View Full Version : Trojan or Not?
Meitricsu
January 27th, 2006, 09:12 PM
Multiple files of 44 KB each, which have double extensions(mp3.exe or jpg.exe) are seen as a Trojan.Win32.VB.aia by Kaspersky Antivirus but is not seen by NOD32. What seems to be the problem? In Kaspersky Malware Enciclopedya is written that it appeared on 19-01-2006 and all the "infected" files on my PC are dated - 20-01-2006. You can download a sample from ~sniped~. It includes one of those files.
What seems to be the explanation that NOD32 isn't aware of it?
snapdragin
January 27th, 2006, 09:17 PM
Hi Meitricsu, I've removed the link as it violates our TOS (http://www.wilderssecurity.com/TOS-Privacy.html). Please do not post links to malware. Thank you.
Regards,
snap
Meitricsu
January 27th, 2006, 09:27 PM
Sorry, I did'n knew that. My bad. I attached now a screenshot which shows how other AV-products see that file as a Trojan. Norton and Kaspersky say YES, NOD32 and McAfee say NO. Which one is it?
NAMOR
January 27th, 2006, 11:00 PM
Hi Meitricsu
Have you submitted the file to eset? samples[at]eset.com
Meitricsu
January 27th, 2006, 11:11 PM
Yes, I submited it using the Submit for analysis option in NOD32 System Tools->Quarantine->Submit for analysis.
Brian N
January 28th, 2006, 05:56 AM
It should go faster if you submit it to the email above.
Happy Bytes
January 28th, 2006, 06:47 AM
Ok, this should be solved ASAP. Looks pretty much similar to Win32/VB.NEI probably some previous version. So no problem - will be added.
kjempen
January 29th, 2006, 07:03 AM
NOD32 - v.1.1385 (20060128 )
Virus signature database updates:
IRC/SdBot (2), SymbOS/Pbstealer.C, Win32/Adware.Virtumonde (2), Win32/Akbot.B (2), Win32/Bagle.EF, Win32/Bagle.EX (3), Win32/IRCBot.PH, Win32/Mytob.OX (2), Win32/Mytob.OY (2), Win32/Opanki.BP (2), Win32/Oscarbot.BS, Win32/Poebot, Win32/Rbot (8 ), Win32/TrojanDownloader.Small.APP, Win32/VB.AIA
vBulletin® Copyright ©2000-2009, Jelsoft Enterprises Ltd.