Author Topic: Undetected Malware  (Read 4400 times)

0 Members and 1 Guest are viewing this topic.

Offline matshekad

  • Newbie
  • *
  • Posts: 2
Undetected Malware
« on: February 02, 2016, 04:40:21 PM »
Hi there

I'm part of an enterprise support team and

I've detected a malware that  major Anti-Virus solution(AVG, VAST, Mcafee, etc) cant pick-up at all. Its packaged as "part" of the malware that normally causes shortcuts on flash disks. Malwarebytes was the only one that detected it though I had to manually remove it from the system..I've been tracking and observing it since last year and the only viable solution for me was to manually remove it, only to come and remove it again if a user were to insert an infected flash

This is what I know of it now

1 Its in the Program Data
2 It modifies the Load string in the registry
3 On almost every PC it has a different name(msgzvju, msddr.exe, mszdzn.exe, msburzi.exe, etc)
5..... :( AVAST END POINT cant detect it at all

The issue is beyond the work place and now I see it almost everywere

Me, Being Thankful



Offline Asyn

  • Avast √úberevangelist
  • Certainly Bot
  • *****
  • Posts: 62473
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Undetected Malware
« Reply #1 on: February 03, 2016, 05:59:28 AM »
You can report suspected malware here: https://support.avast.com/support/tickets/new?form=3
W8.1 [x64] - Avast PremSec 19.9.2394.B1 [UI.441] - CC 5.63 - EEK - Firefox ESR 68.4.2 [NS/AOS/uBO/PB] - Thunderbird 68.4.1 - ASL.B
Deutschsprachiger Bereich -> Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline matshekad

  • Newbie
  • *
  • Posts: 2
Re: Undetected Malware
« Reply #2 on: February 03, 2016, 09:32:45 AM »
Thanks a lot...I've done so

Offline Asyn

  • Avast √úberevangelist
  • Certainly Bot
  • *****
  • Posts: 62473
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Undetected Malware
« Reply #3 on: February 03, 2016, 09:35:23 AM »
You're welcome.
W8.1 [x64] - Avast PremSec 19.9.2394.B1 [UI.441] - CC 5.63 - EEK - Firefox ESR 68.4.2 [NS/AOS/uBO/PB] - Thunderbird 68.4.1 - ASL.B
Deutschsprachiger Bereich -> Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2114
Re: Undetected Malware
« Reply #4 on: February 03, 2016, 12:17:53 PM »
Hello,
thanks, for the ticket. We will need some samples to analyze. As I see they are quite large -- 81 MB, pack them to archive and upload them to our ftp://ftp.avast.com/incoming/ and let us know the uploaded filename.

Milos