Author Topic: wxx.findvirus.ru NOT detected by avast!  (Read 3945 times)

0 Members and 1 Guest are viewing this topic.

Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
wxx.findvirus.ru NOT detected by avast!
« on: April 06, 2011, 01:29:54 PM »
Findvirus.ru is a fake site,similar to avastfrance.com,remember?This site contains HoaxSMS Fake installers -for BitDefender/Avast/Avira/Dr.Web/Mcafee/Norton Fake products
Full story here : http://xylibox.blogspot.com/2011/04/findvirusru-hoaxsms-fake-installers.html
Block it please.You rly find a virus at findvirus.ru ;).How lame!
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus

Offline danny96

  • Malware Fighter
  • Advanced Poster
  • **
  • Posts: 668
  • No-malware!
Re: wxx.findvirus.ru NOT detected by avast!
« Reply #1 on: April 06, 2011, 01:41:06 PM »
Findvirus.ru is a fake site,similar to avastfrance.com,remember?This site contains HoaxSMS Fake installers -for BitDefender/Avast/Avira/Dr.Web/Mcafee/Norton Fake products
Full story here : http://xylibox.blogspot.com/2011/04/findvirusru-hoaxsms-fake-installers.html
Block it please.You rly find a virus at findvirus.ru ;).How lame!
Agree, HoaxSMS is very annoying virus!
analysis
http://www.virustotal.com/url-scan/report.html?id=a8534b56f917799cbcb5976750e4d20d-1302082935 (1/6)
http://www.virustotal.com/file-scan/report.html?id=3f497966330ad949a392169e6571298c1c235a437b0fabec16d5d5d0dafd687e-1302090141
http://safeweb.norton.com/report/show?url=findvirus.ru
« Last Edit: April 06, 2011, 01:44:07 PM by danny96 »
Real-time protection and Firewall: COMODO Internet Security 12.0.0.6810 -- Additional Protection: Web Of Trust, Ublock, NoScript, Malwarebytes Premium, Avast! Online Security, Hitman Pro -- OS: Windows 10

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Re: wxx.findvirus.ru NOT detected by avast!
« Reply #2 on: April 06, 2011, 04:05:47 PM »
Hi, folks, the latest of these malwares resides here: htxp://www.findvirus.ru/downloads/ZoneAlarm_ForceField.exe
Norton Safe Web does not have this one, so very recent find, alive and up malware
avast does not flag it yet: http://www.virustotal.com/file-scan/report.html?id=864cf0b71fc9619e211faf9cda2c252c774c0719718121bd457918747df2e102-1302078027
and for Pondus "nor does norman flag it"
This is a so-called suspicious insight generic find, important to be blocked...

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
Re: wxx.findvirus.ru NOT detected by avast!
« Reply #3 on: April 06, 2011, 04:35:20 PM »
Hi, folks, the latest of these malwares resides here: htxp://www.findvirus.ru/downloads/ZoneAlarm_ForceField.exe
Norton Safe Web does not have this one, so very recent find, alive and up malware
avast does not flag it yet: http://www.virustotal.com/file-scan/report.html?id=864cf0b71fc9619e211faf9cda2c252c774c0719718121bd457918747df2e102-1302078027
and for Pondus "nor does norman flag it"
This is a so-called suspicious insight generic find, important to be blocked...

polonus

I think avast doesn't even detect one of the samples at findvirus.ru/downloads
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89287
  • No support PMs thanks
Re: wxx.findvirus.ru NOT detected by avast!
« Reply #4 on: April 06, 2011, 05:10:58 PM »
Then a) send the sample to avast and b) give them the URL of the site when submitting the sample. Talking about in the forums doesn't help.

Send the sample/s to avast as a Undetected Malware:
Open the chest and right click in the Chest and select Add, navigate to where you have the sample and add it to the chest (see image). Once in the chest, right click on the file and select 'Submit to virus lab...' complete the form and submit, the file will be uploaded during the next update.
Or
Send the sample to virus (at) avast (dot) com zipped and password protected with the password in email body, a link to this topic might help and undetected malware in the subject.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Re: wxx.findvirus.ru NOT detected by avast!
« Reply #5 on: April 06, 2011, 10:48:28 PM »
To all,

Have forwarded the all the valid data to the avast mail address, so the analyst of duty can add detection,
together with this info to check against: http://www.backgroundtask.eu/Systeemtaken/taakinfo/23378/ISWSVC.exe/


polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
Re: wxx.findvirus.ru NOT detected by avast!
« Reply #6 on: April 08, 2011, 03:17:37 PM »
Still undetected :-\
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Re: wxx.findvirus.ru NOT detected by avast!
« Reply #7 on: April 08, 2011, 07:31:35 PM »
Hi Left123,

Is suspicious see here: http://wepawet.iseclab.org/view.php?hash=5dbf6e7345c0dd9f1a7948fc769911e8&t=1302122360&type=js

and look here:

htxp://jsunpack.jeek.org/dec/go?report=88e1a886dd27a397c00b354b472d65e95969d09c
(go here sandboxed and with script protection enabled if you know what you are doing, see attached image)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!