View Full Version : Submitting a file for analysis
msanto
January 31st, 2006, 03:50 PM
I submitted a file that both Avast Home and a-squared free said had the ZapChast trojan, but that NOD32 said was OK.
I noticed when I submitted that it said I wouldn't get a response unless more info is needed. From past experience, will I get a response telling me if the file was indeed OK or just a FP (though since it's two other scanners, I dunno about that)?
Brian N
January 31st, 2006, 03:55 PM
Usually you'll get no response. Only if you submit a password protected file and forgot to include the password or something ;)
And sometimes a few guys from Eset will respond on these forums about the file you submitted.
msanto
January 31st, 2006, 03:59 PM
{QUOTE-> Usually you'll get no response. Only if you submit a password protected file and forgot to include the password or something ;)
And sometimes a few guys from Eset will respond on these forums about the file you submitted. <-QUOTE}
Not too comforting. It looks like NOD32 was missing it, since I just tried Panda ActiveScan online and it found the same trojan. What's interesting is that BOClean doesn't see anything either when I use its file scanner by dragging the file over to the menu.
The Hammer
January 31st, 2006, 04:29 PM
{QUOTE-> Not too comforting. It looks like NOD32 was missing it, since I just tried Panda ActiveScan online and it found the same trojan. What's interesting is that BOClean doesn't see anything either when I use its file scanner by dragging the file over to the menu. <-QUOTE}Corrupted non functional sample perhaps? ??? Submit it here http://www.virustotal.com/flash/index_en.html or here http://virusscan.jotti.org/
NOD32 user
January 31st, 2006, 04:36 PM
{QUOTE-> Corrupted non functional sample perhaps? ??? Submit it here http://www.virustotal.com/flash/index_en.html or here http://virusscan.jotti.org/ <-QUOTE}Be mindful that some of the scanners at both these sites will still say that a corrupted or non-functional file is infected....Normally NOD32 doesn't
Marcos
January 31st, 2006, 04:37 PM
Recently I received some non-functional Zapchat trojans, maybe it was one of them. Send it to support[at]eset.com so that I can have a look at it.
msanto
January 31st, 2006, 04:37 PM
{QUOTE-> Corrupted non functional sample perhaps? ??? Submit it here http://www.virustotal.com/flash/index_en.html or here http://virusscan.jotti.org/ <-QUOTE}
Dunno what you mean. It's now been caught by 3 products but not by NOD32. And I think this is an old trojan.
I submitted to that page anyway.
msanto
January 31st, 2006, 04:38 PM
{QUOTE-> Recently I received some non-functional Zapchat trojans, maybe it was one of them. Send it to support[at]eset.com so that I can have a look at it. <-QUOTE}
OK, will do.
msanto
January 31st, 2006, 04:41 PM
{QUOTE-> Be mindful that some of the scanners at both these sites will still say that a corrupted or non-functional file is infected....Normally NOD32 doesn't <-QUOTE}
OK, I don't understand what you mean by non-functional ...
Brian N
January 31st, 2006, 04:44 PM
{QUOTE-> OK, I don't understand what you mean by non-functional ... <-QUOTE}
Non-functional .. There is no threat because the trojan is not working and can't harm your system. Other AV's will still report it as a threat though, even if it really isn't.
But let's see what it is after the guys at Eset has analyzed it :)
webyourbusiness
January 31st, 2006, 04:49 PM
{QUOTE-> OK, I don't understand what you mean by non-functional ... <-QUOTE}
usually it means that the threat was broken, or disabled in some way...
msanto
January 31st, 2006, 05:08 PM
{QUOTE-> Non-functional .. There is no threat because the trojan is not working and can't harm your system. Other AV's will still report it as a threat though, even if it really isn't.
But let's see what it is after the guys at Eset has analyzed it :) <-QUOTE}
So this DLL was in a ZIP. That mean if it was installed as it was supposed to be it would be detected?
msanto
February 2nd, 2006, 01:53 AM
Still no answer from Eset?
vBulletin® Copyright ©2000-2009, Jelsoft Enterprises Ltd.