The next file is detected by Comodo according to VirusTotal.
But when I download and run this file, CAV is quiet (on access).
It is sandboxed but still not detected by real-time AV module.
Submission says that it is unknown.
On-demand scan detects it.
Why CAV doesn’t catch it during or after download?
Such things also happened to me.
My idea is that the file is a self extracting archive containing infected files. CIS realtime scanner does not identify the archived files.
Does CAV detecting anything if you allow it to run and when it executes ?
Then this is something that I expected. But, surprisingly they must be detected after they are extracted in realtime. PM egemen about this, may be he will have a look.