I then submitted the file via the Webroot SecureAnywhere built-in reporting tool and to VirusTotal. A few minutes later, WSA automatically removed the offending file from the computer.
Can someone at Webroot tell me what triggered the WSA cloud to finally change its determination on this file?
https://www.virustotal.com/file/1fccbab2964e9f0afa46efacfabcd92fb7d655a59d8a33285ca98d00632b50e6/analysis/1359566849/
Did it get detected by
- A live feed from VirusTotal since it was detected by 5 other AV engines
- Get flagged locally since I submitted it as an infection
- Get flagged in the cloud automatically since I submitted it as an infection and it was already suspicious
- Reviewed by a human since I submitted it and they flagged it as an infection
- The cloud figured it out itself presumably since it was mass-spammed to other customers?
explanoit