Strange thing

Hi guy i have scanning a file that i downloaded and virustotal said that only sunbelt find it as a encrypted archive not avast,avira,avg,kaspersky,etc…

Sunbelt 3.2.1855.2 2009.02.17

Detected this as a encrypted archive so i was asking if its safe or no

Thank in any way from me im really happy that im on this forum its really nice to talk with you guy

Encrypted archive files can’t be scanning… the engine does not know the password and does not use brute force.
Sunbelt is only logging this phenomenon.

k but its look clean the file to avast so yeah thx

It doesn’t look clean or dirty to avast! It’s encrypted and therefor not readable or scanned.

Until the file is de-crypted, it can’t do any harm even if it was infected and would be caught by avast!
at that time.

The simple fact is that an encrypted file would require a lot of processing effort to decrypt it and that is totally impractical (though not impossibly) for any resident on-access or on-demand scanner.

I would say that just because the archive is encrypted Sunbelt figures it must be suspect.

Also it isn’t actually saying anything other than it is an encrypted archive nothing else, I suppose a little like avast reporting password protected archives. So you would have to follow the same procedure, file name, location = program involved, so would that seem to have a legitimate reason to encrypt an archive.

avast can’t scan encrypted files, by decryption, other than a raw data scan so you can’t hold too much store in nothing being found as avast wouldn’t be able to extract the encrypted archive to be able to scan it.

but well if i trust it and other guy use it i think i will trust it ?

well i have run some time a zip protected and the exe was a virus and avast did catched it so he blocked it from my cpu so if there was a virus on the dll or exe or something i think avast will catch it im sure

Trust is a word I seldom use and there is nothing in the above information that would lead me to trust anything as we don’t even know the file name or its location to take a stab at what program it belongs as to if there might be a legit reason to encrypt an archive file.

I have no idea who the other guy might be so how is it possible to trust them.

they protected maybe for copyright but i didnt think its a virus because avast will catch it up if its was a virus :smiley:

But we simply don’t know that because in its encrypted form it effectively can’t be scanned, so if it can’t be effectively scanned there is no guarantee if when decrypted avast would be able to detect it if it were infected.

Which is why I’m making such a big deal of file name and location = program, which may equal if there is a valid reason for encrypting an archive, but you seem to be reluctant to tell us what the file name and location are. Perhaps my prodding was too subtly, when I should have asked a direct question.

well i had a zip yesterday and its was in zip protected with pass so i typed the password for open the exe and avast found a virus on it so if there any virus i think avast will know if its got a virus or no and i also do full scan with all my protection program and nothing was found of virus in my pc :smiley:

I hope you’re kidding. That’s a foolish assumption. http://en.wikipedia.org/wiki/Zero_day_virus

im not kidding but avast or any program of protection detected a virus on it so :slight_smile: