Author Topic: Antivirus 2009 Variant?  (Read 5708 times)

0 Members and 1 Guest are viewing this topic.

Offline havildar

  • Full Member
  • ***
  • Posts: 125
Antivirus 2009 Variant?
« on: October 04, 2008, 11:56:29 PM »
Just a heads-up, really, and a request to know if Avast! is aware of something called the
A9installer which seems to have some connection with Antivirus 2009?

There seems to be some confirmation on theses sites:

http://www.virustotal.com/analisis/0cb18fdb5331eea0e56b70e8c352b942

http://malwaredatabase.net/blog/index.php/2008/10/01/antivirus-2009-3-domains-added-8-files-added-0of36/
Windows XP Sp3 Home desktop, Windows 10 Pro laptop, Avast 17.8.2318 Free , Malwarebytes Anti-malware (free), SpywareBlaster. SuperAntispyware, WOT. Firefox Quantum.

Offline Soure73

  • Full Member
  • ***
  • Posts: 137
Re: Antivirus 2009 Variant?
« Reply #1 on: October 05, 2008, 12:36:31 AM »
 It seems that Avast doesn't detects this, if you have a sample send it to Alwil team!
HP Compaq with Amd AthlonII x2 2.7Ghz,4 Gig ram 1066 Mhz DDR3,ATI Radeon HD 3000(onboard),Windows 10 Home 64bit

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89051
  • No support PMs thanks
Re: Antivirus 2009 Variant?
« Reply #2 on: October 05, 2008, 12:55:32 AM »
The signatures are a couple of days out of date on VT, but you should still send the sample to avast.

Send the sample to virus@avast.com zipped and password protected with the password in email body, a link to this topic might help and undetected malware in the subject.

Or you can also add the file to the User Files (File, Add) section of the avast chest (if it isn't already there) where it can do no harm and send it from there (select the file, right click, email to Alwil Software). No need to zip and PW protect when the sample is sent from chest. A copy of the file/s will remain in the original location, so any further action you take can remove that.

avast does detect some of these variants as win32.fraudo and also possibly as win32.trojan-gen.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

timcan

  • Guest
Re: Antivirus 2009 Variant?
« Reply #3 on: October 05, 2008, 01:25:11 AM »
Avast web scanner does not detect this. Sorry, didn't get a sample of the file to send. My hips program running in locked mode won't let me download it.  ;)  I can't believe people click on this crap.

Offline havildar

  • Full Member
  • ***
  • Posts: 125
Re: Antivirus 2009 Variant?
« Reply #4 on: October 05, 2008, 12:27:55 PM »
Thanks for your replies.

I am unable to send a sample to Avast! since my system is not infected with it. The information came from a friend (not an Avast! user despite my best efforts), who uses MySpace and clicked on a link to an outfit called *privateonlinescanner*, which I`ve never heard of before but perhaps someone else has?

Best regards.
Windows XP Sp3 Home desktop, Windows 10 Pro laptop, Avast 17.8.2318 Free , Malwarebytes Anti-malware (free), SpywareBlaster. SuperAntispyware, WOT. Firefox Quantum.

Offline Maxx_original

  • Avast team
  • Super Poster
  • *
  • Posts: 1479
Re: Antivirus 2009 Variant?
« Reply #5 on: October 05, 2008, 02:36:25 PM »
the virustotal scan is from february 2008, that's quite old... i believe this file is detected already as Win32:Fraudo, but wasn't rescanned.. we can match the hash against our internal set of samples..

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89051
  • No support PMs thanks
Re: Antivirus 2009 Variant?
« Reply #6 on: October 05, 2008, 03:24:07 PM »
The scan isn't from February but this month unfortunately they are using the US Date notation of Month/Day/Year in the Header information.

Quote
File A9installer_880221.exe received on 10.02.2008 15:09:58 (CET)

If you look at the scanner info, as in the date of the signature files this is reported in the Day/Month/Year notation.

Quote
AhnLab-V3    2008.10.2.0    2008.10.02    -
AntiVir    7.8.1.34    2008.10.02    -
Authentium    5.1.0.4    2008.10.02    -
Avast    4.8.1248.0    2008.10.02    -
AVG    8.0.0.161    2008.10.02    -
BitDefender    7.2    2008.10.02    -
CAT-QuickHeal    9.50    2008.10.01    -
ClamAV    0.93.1    2008.10.02    -
DrWeb    4.44.0.09170    2008.10.02    -
eSafe    7.0.17.0    2008.10.01    -
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline havildar

  • Full Member
  • ***
  • Posts: 125
Re: Antivirus 2009 Variant?
« Reply #7 on: October 05, 2008, 06:01:32 PM »
Maxx, David,

Thanks for your responses.

This month/day/year notation is certainly the cause of some confusion. I does seem to be an odd way to write the date but perhaps that`s just because I`m not used to it.

I can confirm, though, that this A9installer thing I referred to earlier dates from Thursday or Friday of last week when the incident happened; an ill-advised click on a pop-up I`m told, which resulted in the fake anti-virus being installed.

Since Avast was not installed on the machine at the time the question of whether or not it would have stopped the malware did not arise.

Needless to say, it is now.
Windows XP Sp3 Home desktop, Windows 10 Pro laptop, Avast 17.8.2318 Free , Malwarebytes Anti-malware (free), SpywareBlaster. SuperAntispyware, WOT. Firefox Quantum.

Spiritsongs

  • Guest
Re: Antivirus 2009 Variant?
« Reply #8 on: October 05, 2008, 09:43:05 PM »
 :)  Hi all :

 The most complete Info about this "Rogue" program I know is at

 www.bleepingcomputer.com/malware-removal/uninstall-antivirus-2009 .