Author Topic: Avast cannot detect KeyBTC ransomware  (Read 2619 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Avast cannot detect KeyBTC ransomware
« on: January 21, 2016, 04:22:00 PM »
Hi,

One of my users got his PC infected with a ransomware that encrypted his files and ask for 0.5BTC (keybtc@inbox.com)

I am currently scanning with "Malwarebytes" but I am wondering : why Avast did not find it ???
Resident shield protection is active and a virus scan found nothing

Best regards,

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37582
  • Not a avast user
Re: Avast cannot detect KeyBTC ransomware
« Reply #1 on: January 21, 2016, 04:58:12 PM »
Quote
I am currently scanning with "Malwarebytes" but I am wondering : why Avast did not find it
NO security program have 100% detection or zero false positives

the malware world is not static, bad guys constantly update, modify, create new versions to avoid detection

This what AV vendors try to block/detect evry day  https://www.av-test.org/en/statistics/malware/


Quote
One of my users got his PC infected with a ransomware that encrypted his files and ask for 0.5BTC (keybtc@inbox.com)
We can assist in removing it here if you want, but the files are gone ... unless you pay

« Last Edit: January 21, 2016, 05:00:57 PM by Pondus »

REDACTED

  • Guest
Re: Avast cannot detect KeyBTC ransomware
« Reply #2 on: January 21, 2016, 05:00:49 PM »
I am puzzled right now, Malwarebytes, Spyhunter cannot them it as well ...

Is it possible the script erases itself after encrypting the files ?

Thanks

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37582
  • Not a avast user
Re: Avast cannot detect KeyBTC ransomware
« Reply #3 on: January 21, 2016, 05:02:16 PM »
Quote
Is it possible the script erases itself after encrypting the files ?
That is possible, there are malware that does that, or it is a very new version that few detect

do you want help removing it?


REDACTED

  • Guest
Re: Avast cannot detect KeyBTC ransomware
« Reply #4 on: January 21, 2016, 05:03:53 PM »
I found the originating script file ... can I send it to avast for inspection ?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37582
  • Not a avast user
Re: Avast cannot detect KeyBTC ransomware
« Reply #5 on: January 21, 2016, 05:07:50 PM »
I found the originating script file ... can I send it to avast for inspection ?
yes, try here   https://support.avast.com/support/tickets/new?form=3

you may also upload the file to  www.virustotal.com  and test it, if scanned before, click rescan for a fresh result
Post link to scan result here



Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37582
  • Not a avast user
Re: Avast cannot detect KeyBTC ransomware
« Reply #7 on: January 21, 2016, 05:12:39 PM »
seems to be very new  First submission 2016-01-21 16:08:36 UTC ( 2 minutes ago )

and it is a java script, so Malwarebytes will never detect it as it dont target script files

« Last Edit: January 21, 2016, 05:16:46 PM by Pondus »