Author Topic: Report a malicious files  (Read 2598 times)

0 Members and 2 Guests are viewing this topic.

Offline 魯芷涵

  • Newbie
  • *
  • Posts: 3
Report a malicious files
« on: April 22, 2021, 08:17:53 AM »
Dear Sir/Madam:

My English is not good,but I will try to describe
the situation in English I encountered in as much detail
as possible(I'm a Taiwanese).

I have run a virus scan (with Avast premium trail) on the software before installing it.
Nothing unusual.
I saw some tick boxes with garbled message during the installation.
About 2 minutes after installation, an unknown software shortcut
 appears on the desktop,probably a rogue software download in the background.

I then checked the system logs and found that the following
 software had been installed on my computer without permission:

元气壁纸服务 kdeskcore.exe
元气桌面动态壁纸 kwallpaper.exe
元气桌面锁屏 keyemain.exe
元气桌面整理 kdesk64.exe
万能输入法 setup_wnpykb001.exe

I was also forced to install Kingsoft Antivirus, but for unknown reason
the rogue software didn't install Kingsoft Antivius when I was screen recording.
The lock screen of Windows 10 is also bundled, forcing you to add a program that covers the full screen.
These were very difficult to remove and were finally removed using revo uninstaller.

After a second test on my virtual machine (I always reset the virtual machine with snapshots and
all anti-virus software set to maximum sensitivity before testing)

Trand marco,ESET,bitdefender, Avria
These anti-viruses cannot be scanned for viruses before installation,
 but rogue background installations are successfully blocked.

Kaspersky and Avast only detect part of the rogue software execution and do not completely
 block the background installation of the rogue software.

I have posted the full process of my test on Youtube
 at the following link:

(Software used during testing:Windows 10 64bit 20H2 Traditional Chinese, VMWare Workstation Pro 15)

KIS:https://youtu.be/HieXbbzUWZw
Avria Free:https://youtu.be/9YART6QygRE
ESET:https://youtu.be/c_mtWASGTIQ
bitdefender:https://youtu.be/igGfoImkD60
Avast preminum:https://youtu.be/jQc2D_IP90I
Trand marco:https://youtu.be/wwPINejM7ic

All Antivirus scan logs here(password:infected)
htxps://drive.google.com/drive/folders/13TJlfzBXwdci5s49Nm3Mz3pyn7Jx9_kJ?usp=sharing

Infected files here
htxps://drive.google.com/drive/folders/1BU2_YfS0AwYeM3L4It-klVfFKvOuhDHE?usp=sharing

Intected website:
htxp://www.pcgeshi.com/
« Last Edit: April 22, 2021, 12:24:37 PM by Milos »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Report a malicious files
« Reply #1 on: April 22, 2021, 10:46:21 AM »
Quote
Intected website:
hxxp://wxw.pcgeshi.com/

programfile from that location
https://www.virustotal.com/gui/file/fc6fa496dbd6430131d04b4c851705711e93e9dbc79e4342b983c556b5860cb1/detection



Offline 魯芷涵

  • Newbie
  • *
  • Posts: 3
Re: Report a malicious files
« Reply #2 on: April 23, 2021, 03:50:13 AM »
But I have tested this virus on a VMware workstation, Avast failed to block the rouge software on this website, which forces the installation of suspicious software in background.

Offline 魯芷涵

  • Newbie
  • *
  • Posts: 3
Re: Report a malicious files
« Reply #3 on: April 23, 2021, 04:07:44 AM »
Instead, Avria Free, Trend Marco, ESET,bitdefender successfully blockedthe background downloads of malicious program.
No offence but is the content of your suggested website out of date?
I have also reported this virus to Kaspersky Lab in Taiwan, and in response, Kaspersky has now blocked this software backgrounds download.
(Detailed test procedure on YouTube)
« Last Edit: April 23, 2021, 04:12:53 AM by 魯芷涵 »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Report a malicious files
« Reply #4 on: April 23, 2021, 08:36:48 AM »
You can report a suspicious/malicious sample (File/Website) here: https://www.avast.com/report-malicious-file.php
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Report a malicious files
« Reply #5 on: April 23, 2021, 09:50:10 AM »
It is detected as PUP type
Note that avast PUP detection is default off