaeGu vs sOs
CranKy Ducklings
7h 53m
WardiTV Invitational
8h 53m
AllThingsProtoss
8h 53m
SC Evo League
9h 53m
WardiTV Invitational
11h 53m
Chat StarLeague
13h 53m
PassionCraft
14h 53m
Circuito Brasileiro de…
15h 53m
[ Show More ]
Online Event
1d 1h
MaxPax vs herO
SHIN vs Cure
Clem vs MaxPax
ShoWTimE vs herO
ShoWTimE vs Clem
Sparkling Tuna Cup
1d 7h
WardiTV Invitational
1d 8h
AllThingsProtoss
1d 8h
uThermal 2v2 Circuit
1d 11h
Chat StarLeague
1d 13h
Circuito Brasileiro de…
1d 15h
Afreeca Starleague
2 days
BeSt vs Light
Wardi Open
2 days
PiGosaur Monday
2 days
Afreeca Starleague
3 days
Snow vs Soulkey
WardiTV Invitational
3 days
Replay Cast
3 days
GSL Code S
4 days
ByuN vs Rogue
herO vs Cure
Replay Cast
4 days
GSL Code S
5 days
Classic vs Reynor
GuMiho vs Maru
The PondCast
5 days
RSL Revival
5 days
GSL Code S
6 days
Liquipedia Results

Completed

BSL Nation Wars Season 2
PiG Sty Festival 6.0
Calamity Stars S2

Ongoing

StarCastTV Star League 4
JPL Season 2
ASL Season 19
YSL S1
BSL 2v2 Season 3
BSL Season 20
China & Korea Top Challenge
KCM Race Survival 2025 Season 2
CSLPRO Spring 2025
2025 GSL S1
Heroes 10 EU
PGL Astana 2025
Asian Champions League '25
ECL Season 49: Europe
BLAST Rivals Spring 2025
MESA Nomadic Masters
CCT Season 2 Global Finals
IEM Melbourne 2025
YaLLa Compass Qatar 2025
PGL Bucharest 2025
BLAST Open Spring 2025
ESL Pro League S21

Upcoming

NPSL S3
CSLPRO Last Chance 2025
CSLAN 2025
Esports World Cup 2025
HSC XXVII
Championship of Russia 2025
Bellum Gens Elite Stara Zagora 2025
2025 GSL S2
DreamHack Dallas 2025
IEM Cologne 2025
FISSURE Playground #1
BLAST.tv Austin Major 2025
ESL Impact League Season 7
IEM Dallas 2025
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2025 TLnet. All Rights Reserved.