R
Retired
I have a malware sample on my desktop named install_cn.exe which is
detected by Microsoft as TrojanDownloader:Win32/Small.ZZB (this is from
a Virustotal result - see below). Using Sandboxie, I executed the file
and Windows Defender did nothing to stop it. Is this normal behaviour
for WD? Thanks for your help.
Virustotal result:
www.virustotal.com/analisis/9e2cae813e8514ecf61e19f92829811c
Result: 7/32 (21.88%)
File install_cn.exe received on 02.11.2008 00:28:41 (CET)
Antivirus Version Last Update Result
Avast 4.7.1098.0 2008.02.10 Win32:Agent-LTS
AVG 7.5.0.516 2008.02.10 Downloader.Zlob
ClamAV 0.92 2008.02.10 Trojan.Dropper-4103
DrWeb 4.44.0.09170 2008.02.10 Adware.Supa
Kaspersky 7.0.0.125 2008.02.11 not-a-virus:AdWare.Win32.Vapsup.azp
Microsoft 1.3204 2008.02.10 TrojanDownloader:Win32/Small.ZZB
VBA32 3.12.6.0 2008.02.10 suspected of Downloader.Zlob.7
Additional information
File size: 361158 bytes
MD5: 7242e876564fdb008db749710fc87a92
SHA1: c1c6e287c47d744d8d549a0c81a065a5ce133037
PEiD: -
detected by Microsoft as TrojanDownloader:Win32/Small.ZZB (this is from
a Virustotal result - see below). Using Sandboxie, I executed the file
and Windows Defender did nothing to stop it. Is this normal behaviour
for WD? Thanks for your help.
Virustotal result:
www.virustotal.com/analisis/9e2cae813e8514ecf61e19f92829811c
Result: 7/32 (21.88%)
File install_cn.exe received on 02.11.2008 00:28:41 (CET)
Antivirus Version Last Update Result
Avast 4.7.1098.0 2008.02.10 Win32:Agent-LTS
AVG 7.5.0.516 2008.02.10 Downloader.Zlob
ClamAV 0.92 2008.02.10 Trojan.Dropper-4103
DrWeb 4.44.0.09170 2008.02.10 Adware.Supa
Kaspersky 7.0.0.125 2008.02.11 not-a-virus:AdWare.Win32.Vapsup.azp
Microsoft 1.3204 2008.02.10 TrojanDownloader:Win32/Small.ZZB
VBA32 3.12.6.0 2008.02.10 suspected of Downloader.Zlob.7
Additional information
File size: 361158 bytes
MD5: 7242e876564fdb008db749710fc87a92
SHA1: c1c6e287c47d744d8d549a0c81a065a5ce133037
PEiD: -