IMHO:
I'd say NOD32-Heuristics could detect the transferred Sasser-FILE(s)
- on-Access
- without specific new signatures
- AFTER the Exploit/attack succeeded and the worm-file was written to HD, but
- BEFORE the Worm was executed, so it would not install or spread
So a system protected by NOD32 was not "infected", but the initial network-attack could not have been blocked (as avast's Shield now does it)
