Avast WEBforum

Consumer Products => Avast Free Antivirus / Premium Security (legacy Pro Antivirus, Internet Security, Premier) => Topic started by: dos622 on July 18, 2009, 08:44:10 AM

Title: virus detect
Post by: dos622 on July 18, 2009, 08:44:10 AM
Sorry for English.
I Founded a couple of viruses. sent them by mail virus@avast.com three days ago, but nothing has changed. Avast still finds no viruses, although the update receives a daily basis.

Founded: Dr.Web, Kasperskiy, Nod, Symantec.
Avast Pro: Not Founded.
Title: Re: virus detect
Post by: Tarq57 on July 18, 2009, 10:04:43 AM
Hi dos622,
Your English is OK.
Any chance you could also upload the files to Virustotal (http://www.virustotal.com/) and post the links to the results page, please?
It would be good to see Avast get onto these.
Title: Re: virus detect
Post by: dos622 on July 18, 2009, 10:41:13 AM
http://www.virustotal.com/ru/analisis/ba61f4318af2ecc7697241d5dbedf08c19b3a0265a2478430aacdfabe37d2724-1247906711

http://www.virustotal.com/ru/analisis/24f0c1b181040c221e9fc6ea434cbed8c877d716336c6c6432781c583ae88eb8-1247906776

2 files

Title: Re: virus detect
Post by: Tarq57 on July 18, 2009, 01:36:32 PM
Thank you.
That confirms your statement. (I didn't doubt it at all.)


According to Symantec, here (http://www.symantec.com/security_response/writeup.jsp?docid=2008-102011-5014-99) and here (http://www.symantec.com/security_response/writeup.jsp?docid=2009-071713-2155-99), the risk level is low, there are not many infections (0-49 known, for both,) damage medium/low.
Other information I have read indicates one or both of these are password stealers. Not to be taken lightly. Country of origin, I haven't seen. (Don't know.)
Lucky you!  ;)
Lets hope Avast adds these detections, soon.
Title: Re: virus detect
Post by: Lisandro on July 18, 2009, 02:00:19 PM
Please, improve detection!
Title: Re: virus detect
Post by: dos622 on July 18, 2009, 02:15:06 PM
Vps:  090717-0
server download948.avast.com (74.54.46.98:80)

virus    not found

I have about 200 computers protected by Avast.
walk virus in all.  ;D
Title: Re: virus detect
Post by: .: L' arc :. on July 18, 2009, 03:35:09 PM
 Hope it gets fixed. As of now, based from what I see, analysis of new samples submitted to ALWIL is a bit faster than before. So i guess, tomorrow would be the day for that.
Title: Re: virus detect
Post by: dos622 on July 18, 2009, 03:51:57 PM
ok! Thanks! ;D
Title: Re: virus detect
Post by: dos622 on July 20, 2009, 08:35:28 AM
Warning!
Avast not detect virus!!!! Help.
http://www.virustotal.com/ru/analisis/ba61f4318af2ecc7697241d5dbedf08c19b3a0265a2478430aacdfabe37d2724-1248071981
http://www.virustotal.com/ru/analisis/24f0c1b181040c221e9fc6ea434cbed8c877d716336c6c6432781c583ae88eb8-1248071990
Title: Re: virus detect
Post by: dos622 on July 20, 2009, 10:04:26 AM
If you need files, tell me where to send.
Title: Re: virus detect
Post by: dos622 on July 20, 2009, 12:35:12 PM
Au! You here?  :) help please!
Title: Re: virus detect
Post by: spg SCOTT on July 20, 2009, 12:37:46 PM
If you want to send them to alwil, send them in a password protected archive to virus(at)avast(dot)com, advisingthe password in the body of the email. you could also add a link to this thread.

Or you could add the files to the 'user files' area of the chest and send it from there.
Title: Re: virus detect
Post by: Tarq57 on July 20, 2009, 12:41:02 PM
These are the same as the files you reported at the beginning of the thread?
You say you have already emailed them to Avast.
Nothing more to do, but wait, I'm afraid.

