View Full Version : Uncertain positive result from CPSecure at Jotti and VirScan
Tim Tylor
February 16th, 2009, 07:47 AM
I've submitted an .exe file to the Jotti, Virscan and VirusTotal malware scanning sites. The CPSecure scanner on Jotti and VirScan reports Troj.Spy.W32.Banker.bve, but every other scanner finds the file clean. ESET NOD32 antivirus on my computer finds it clean as well. Would it be sensible for me to dismiss the lone CPSecure result as a false positive? I'm new to this stuff and I'd be glad of advice. (I'm reluctant to post the name and source of the file here as I don't want to make trouble for its creator.)
dorgane
February 16th, 2009, 09:29 AM
can you paste virustotal link plz ?
thank you.
Tim Tylor
February 16th, 2009, 09:50 AM
www.virustotal.com
VirusTotal doesn't include the CPSecure scanner, and I didn't get any positives from it. The other two I tried are
Jotti virusscan.jotti.org (http://virusscan.jotti.org/)
VirSCAN www.virscan.org
GES/POR
February 16th, 2009, 10:59 AM
-{ Quote: "I've submitted an .exe file to the Jotti, Virscan and VirusTotal malware scanning sites. The CPSecure scanner on Jotti and VirScan reports Troj.Spy.W32.Banker.bve, but every other scanner finds the file clean. ESET NOD32 antivirus on my computer finds it clean as well. Would it be sensible for me to dismiss the lone CPSecure result as a false positive? I'm new to this stuff and I'd be glad of advice. (I'm reluctant to post the name and source of the file here as I don't want to make trouble for its creator.)" }-
ppl need to stop using viruscanning engines sites as the gospel, theres plenty of malware undetected by all av's so yes be suspicious and send it in to a few av vendors, professional analysis would provide you with a more certain outcome.
NoIos
March 13th, 2009, 02:20 PM
If the hash of the file you submit is already in the databases of sites like virustotal and the date of the initial submission is at least 4 - 5 days old, considering that virustotal collects data and samples for the various security companies, then there is a high possibility that your file already passed from the labs of the antivirus companies. Request a rescan from virustotal. The new results will be safer to accept.
My strategy was always to leave a suspected file zipped in a password protected archive for at least a week and then rescan it. That does not work when you have to immediately open or run the file...for your job or other important tasks.
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums