PDA

View Full Version : can someone tell me if this zip if clean, please?


iceni60
November 16th, 2006, 10:04 PM
some heuristics flag this wordlist as malware. is it just one of the words that's setting it off?
http://www.outpost9.com/files/WordLists.html
this is the name of the file -
dic-0294.zip

thanks
i just opened it and had alook with a hex editor. looks just like words to me. i was just starting to panic abit sorry.

Tommy
November 16th, 2006, 10:20 PM
NOD32 says its clean.
By the way that's an ordinary txt files, very very very low chance that it's malware :)

ggf31416
November 16th, 2006, 10:32 PM
-{ Quote: "some heuristics flag this wordlist as malware. is it just one of the words that's setting it off?
" }-

I scanned the zip in VirusTotal and all scanners reported "no virus found"

iceni60
November 16th, 2006, 10:44 PM
now i'm worried again, what did i end up scanning if it wasn't that zip ???

i scanned it at jottis and i got these flags -
AntiVir Worm/SdBot.111616
BitDefender Trojan.Downloader.Small.Gen
F-Prot Antivirus Possibly a new variant of W32/Internet-Trojan-patched-based!Maximus
F-Secure Anti-Virus Backdoor.Win32.SdBot.xd
Kaspersky Anti-Virus Backdoor.Win32.SdBot.xd

i was having problems getting it to scan the file, so i disconnected my http proxy. i'll try it again. when i looked at it it was just a wordlist. i'll try scanning it again.

lol, ok i see what i did. it didn't scan at jottis, and i was just looking at the last malware found at the bottom of the screen ;D

does Kaspersky even use heuristics lol, ok i'm going to bed.

anyway...

Malcontent
November 17th, 2006, 06:53 AM
Dr. Web says it's clean.

Howard Kaikow
November 17th, 2006, 07:05 AM
-{ Quote: "NOD32 says its clean.
By the way that's an ordinary txt files, very very very low chance that it's malware :)" }-

Yes, what if it is the .exe form of a .zip, it could actually execute code during decompression.

Howard Kaikow
November 17th, 2006, 07:09 AM
-{ Quote: "
does Kaspersky even use heuristics lol, ok i'm going to bed.
" }-

Kaspersky is supposed be issuing an update on Monday that I believe includes heuristics.

Howard Kaikow
November 17th, 2006, 07:18 AM
NAV 2006 had no complaints.

iceni60
November 17th, 2006, 07:31 AM
lol, thanks, it's just a text file, i managed to work it out in the end. the reason i was abit frantic is someone asked for a wordlist and i gave that link, then i thought i scanned it at jottis and it contained malware, but i didn't realise jottis didn't do a scan. i was just looking at the last malware found at the bottom of the screen.

i thought there might be malware somewhere in the zip, but my cousin thought the word list might trigger an heuristic flag because there was no other explaination at the time, i'll sit him down and have a word with him later :P

Howard Kaikow
November 17th, 2006, 07:41 AM
-{ Quote: "Kaspersky is supposed be issuing an update on Monday that I believe includes heuristics." }-

According to the KAV 6 user guide, the current KAV already uses heuristics.

SSK
November 17th, 2006, 08:06 AM
Yes, Kaspersky uses Heuristics. Has been using it for some time, just like most other AV's.

No, the update scheduled to be released on monday (Maintenance Pack 1) will not inclued an update to the Heuristics. The Heuristics update is under development.

(A search on the Kaspersky forum would have given you this info, Howard... ;D )

Howard Kaikow
November 17th, 2006, 09:43 AM
-{ Quote: "Yes, Kaspersky uses Heuristics. Has been using it for some time, just like most other AV's.

No, the update scheduled to be released on monday (Maintenance Pack 1) will not inclued an update to the Heuristics. The Heuristics update is under development.

(A search on the Kaspersky forum would have given you this info, Howard... ;D )" }-
I saw something that stated MP1 would be doing something with heuristics.