PDA

View Full Version : Trojans not malware?


Bilbo
July 6th, 2005, 04:18 PM
I recently tested a file that tried to automatically download to my computer. The results of that file are below. My question is this; why do not some of the major AV's identify this? (ie. Bitdefender, Norton, Nod32) Even AVG and AntVir catch this. Is this trojan not dangerous? Would you want this on your machine?
This has been submitted to Eset weeks ago.

Bubba
July 6th, 2005, 04:33 PM
Since download_plugin.exe and ISTbar are usually associated with LOP....I would use the word trojan loosely in regards to this file. IMHO....Eset will eventually have this in their Spyware\Adware database in due time. As for the other AV's....if they are not into Spyware\Adware you can not expect them to trigger on this file.

The Hammer
July 6th, 2005, 04:36 PM
-{ Quote: "Since download_plugin.exe and ISTbar are usually associated with LOP....I would use the word trojan loosely in regards to this file. IMHO....Eset will eventually have this in there Spyware\Adware database in due time." }-
Whats a LOP?

Bubba
July 6th, 2005, 04:40 PM
-{ Quote: "Whats a LOP?" }-Lop (http://www.doxdesk.com/parasite/lop.html) is just one of the many hidious parasites floating around waiting to infect users unsecured systems.

Infinity
July 6th, 2005, 04:43 PM
very true..this should be taken care off by your antispyware program..

well, here we go .. :) As long as Nod32 takes care of "original" Trojans and not trojanlike spyware (I got other tools for that, layered security..) it's all good.

"don't bet all your luck on one horse" .. especialy not on weekdays :D

ronjor
July 6th, 2005, 04:43 PM
Lop is listed in NOD's definitions. Or variations of same.

Infinity
July 6th, 2005, 05:32 PM
In some years maybe nod32 will detect banana's heuristicaly...:)

Detox
July 6th, 2005, 05:44 PM
I do hate having to dig the bananas out of my PC case by hand :(

Infinity
July 6th, 2005, 05:49 PM
yes, me too...:) pfff, all in one suites is not what I like...that's all :)

SDS909
July 6th, 2005, 07:15 PM
I've had this issue lately. SEVERAL downloaders are being listed by some AV companies as Dialers or Riskware, when they are truely trojan downloads and SHOULD be in the database.

This has recently caused me to install VBA32 for testing because it seems to cover all of the ones i've run into. NOD32 didn't, and DR.Web seems to miss them or not take them seriously. ???

Pollmaster
July 7th, 2005, 09:23 AM
What was it packed with?

Bilbo
July 7th, 2005, 04:35 PM
NOD32 now identifies this trojan! :)