Kudos0

Different results: my PC vs. Symantec virustotal.com

I have NIS 18.5.0.125, with automatic live updates.

There's a file with diffferent scan results:

In my PC - nothing found

In virustotal.com - "Symantec    20101.3.0.103    2011.03.22    WS.Reputation.1"

Thanks in advance.

Replies

Kudos0

Re: Different results: my PC vs. Symantec virustotal.com

So you did find the file yourself and Symantec says there is no malware and virustotal tells you there is?

"All that we are is the result of what we have thought"
Kudos0

Re: Different results: my PC vs. Symantec virustotal.com

Please read my post with a bit of attention.

All that we are, is the result of what we have not read...

Also, i can send you the file.

Kudos0

Re: Different results: my PC vs. Symantec virustotal.com

Something may interfere with AV kernel and may hook it. For example, can you download malware test file from http://eicar.org/anti_virus_test_file.htm (eicar.com) and see the result? When AV is hooked you will see nothing.

This file by itself contains only following string:

X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*

which needs to be handled by all antivirus products.

Kudos0

Re: Different results: my PC vs. Symantec virustotal.com

Afaik,  you can get WS.Reputation.1 only from Download Insight. Therefore, you can't get it if you scan a file which is already on your hard drive, memory stick ...

On VirusTotal they are probably download files for analyses and get WS.Reputation.1 from Download Insight

Kudos0

Re: Different results: my PC vs. Symantec virustotal.com

Kudos1 Stats

Re: Different results: my PC vs. Symantec virustotal.com


ruiplacido wrote:

Please read my post with a bit of attention.

All that we are, is the result of what we have not read...

Also, i can send you the file.


Based on the information that you gave in your first post in this thread, is the name of the file in question 'Rumpelstiltskin.exe"?

"All of our responses stem from the information that you have not given."

Kudos0

Re: Different results: my PC vs. Symantec virustotal.com

Just run Reputation scan on your PC it will fix suspicious files.

Kudos0

Re: Different results: my PC vs. Symantec virustotal.com

- My NIS detects "Eicar".

- "you can't get it if you scan a file which is already on your hard drive, memory stick ..." Well, it's not very protective.

- The name of the file in question it is not 'Rumpelstiltskin.exe", but it's an "exe" file.

Kudos0

Re: Different results: my PC vs. Symantec virustotal.com

Not yet detected by NIS, decided to send/submit the file 5 min ago to Symantec...

Kudos0

Re: Different results: my PC vs. Symantec virustotal.com

Is this some kind of Easter Egg hunt? What is the name of the file that you think is malware?

Also more than one of the VirusTotal scanners detected the file as hueristic based. In other words, the file appears suspicious but is not necessarily malware. The file might be unsigned and perform high level OS functions. Quite a bit of freeware utility type software falls in this catagory.

Bottom line - software in this catagory can best be summed up as run at your own risk. I run software like this but block all Internet access to it including updating.

This thread is closed from further comment. Please visit the forum to start a new thread.