Results 1 to 4 of 4

Thread: ZA anti-virus fails to identify the eicar.com test file

  1. #1
    rawebb Guest

    Default ZA anti-virus fails to identify the eicar.com test file

    Background.

    (1) Sunday I noticed that the ZA-AV log showed an access error (8004025D) for any file that it attempted to scan.

    (2) Monday, based on recommendations here, I did the boot to safe mode -> delete, delete, delete -> reboot -> run MBAM AV and SuperAntiSpyware (both okay, no malware) -> clean registry & system with CClean -> reboot -> do a clean reinstall of ZA-IIS. *Apparently* that whole process went okay, as it completed without errors and ZA seemed to be behaving correctly.

    Today.

    (3) Foolish optimist that I am, I d/l'ed the eicar.com test file again "just to see..." Uh-oh. Running ZA-AV on the directory containing eicar or on the file directly, the log shows "scan complete" with nothing detected, the AV log file also just shows scan complete, no detections, treatments, or quarantines. The contents of eicar.com check correct with the web site, so that's not the problem.

    And ... while pondering the meaning of all this, a scheduled AV scan commenced at 1230. I had set the scan options to "Ultra-Deep Scan" while trying to get it to see eicar.com, so I figured the machine would be busy for a few hours of deep, deep scanning.

    Uh-oh again. The "ultra deep" scan completed (by the AV log) in 7 minutes after "scanning" 355,651 files; the Scanning Status dialog box was (is) still in place, however, stuck on Win32.Trojan.Zlob.2.Gen.179.

    My spider senses are tingling...



    ZoneAlarm Security Suite version:8.0.298.000
    TrueVector version:8.0.298.000
    Driver version:8.0.298.000
    Anti-virus engine version:6.0.2.678
    Anti-virus signature DAT file version:981377051
    Anti-spyware engine version:5.0.209.0
    Anti-spyware signature DAT file version:01.200903.5635
    AntiSpam version:6.0.0.1429

    Operating System:Windows XP Pro
    Software Version:8.0
    Product Name:ZoneAlarm Internet Security Suite

  2. #2
    Join Date
    Nov 2004
    Location
    localhost
    Posts
    17,289

    Default Re: ZA anti-virus fails to identify the eicar.com test file

    HI!you should contact ZA technical support at: www.zonealarm.com/tsformand report your issue.What happens there is not normal. You can't get the ZASS corrupted is such a short time.Probably something else installed on your system that conflicts with ZA.Did you tried to scan in SAFE MODE with networking?Did you actually tried to download and save eicar.com on the desktop? It should be deleted instantly.Good luck and post back your progress with ZA technical support.Cheers,Fax

    Click here for ZA Support
    Monday-Saturday 6am to 10pm Central time
    Closed Sundays and Holidays

  3. #3
    rawebb Guest

    Default Re: ZA anti-virus fails to identify the eicar.com test file

    Yes, something strange is definitely going on.

    After the cleaning and reinstalling yesterday afternoon, I did do a couple of test runs with eicar.com and it was detected and quarantined as expected. Today, not so much.

    Maybe I'll just run Linux for a while... :-(

  4. #4
    little_jo Guest

    Default Re: ZA anti-virus fails to identify the eicar.com test file

    I've got the same version etc as you and my scans are hanging on Win32.Trojan.Zlob.Gen.179 too.
    I tried reinstalling, I have tried reverting to the previous version, all to no avail.
    Last time something like this happened (after v7 came out), we were without AV protection for several weeks until a new version was released.
    Not good.
    Jo

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •