Author Topic: USB worm  (Read 3532 times)

0 Members and 2 Guests are viewing this topic.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
USB worm
« on: February 16, 2017, 04:51:41 PM »
First submission 2016-12-26 07:54:27 UTC ( 1 month, 3 weeks ago )
https://virustotal.com/en/file/fb65c2425069a2584590acf67878f5591d40e47834694276423d4e6baff9d002/analysis/1487259934/

Must have slipped true the labs auto analyse, no avast / AVG detection  ...  good we have MCShield    ;)





Offline TrueIndian

  • Poster
  • *
  • Posts: 433
Re: USB worm
« Reply #1 on: February 16, 2017, 05:21:56 PM »
This is a downloader...probably downloads ransom.Yet again it proves avast's cybercapture and deepscreen not monitoring these .js and .vbs extensions is a flaw.

REDACTED

  • Guest
Re: USB worm
« Reply #2 on: February 17, 2017, 04:29:58 AM »
should be repaired anymore antivirus avast again to investigate the problem ransomware  ;)

REDACTED

  • Guest
Re: USB worm
« Reply #3 on: February 17, 2017, 04:56:14 AM »
dont worry , behavior protection still activated  ;)

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: USB worm
« Reply #4 on: February 17, 2017, 08:55:51 AM »
I will create a gen detection for the file, too ;)

Offline Lord_Ami

  • Sr. Member
  • ****
  • Posts: 227
Re: USB worm
« Reply #5 on: February 17, 2017, 01:38:44 PM »
First submission 2016-12-26 07:54:27 UTC ( 1 month, 3 weeks ago )
https://virustotal.com/en/file/fb65c2425069a2584590acf67878f5591d40e47834694276423d4e6baff9d002/analysis/1487259934/

Must have slipped true the labs auto analyse, no avast / AVG detection  ...  good we have MCShield    ;)

This VBS script probably has download link that is long gone/terminated.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: USB worm
« Reply #6 on: February 17, 2017, 03:32:10 PM »

REDACTED

  • Guest
Re: USB worm
« Reply #7 on: February 17, 2017, 06:09:34 PM »
I will create a gen detection for the file, too ;)

hi , i found the problem delete sample in the virus chest . (that sample block by IDP)
suppose delete instantly ,did u fix soon ?
« Last Edit: February 17, 2017, 06:12:33 PM by ymchen »

Offline TrueIndian

  • Poster
  • *
  • Posts: 433
Re: USB worm
« Reply #8 on: February 17, 2017, 06:13:44 PM »
I will create a gen detection for the file, too ;)

hi , i found the problem delete sample in the virus chest . (that sample block by IDP)
suppose delete instantly ,did u fix soon ?

You mean the sample is not detected if deleted from virus chest? Can you attach screenshot and explain what you mean?

REDACTED

  • Guest
Re: USB worm
« Reply #9 on: February 17, 2017, 06:18:14 PM »
I will create a gen detection for the file, too ;)

hi , i found the problem delete sample in the virus chest . (that sample block by IDP)
suppose delete instantly ,did u fix soon ?

You mean the sample is not detected if deleted from virus chest? Can you attach screenshot and explain what you mean?

i means a sample blocked by IDP , and u go check in the chest , try delete that sample , it take a few minute delete sample.