You could try a different demand scanner, such as Superantispyware, and/or MBAM,. both run OK with Avast. They are (in the free versions) demand anti malware/trojan scanners, and both are very good.
Title: Re: virus detect
Post by: dos622 on July 20, 2009, 12:44:43 PM
I`m send this files 5 day ago. Since then nothing has changed.
Title: Re: virus detect
Post by: dos622 on July 20, 2009, 01:24:30 PM
Mail send.
Title: Re: virus detect
Post by: dos622 on July 20, 2009, 02:24:46 PM
Superantispyware, and/or MBAM,.
It`is Working for Win 2003 Server?
Title: Re: virus detect
Post by: dos622 on July 21, 2009, 07:02:03 AM
Hi,
virus database 090720-0.
http://www.virustotal.com/ru/analisis/24f0c1b181040c221e9fc6ea434cbed8c877d716336c6c6432781c583ae88eb8-1248152635
http://www.virustotal.com/ru/analisis/ba61f4318af2ecc7697241d5dbedf08c19b3a0265a2478430aacdfabe37d2724-1248152669

Support works?
first post in this topic: July 18, 2009, 06:44:10 AM
Avast not detect virus!!!  >:( WHY???
Title: Re: virus detect
Post by: Tarq57 on July 21, 2009, 07:09:26 AM
Quote
It`is Working for Win 2003 Server?
It does not say it does, in the supported operating systems, but I see no reason why it would not.
You could always try it.
Title: Re: virus detect
Post by: dos622 on July 21, 2009, 11:30:21 AM
tell me about my problem. virus not detected avast.
Title: Re: virus detect
Post by: Maxx_original on July 21, 2009, 12:06:47 PM
it's the case of AutoIt, which is internally decompiled already, but the proper update of the engine is not yet publicly available - it's not about the update of virus database, we decided to apply some smart methods to detect AutoIt malware and these must be implemented to engine... once it will be done, the detection of AutoIt malware will be quick, easy and accurate.. sorry for any inconvenience, we know about some lags in the processing of AutoIt samples, but all necessary steps to resolve this issue are ready to rock & roll (you'll se soon) ;)
Title: Re: virus detect
Post by: dos622 on July 21, 2009, 12:22:11 PM
ok.
I will wait with impatience.
Title: Re: virus detect
Post by: waleed101 on July 21, 2009, 08:44:17 PM
I had the same problem 3 months ago I sent the virus to avast by Email and by quarantine but avast still never catch the virus this is total virus report:
http://www.virustotal.com/analisis/8d5ba610dad2d60901117e81a4698a5950889972260e9fe5e2bb5ccee2d07f5d-1248201538
why this slow response from avast :( :( :(
Title: Re: virus detect
Post by: Maxx_original on July 21, 2009, 11:15:52 PM
because it is not much clever to detect AutoIt malware from outside and the developing (and testing) of an decompiler took some time... as you maybe know - there are some publicly available AutoIt scramblers and "encryptors" and AutoIt itself could be quite polymorphic - that makes the detection from outside ineffective, because it covers only the one particular file, while the authors of the malware are able to make the same (or slightly different) sample in a minute and it will be undetected... the decompilation gives us a chance to make algorithmical detections, which are much stronger (in our internal testing two algo detections can catch thousands of malware AutoIt samples, that really worth it)...
Title: Re: virus detect
Post by: Lisandro on July 21, 2009, 11:23:21 PM
It's a pity that a fantastic tool to develop .exe files is being used by the dark side...
Title: Re: virus detect
Post by: Maxx_original on July 22, 2009, 09:39:40 AM
Tech: almost all good tools were already abused by malware authors... very similar to AutoIt is a case of QuickBatch (you can embed a batch file and any additional data into an encrypted and compressed stream) - it's easy to make a malware with few mouse clicks :(... the extractor of QuickBatch files is under development now..
Title: Re: virus detect
Post by: dos622 on July 24, 2009, 07:59:44 AM
when we wait for version of avast which will treat these viruses?