View Full Version : probably a variant of Perl/Exploit.Generic.S trojan
Megachip
August 20th, 2007, 12:02 PM
Hello Eset,
possible a false positive in climate data in a .txt file.
Send a sample to support(at)eset.sk at friday, no reation till now. File is still detected.
Can anyone confirm?
Thanks
ugly
August 20th, 2007, 02:12 PM
Scan it on virustotal.
See what you get.:lurking:
Marcos
August 20th, 2007, 02:20 PM
I couldn't find any false positive sent to samples on Friday. Please re-send it to support[at]eset.com
Megachip
August 21st, 2007, 04:24 AM
{QUOTE-> I couldn't find any false positive sent to samples on Friday. Please re-send it to support[at]eset.com <-QUOTE}
Resend it to eset.com
{QUOTE-> Scan it on virustotal.
See what you get.:lurking: <-QUOTE}
Get nothing ;), expect nod
Megachip
August 21st, 2007, 06:01 AM
Some new false positives...
Quote of an employee
{QUOTE->
And yesterday I would like to create new data sets in 2005.
I got 5 "infected" files.
These files were infected by "BAT/Bomgen.S virus" ,"BAT/Liberte.B virus"
, "BAT/Delterr.Y trojan virus" and "Perl/Exploit.Generic.S trojan virus".
<-QUOTE}
All Viruses are "probably variant of"...
IMHO these are all textfiles of aprox. 20 MB... possible the sizes makes problems?
Regards...
P.S. Should i submit a sample of each file?
Megachip
August 23rd, 2007, 09:36 AM
Seems the the perl file problem is solved, but the other "false positives" are still detected
Megachip
August 27th, 2007, 05:06 AM
Your mailserver rejected the the mail, try to send each file seperatly...
Seems that nod have much fp in last time!? (see other threads here)
Regards
Megachip
August 29th, 2007, 10:49 AM
Nothing new...
almost impossible to work for the user with the climate data...
Macros, did u received the emails?
Regards
The Hammer
August 29th, 2007, 03:04 PM
{QUOTE->
Get nothing ;), expect nod <-QUOTE}You should still submit to virustotal or jotti's as sugested earlier.
Marcos
August 29th, 2007, 03:30 PM
{QUOTE-> Nothing new...
almost impossible to work for the user with the climate data...
Macros, did u received the emails?
Regards <-QUOTE}
When and where did you send it to?
Megachip
August 31st, 2007, 04:31 AM
one big file (44MB) at 24.08.07 14:40 UTC+1 to samples and support... rejected by your mailserver
five mails (aprox. 9 mb) at 28.08.07 8:50 UTC+1 to samples...
BTW, it freeze the PC some minutes, when accessing the folder, where the files ware (amon scan)
Regards
Megachip
September 5th, 2007, 09:27 AM
problem seems fixed... thx to eset
vBulletin® Copyright ©2000-2009, Jelsoft Enterprises Ltd.