Author Topic: Avast does not detect TR/Crypt.XPACK.Gen [SOLVED]  (Read 2129 times)

0 Members and 2 Guests are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34067
  • malware fighter
Avast does not detect TR/Crypt.XPACK.Gen [SOLVED]
« on: July 12, 2012, 12:27:27 PM »
See: http://zulu.zscaler.com/submission/show/b00520a78f0b1978cfdf828cfe404e6d-1342087877
and
https://www.virustotal.com/file/de49d3e6b6e07d6608dd4019115188691b976d05d36ed7b008f59ae96fc19cba/analysis/
Two IDS alerts here: http://urlquery.net/report.php?id=88302
for FILEMAGIC windows executable (read: http://blog.inliniac.net/2011/11/29/file-extraction-in-suricata/  link author =  inliniac)
& FILE-IDENTIFY Portable Executable binary file magic detected (for those interested in download alerts, as we are)
See: http://minotauranalysis.com/search.aspx?q=58af0f7cb3eb0273881c8733b336cced

reported to virus AT avast dot com,

polonus
« Last Edit: August 20, 2012, 05:56:14 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Rambouu

  • Guest
Re: Avast does not detect TR/Crypt.XPACK.Gen
« Reply #1 on: August 20, 2012, 03:50:43 PM »
Just wondering what the latest is on this, please!

All Anti-virus software out there (To my knowledge) except 'one' will detect this particular Trojan.  I love Avast with all my heart but i would be interested to know why the highly dangerous  'TR/Crypt.XPACK.Gen' is'nt getting detected. 

Thanks! :)


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34067
  • malware fighter
Re: Avast does not detect TR/Crypt.XPACK.Gen
« Reply #2 on: August 20, 2012, 04:12:36 PM »
Hi Rambouu,

You can continue to love your avast av solution, because you were protected all the time by the avast Network shield that prevents you to connect to sites like this: htxp://stireadebacau.ro/ey4o.exe  and to 'TR/Crypt.XPACK.Gen on there, so your computer won't even meets this malcode....
So this threat url  is being detected as URL:Mal. We have detection via the shields. So as ageneral advice to all, keep these avast shields up and running, guys and gals, because they form a vital part of your ptotection,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!