Avast WEBforum

Other => Viruses and worms => Topic started by: Mr.Agent on February 05, 2009, 09:56:24 PM

Title: Avast missed a dangerous virus
Post by: Mr.Agent on February 05, 2009, 09:56:24 PM
Hi Avast you missed a nice keylog/trojan if u want the .exe tell me because you are the only 1 that dont detect it !!!!! well i dont know if i post on the right section but i just wanted to let you know for you add it to in the list of the virus data base because its really dangerous to let a virus like that on internet.

One chance i dont execute this file !!!! my god

Virus scan proof : http://www.virustotal.com/analisis/6284bd01c3556399650ea45195d18b6f

Mr.Agent
Title: Re: Avast missed a dangerous virus
Post by: DavidR on February 05, 2009, 10:06:32 PM
Send the sample to virus@avast.com zipped and password protected with the password in email body, a link to this topic might help and undetected malware in the subject.

Or you can also add the file to the User Files (File, Add) section of the avast chest (if it isn't already there) where it can do no harm and send it from there. A copy of the file/s will remain in the original location, so you will need to take further action and can remove/rename that.

Send it from the User Files section of the chest (select the file, right click, email to Alwil Software). It will be uploaded (not actually emailed) to avast when the next avast auto (or manual) update is done.
Title: Re: Avast missed a dangerous virus
Post by: Mr.Agent on February 05, 2009, 10:11:22 PM
but i wanna be sure if i didnt execute the exe does i will be infected or no

and how do i protect the zip by a password ?
Title: Re: Avast missed a dangerous virus
Post by: DavidR on February 05, 2009, 10:23:28 PM
It won't execute adding it to the avast chest or zipping and password protecting it.

This really isn't as serious as you believe, I also believe that avast previously removed ard

http://www.viruslist.com/en/analysis?pubid=187865525 (http://www.viruslist.com/en/analysis?pubid=187865525)
Quote
Ardamax is not considered a Trojan because it was developed by a legitimate software company and is sold as a legal program. However, authors of many malicious programs are happy to regard it as a ready-made spyware module they can use instead of bothering to write their own. Commercial keyloggers are one of the biggest gray areas in the relations between antivirus companies and software developers. Even though they can be used as Trojans, these programs do have legal and genuinely legitimate applications.

http://www.sophos.com/security/analyses/viruses-and-spyware/trojmdropajm.html (http://www.sophos.com/security/analyses/viruses-and-spyware/trojmdropajm.html)
Title: Re: Avast missed a dangerous virus
Post by: Mr.Agent on February 05, 2009, 10:25:30 PM
ok then how i protect the file with password

i will just send the file to virus avast i wont do the chest thing u say i didnt executed it so im safe for now until you update the virus data base for its became as a threat
Title: Re: Avast missed a dangerous virus
Post by: DavidR on February 05, 2009, 10:31:47 PM
That entirely depends on what zip program you use, but the second option to add it to the avast chest is by far the simplest option and send it directly from there.
Title: Re: Avast missed a dangerous virus
Post by: Mr.Agent on February 05, 2009, 10:39:36 PM
i think i found it its say make a password so thank you i hope its that i will send it to virus avast thank you again david until i didnt opened the file its ok

!!!! another problem is i cant send any virus because my comp wont let me to do it omg lol

Edit : i have moved it to chest like you said and there no problem i sended it to alwil thx !
Title: Re: Avast missed a dangerous virus
Post by: Maxx_original on February 06, 2009, 10:08:24 AM
do you mean this Ardamax, which seems to be a legit keylogger? we've removed the detection few weeks ago..
Title: Re: Avast missed a dangerous virus
Post by: CharleyO on February 06, 2009, 10:47:13 AM
***

ScanDoo says the site is not a good one to visit. Click the image below to enlarge.


***
Title: Re: Avast missed a dangerous virus
Post by: YoKenny on February 06, 2009, 01:04:12 PM
***

ScanDoo says the site is not a good one to visit. Click the image below to enlarge.


***
McAfee SiteAdvisor rates it RED and it is blocked in my HOSTS file.
Title: Re: Avast missed a dangerous virus
Post by: Maxx_original on February 06, 2009, 01:09:52 PM
ook, we'll reconsider the classification..
Title: Re: Avast missed a dangerous virus
Post by: DavidR on February 06, 2009, 03:06:40 PM
If you look at my Reply #3, the quote is clear that it is a legit program, the problem it that it can be used by malware for malicious purposes and this it the problem with tools like this, the AV can't determine intent.

That is down to the user, did they download/install this and if not then the intent is likely to be malicious. So perhaps the classification should be risk tool, or something like that.
Title: Re: Avast missed a dangerous virus
Post by: Mr.Agent on February 06, 2009, 05:24:57 PM
well i reported a virus for ppl be more safe of the user that created that ardamax
Title: Re: Avast missed a dangerous virus
Post by: Mr.Agent on February 22, 2009, 07:53:49 PM
well i think avast didnt putted it in the virus data base and i find another virus which its a backdoor trojan which i was about to execute and i didnt have do it i scanned it on virustotal and see what its find http://www.virustotal.com/en/analisis/06f13e1e1d27675185032441553c6cbd
Title: Re: Avast missed a dangerous virus
Post by: DavidR on February 22, 2009, 08:03:32 PM
Send the sample to virus@avast.com zipped and password protected with the password in email body, a link to this topic might help and false positive/undetected malware in the subject.

Or you can also add the file to the User Files (File, Add) section of the avast chest (if it isn't already there) where it can do no harm and send it from there. A copy of the file/s will remain in the original location, so you will need to take further action and can remove/rename that.

