PDA

View Full Version : NOD32 Virus Definition Update issues [2012-11-07]



NewsArchive
11-07-2012, 02:24 AM
All,

If you have NOD32, please note that one of the latest NOD32 definition file
updates introduced problems.

If you are using the SetupBuilder "#pragma SETUPICON" compiler directive to
customize the actual installer icon (this will inject a new icon into your
setup.exe binary) and you see the following error, then you should report it
to ESET:

Fatal Compiler Error: GEN1094: Cannot inject stub loader entrypoint: Para1:
C:\SYS\APPS\install\cd\yada.exe Para2: 91648 Para3: 6664

It's also possible that some of your scripts give an "Cannot be saved [2].
The error code reported is: 5 -- Access Denied" error that it can not save
the changes and offers to try again.

If "excluding" the SB7 IDE does not help, completely disabling NOD32 will do
the trick. But of course, this is a suboptimal workaround <g>.

Unfortunately, there is absolutely nothing that we can do because it is not
caused by SetupBuilder at all. It's a NOD32 bug.

--
Friedrich Linder
Lindersoft
www.lindersoft.com
+1.954.252.3910

--Helping You Build Better Installations
--SetupBuilder "point. click. ship"
--Create Windows 8 ready installations in minutes
--Official Comodo Code Signing and SSL Certificate Partner

NewsArchive
11-08-2012, 04:23 AM
We are in contact with ESET Customer Care now. I'll keep you posted.

Friedrich

--
Friedrich Linder
Lindersoft
www.lindersoft.com
+1.954.252.3910

--Helping You Build Better Installations
--SetupBuilder "point. click. ship"
--Create Windows 8 ready installations in minutes
--Official Comodo Code Signing and SSL Certificate Partner

NewsArchive
11-09-2012, 11:51 AM
Unfortunately, ESET Support is unable to reproduce the issue. The ESET
ticket number for this case is: TICKET-83977

ESET Support told us the following:

---

"We aren`t able to reproduce the issue, thats why we need you to reproduce
the issue and create procmon log from this issue.

Please send us Sysinspector log, export of settings and log from procmon, we
need these files for analyzing this issue.

1) In this article you can find how to create Sysinspector log :
http://kb.eset.com/esetkb/index?page=content&id=SOLN2219&actp=search&viewlocale=en_US&searchid=1342100418438

2) In this article you can find how to create export of settings
http://kb.eset.com/esetkb/index?page=content&id=SOLN3133&actp=search&viewlocale=en_US&searchid=1352465692025

3) Procmon log: here you can download this tool
http://technet.microsoft.com/en-us/sysinternals/bb896645.aspx in attached
manual you can see the steps in screenshot how to make it.

Thank you.

---

So if your SetupBuilder compiler reports:

1.) "GEN1094: Cannot inject stub loader entrypoint"

-and/or-

2.) your scripts give an "The file xyz cannot be saved [2]. The error code
reported is: 5 -- Access Denied"

then it would be great if you could create a Sysinspector log and send it to
our Support at support [at] lindersoft [dot] com. We'll then forward it to
ESET.

Friedrich

--
Friedrich Linder
Lindersoft
www.lindersoft.com
+1.954.252.3910

--Helping You Build Better Installations
--SetupBuilder "point. click. ship"
--Create Windows 8 ready installations in minutes
--Official Comodo Code Signing and SSL Certificate Partner

NewsArchive
11-09-2012, 11:52 AM
Correct link is:

http://kb.eset.com/esetkb/index?page=content&id=SOLN2219&actp=search&viewlocale=en_US&searchid=1342100418438

We played a bit (enabled/disabled specific security features) with the
latest NOD32 and I think we found one security configuration combination
that causes it. There might be other combinations with similar results.

Friedrich

NewsArchive
11-09-2012, 11:53 AM
And another one.

Sysinspector log sent to ESET.

Friedrich

NewsArchive
11-09-2012, 11:54 AM
Friedrich,

Just what I always thought - play'n games!<g>

Lee White

NewsArchive
11-09-2012, 11:54 AM
Lee,

>
> Just what I always thought - play'n games!<g>
>

Hehehehehe :-)

Friedrich

NewsArchive
11-10-2012, 01:22 AM
Its how I can play Eve Online <g>. Granted, I've not needed to make any
SB compiles lately, so the timing for me is perfect. Wish it was for
Friedrich, but you do have to admire his testing/debugging technique <g>.

--

Russ Eggen
RADFusion International, LLC

NewsArchive
12-10-2012, 12:43 AM
Update: Instead of trying to reproduce and fix the bug in NOD32, ESET
Customer Care (Bratislava, Slovak Republic) requested again and again
"Sysinspector" log files and other exported settings and logs from
"Procmon".

We already invested more than 30 hours in this case. Because we have better
things to do, we decided to stop here and now.

The ESET ticket is closed, but the fundamental bug in ESET products is still
there!

>
> Your service request #TICKET 83977 was resolved.
>

So if you are using an ESET product and you get the errors as described in
this thread, please contact ESET Customer Care and refer to #TICKET 83977.

--
Friedrich Linder
Lindersoft
www.lindersoft.com
+1.954.252.3910

--Helping You Build Better Installations
--SetupBuilder "point. click. ship"
--Create Windows 8 ready installations in minutes
--Official Comodo Code Signing and SSL Certificate Partner

NewsArchive
12-10-2012, 12:44 AM
Friedrich,

> We already invested more than 30 hours in this case.

You shouldn't have to invest time like that to get someone else's bug
fixed. Luckily I don't use that product so it's a non-issue.

> Because we have better things to do

Then, by all means, GET BUSY!!!!<g>

--
Lee White

RPM Report Viewer.: http://www.cwaddons.com/products/rpm/
RPM Review........: http://www.clarionmag.com/cmag/v11/v11n06rpm.html
Report Faxing.....: http://www.cwaddons.com/products/afe/
---Enroll Today---: http://CWaddons.com

Enhanced Reporting: http://CreativeReporting.com

Product Release & Update Notices
http://twitter.com/DeveloperPLUS

Windows 8 brings us "The Oval, Bumper Car, Roller Coaster of Wait!"

NewsArchive
12-10-2012, 12:44 AM
>> Because we have better things to do
>
> Then, by all means, GET BUSY!!!!<g>

<BG> ;-)

Friedrich