- "Unfortunately the file (669.f70p53_i_b.dot) is NON-PE. This means the file is a file which does not contain a portable executable header i.e. .dot extension. Webroot is currently only capable of PE malware detection, however the program also contains a heuristics engine for some NON-PE files. In the future, this detection feature will be added."
- "Malware downloaders are commonly re-obfuscated and soon all antivirus will not detect examples of the document you have supplied. This is also true for malware in general."
- This was not verbatim but basically that non-PE files that are manually scanned (Right click, Scan with WebRoot) are not actually scanned or are scanned but WebRoot is mostly unable (depends on the exact file and type) to detect if the file is infected. The proof is that the log file doesn't include an MD5 for the file."
Files scanned = 1, Total Scans = 39, Threats Detected = 0, Active Threats = 0
that WebRoot doesn't actually know if the file is infected because it's a non-PE file. The tech is correct in that the log file does not include an MD5 for this file, only the following:
Tue 2016-05-10 12:03:52.0588 Begin passive write scan (1 file(s))
Tue 2016-05-10 12:03:53.0221 End passive write scan (1 file(s))
Tue 2016-05-10 12:11:13.0187 Scan Started: C:UsersUsernameDownloadsVirusCheck669.f70p53_i_b.dot| [ID: 36 - Flags: 256/36]
Tue 2016-05-10 12:11:14.0080 Scan Results: Files Scanned: 17, Duration: 1s, Malicious Files: 0
Tue 2016-05-10 12:11:14.0089 Scan Finished: [ID: 36 - Seq: 36]
Tue 2016-05-10 12:16:02.0769 Agent Bits : 0
I requested documentation regarding the above functionality or limitations and was told there was none.
Can anyone comment/confirm or provide documentation?