Avast WEBforum

Other => Viruses and worms => Topic started by: Yanto.Chiang on January 17, 2011, 08:57:55 AM

Title: 6000 virut from vietnam
Post by: Yanto.Chiang on January 17, 2011, 08:57:55 AM
Dear All,

Does anybody ever try with this variants virus before?

(The link has remove)

Note : Please aware to try it on your another system, before your download from this link

cheers,
Title: Re: 6000 virut from vietnam
Post by: Yanto.Chiang on January 17, 2011, 10:53:51 AM
Hi Pondus and Omid,

Thanks for your support and co-operation,

I already tried with my vmware with avast free antivirus and avast capable to detect this variants as well till i submit this update avast still working hard to remove....is need 6000 times....crazy i should waiting till 6000 files removed.... :o :o :o
Title: Re: 6000 virut from vietnam
Post by: Yanto.Chiang on January 17, 2011, 10:54:30 AM
2nd pictures
Title: Re: 6000 virut from vietnam
Post by: Omid Farhang on January 17, 2011, 11:58:21 AM
you better extract them in a folder excluded from real-time shield and then do an on-demand scan, the way you are extracting this and detections from real-time shield will make it a never ending story
Title: Re: 6000 virut from vietnam
Post by: Omid Farhang on January 17, 2011, 03:42:10 PM
While reading these results please mind there are about 100 clean or very old (out-dated) samples in this archive.

Norman:
Quote
Scan result;;Malware found.;2
5926;Objects scanned (files and items inside archives).;;0
5915;Files scanned.;;0
0;Files skipped (access problems).;;0
0;Files on Exclude list excluded.;;0
2;Archive files (or archives inside archives).;;0
0;Archive files that could not be properly scanned.;;0
5755;Infections found.;;0
17;Files with multiple infections found.;;0
373;Files repaired.;;0
5363;Files deleted.;;0
0;Files will be deleted at next computer restart.;;0
0;Infections detected by Sandbox.;;0
21827435;Bytes scanned (files and archive content).;;0
21730909;Bytes found in files.;;0
;Elapsed time: 0:05:36 (hh:mm:ss);;0

Avira:
Quote
The scan has been done completely.

      1 Scanned directories
   5927 Files were scanned
   5820 Viruses and/or unwanted programs were found
      0 Files were classified as suspicious
   5819 files were deleted
      0 Viruses and unwanted programs were repaired
      0 Files were moved to quarantine
      0 Files were renamed
      0 Files cannot be scanned
    107 Files not concerned
      2 Archives were scanned
      0 Warnings
   5819 Notes

Microsoft:
Quote
Scan completed on 6091 items
detected 5724 potential threats

VirusBuste (Outpost):
It had not a good result so let ignore it  ;D

Also I've dropped AVG from my Scanners as they are acting very unprofessionally in past few years
Title: Re: 6000 virut from vietnam
Post by: danny96 on January 17, 2011, 05:19:33 PM
Hi Pondus and Omid,

Thanks for your support and co-operation,

I already tried with my vmware with avast free antivirus and avast capable to detect this variants as well till i submit this update avast still working hard to remove....is need 6000 times....crazy i should waiting till 6000 files removed.... :o :o :o

offtopic,... but don't wanna to create a new topic
why can avast pop-up maximum of 51 popups? i tried to use "show last popup..." hundred times but max. capacity is 51. avast team should do Multiple thread detection - visit avg (show 100  popups viruses or more at time)
Title: Re: 6000 virut from vietnam
Post by: nmb on January 17, 2011, 05:23:37 PM
@Yanto

Isn't it a forum rule that we don't or shouldn't post the links to viruses? - Just in view of those people who might get infected trying such things.
Title: Re: 6000 virut from vietnam
Post by: DavidR on January 17, 2011, 05:46:35 PM
Yes, the link should be removed as you have no control over who can download it or what they intend to do with them.

