Avast WEBforum

Other => Viruses and worms => Topic started by: Hellion on February 16, 2012, 09:47:57 AM

Title: Are you kidding me?
Post by: Hellion on February 16, 2012, 09:47:57 AM
Hi,

I submitted a zero-day malware sample three days ago and Avast still doesn't detect it?

When I was sent this sample, 1/43 av's on VT detected it.

Today 27/43 detects it and Avast is not one of them! I sent the sample via E-mail with a password and I uploaded it from virus chest!

This is actually shocking.

VT -https://www.virustotal.com/file/67d8ca23e6eb40bc848fcae71191d6b8c1d5ce9c0b92150eece351036acb2396/analysis/1329381714/
Title: Re: Are you kidding me?
Post by: Hermite15 on February 16, 2012, 10:24:34 AM
+1 Avast should be a bit faster ... hope they notice this thread and update the next VPS accordingly.
Title: Re: Are you kidding me?
Post by: DavidR on February 16, 2012, 11:40:20 AM
@ Hellion
Why not submit it from the avast chest, as it doesn't have to go through numerous email servers (which could possibly kill it). I think coming directly from the chest may well get a faster response and you don't zip and password protect the sample in order to email it as it is directly uploaded during the next auto update check (or if you invoke a manual update check).

Can you please modify your signature it is massive, no need for double line spacing and more can be placed on a single line, thanks.
Title: Re: Are you kidding me?
Post by: Hellion on February 16, 2012, 12:47:16 PM
Hi DavidR,

Please look more closely at my original post.

Quote
I sent the sample via E-mail with a password and I uploaded it from virus chest!

I have edited my signature, I trust that it's fine now.

EDIT: I inserted "Hi" before DavidR,
Title: Re: Are you kidding me?
Post by: DavidR on February 16, 2012, 12:49:44 PM
Sorry missed the bit where it was sent from the chest also.

Well no need to go to the other extreme with the signature ;D
Title: Re: Are you kidding me?
Post by: Hellion on February 16, 2012, 01:01:06 PM
Hi DavidR,

No problem.

It's ok, it's only relevant when I post an issue or bug, but I will copy-paste that in manually when It's needed.

Thanks for the response.
Title: Re: Are you kidding me?
Post by: DavidR on February 16, 2012, 01:25:05 PM
You're welcome.
Title: Re: Are you kidding me?
Post by: Hellion on February 17, 2012, 07:59:54 AM
Hi,

I would just like to report that Avast now detects this malware as Malware-gen.

This virus infected my machine with 3 others in less than a day, Fortunately Malwarebytes added the sample within a day and I was able to remove this threat before any real damage.
Title: Re: Are you kidding me?
Post by: DavidR on February 17, 2012, 01:18:34 PM
Thanks for the update.