Send it from the User Files section of the chest (select the file, right click, email to Alwil Software). It will be uploaded (not actually emailed) to avast when the next avast auto (or manual) update is done.
Title: Re: Avast missed a dangerous virus
Post by: Mr.Agent on February 22, 2009, 08:15:26 PM
David can i just send the upload link to them ?
Title: Re: Avast missed a dangerous virus
Post by: DavidR on February 22, 2009, 08:22:41 PM
Well if you have this sample on your system it is easy to add it to the user files section of the chest and upload it from there.

They can analyse a file, they can't analyse the virustotal results page.
Title: Re: Avast missed a dangerous virus
Post by: Mr.Agent on February 22, 2009, 08:31:37 PM
ok i will send the 2 files
Title: Re: Avast missed a dangerous virus
Post by: Mr.Agent on February 22, 2009, 08:36:18 PM
But after i sended it can i remove the files of my pc because im really scare about these files !
Title: Re: Avast missed a dangerous virus
Post by: DavidR on February 22, 2009, 09:12:56 PM
They can do no harm in the User Files section of the chest (delete the original copy in the original location). With them there it also allows you to periodically scan them within the chest, when avast adds them to the VPS you will see them detected.
Title: Re: Avast missed a dangerous virus
Post by: Mr.Agent on February 22, 2009, 09:29:06 PM
k well i delete the original copy of the upload and i put them on the chest and i have email them to alwil i hope this time he will put it because its really a virus these 2 files and i alway do virustotal before running a program

But a question does its the true if i didnt execute the exe i wont be infected ? and if i have open the zip and not the exe does i will be infected or no ?

Sry for these question im just scaring for downloaded them on my pc im just wondering if i have open the zip and see what its contain on it !
Title: Re: Avast missed a dangerous virus
Post by: Lisandro on February 22, 2009, 10:18:08 PM
does its the true if i didnt execute the exe i wont be infected ?
Yes.

and if i have open the zip and not the exe does i will be infected or no ?
Not infected, yet.
Title: Re: Avast missed a dangerous virus
Post by: Mr.Agent on February 23, 2009, 09:09:25 PM
one chance so im not infected i hope :D but some time i execute the zip and see what its got but some time its the exe is infected or something but i wont take any chance in any way thx Tech you save me i was attempt to cry but its didnt happaned xD
Title: Re: Avast missed a dangerous virus
Post by: Lisandro on February 23, 2009, 09:21:50 PM
one chance so im not infected i hope :D but some time i execute the zip and see what its got but some time its the exe is infected or something but i wont take any chance in any way thx Tech you save me i was attempt to cry but its didnt happaned xD
Run a full avast scanning, archive included, just to be sure ;)
Title: Re: Avast missed a dangerous virus
Post by: Mr.Agent on February 23, 2009, 09:46:03 PM
ok mate i setting my performance to standard and archive and its scan now thx
Title: Re: Avast missed a dangerous virus
Post by: Mr.Agent on February 23, 2009, 10:41:00 PM
avast find some files that cant be scanned because its was protected with password on my folder but i scanned them on virustotal and its seem to be fight trought the other av so thank tech i will scan my pc with my anti spyware i have clear my temp folder of windows i think my pc is fine of the virus thx very mush tech
Title: Re: Avast missed a dangerous virus
Post by: Lisandro on February 23, 2009, 11:16:35 PM
i scanned them on virustotal
Same answer as here: http://forum.avast.com/index.php?topic=42725.msg358531#msg358531
Title: Re: Avast missed a dangerous virus
Post by: Mr.Agent on February 23, 2009, 11:31:00 PM
i have see thx tech
Title: Re: Avast missed a dangerous virus
Post by: malberto on February 24, 2009, 03:26:41 AM
Send a mail with the file to the ALWIL Lab for the analysis. Compress the file and put an password, remember says the password in the mail and next atach this
Title: Re: Avast missed a dangerous virus
Post by: Mr.Agent on February 24, 2009, 09:11:41 PM
i think zilontrainer.exe its easy to see its a keylogger just to see it in virustotal all anti virus detect it but no avast,pctools etc
Title: Re: Avast missed a dangerous virus
Post by: Mr.Agent on February 25, 2009, 12:54:22 PM
Avast have put nefertyhook v5.03 as a trojan-gen so i can delete it from the chest ? and zilontrainer is still no there its a ardamax keylogger which is vunerable to user i recommand to avast to scan it on virustotal if they didnt believe me
Title: Re: Avast missed a dangerous virus
Post by: Lisandro on February 25, 2009, 01:07:05 PM
Mr.Agent, files into Chest are safe to be kept there. Can't harm your computer.
Also, to legit files, you can use the avast exclusion lists (there are two).
Title: Re: Avast missed a dangerous virus
Post by: Mr.Agent on February 25, 2009, 09:23:26 PM
you say i can add my own file to the my virus database ? if its really that u say tell me how please
Title: Re: Avast missed a dangerous virus
Post by: Lisandro on February 25, 2009, 10:51:02 PM
you say i can add my own file to the my virus database ? if its really that u say tell me how please
Not the database, but exclusion lists IF THE FILE IS CLEAN.
You need to use the Exclusion lists:

For the Standard Shield provider (on-access scanning):
Left click the 'a' blue icon, click on the provider icon at left and then Customize.
Go to Advanced tab and click on Add button...

For the other providers (on-demand scanning such as the screen-saver or the Simple User Interface):
Right click the 'a' blue icon, click Program Settings.
Go to Exclusions tab and click on Add button...

You can use wildcards like * and ?.
But be careful, you should 'exclude' that many files that let your system in danger.
Title: Re: Avast missed a dangerous virus
Post by: Mr.Agent on February 26, 2009, 12:44:44 PM
k i understand but well i still wait for zilontrainer to be in the virus data base because its like a keylogger that can harm the other ppl which avast didnt see