The forums should not become a quasi malware distribution site.

Please remove the link.
Title: Re: 6000 virut from vietnam
Post by: Pondus on January 17, 2011, 05:58:05 PM
Malwarebytes

Quote
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Databaseversjon: 5538

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

17.01.2011 17:52:17
mbam-log-2011-01-17 (17-52-17).txt

Skanntype: Hurtigsøk
Objekter skannet: 3571
Tid tilbakelagt: 1 minutt(er), 18 sekund(er)

Minneprosesser infisert: 0
Minnemoduler infisert: 0
Registernøkler infisert: 0
Registerverdier infisert: 0
Registerfiler infisert: 0
Mapper infisert: 0
Filer infisert 191
Title: Re: 6000 virut from vietnam
Post by: Omid Farhang on January 17, 2011, 08:40:16 PM
avast scan:

Quote
Files Tested: 5984
Detected: 5647

Nice, huh?
Title: Re: 6000 virut from vietnam
Post by: Silk0 on January 17, 2011, 08:46:57 PM
avast scan:

Quote
Files Tested: 5984
Detected: 5647

Nice, huh?

A total of detection rate: 94,36%.  Not bad at all..
Submit the rest to avast!.. but first check if they are real malware with other scanners (per example: Malwarebytes) before the process of submit.

By the way, it was a quick scan? If not, which one?
And did you use default settings?
Title: Re: 6000 virut from vietnam
Post by: Pondus on January 17, 2011, 09:27:50 PM
Quote
but first check if they are real malware with other scanners (per example: Malwarebytes) before the process of submit.
if you read it all you will see that Norman/Avira/microsoft/malwarebytes scan result is posted above

Quote
By the way, it was a quick scan? If not, which one?
there is no quick or full scan when scanning a folder....
Title: Re: 6000 virut from vietnam
Post by: Omid Farhang on January 17, 2011, 09:42:01 PM
@Silk0: Please read rest of the topic first. As I said before, I said about clean files, new and old ones and... I posted result of some and said how others reacted...

Sure I will share missed samples to them as I've submitted over +4000 samples (about a total of 2GB) already in last year. ;)

And did you use default settings?
Yes, Default setting (PUP disabled by default setting of avast).
Title: Re: 6000 virut from vietnam
Post by: Pondus on January 18, 2011, 01:47:34 PM
Norman analysis


Quote
This file contains 5922 viruses (not Virut) for DOS (aprx 1988-1996). We detect 5730, the rest is various 1-st generation samples and so on. These things don't work anymore, but people still collect them. We won't prioritize these; if anything we might be removing the entire DOS catalogue from the defs.
Title: Re: 6000 virut from vietnam
Post by: Yanto.Chiang on January 19, 2011, 03:26:15 AM
@Yanto

Isn't it a forum rule that we don't or shouldn't post the links to viruses? - Just in view of those people who might get infected trying such things.

Hi NMB,

Thanks for your kindly advice,

But please see my bold statement to avoid the link to download if you dont want it...

So i already warned to each users before they want to download.

cheers,
Title: Re: 6000 virut from vietnam
Post by: Yanto.Chiang on January 19, 2011, 03:30:56 AM
Hi Pondus and Omid,

Thank you very much for your help to analysis this compress viruses and malwares,

I am still run my virtual machine and still very noisy...i still curious to know it...


But again thanks for your all summary report...keep fighting for malware...
Title: Re: 6000 virut from vietnam
Post by: Yanto.Chiang on January 19, 2011, 04:17:11 AM
Hi Pondus and Omid,

Finally i finished the scan and the results as your guys summary report there is a remains around 278 files and from virustotal summary report for this remains file inside of the folder is around 76% detected as malware

http://www.virustotal.com/file-scan/report.html?id=bc275f42deb7ffab9ef91b067503226f9996e0cf4c72769818ae0b2b03371927-1294577977

cheers,