Author Topic: unknown virus  (Read 2595 times)

0 Members and 1 Guest are viewing this topic.

waleed101

  • Guest
unknown virus
« on: May 22, 2009, 03:01:29 PM »
I found virus in my PC but avast didn't catch it I put the file in virus chest and email it but avast still didn't look at it as virus
I scaned the file in virustotal site and this is the report:
Antivirus    Version    Last Update    Result
a-squared    4.0.0.101    2009.05.19    Packed.Win32.Klone!IK
AhnLab-V3    5.0.0.2    2009.05.19    -
AntiVir    7.9.0.168    2009.05.19    SPR/AutoIt.Gen
Antiy-AVL    2.0.3.1    2009.05.19    -
Authentium    5.1.2.4    2009.05.19    W32/AutoIt.D.gen!Eldorado
Avast    4.8.1335.0    2009.05.18    -
AVG    8.5.0.336    2009.05.19    -
BitDefender    7.2    2009.05.19    Gen:Trojan.Heur.AutoIT.3374150505
CAT-QuickHeal    10.00    2009.05.19    -
ClamAV    0.94.1    2009.05.19    Trojan.Autoit-72
Comodo    1157    2009.05.08    -
DrWeb    5.0.0.12182    2009.05.19    -
eSafe    7.0.17.0    2009.05.19    Suspicious File
eTrust-Vet    31.6.6511    2009.05.19    -
F-Prot    4.4.4.56    2009.05.18    W32/AutoIt.D.gen!Eldorado
F-Secure    8.0.14470.0    2009.05.19    Packed.Win32.Klone.bj
Fortinet    3.117.0.0    2009.05.19    -
GData    19    2009.05.19    Gen:Trojan.Heur.AutoIT.3374150505
Ikarus    T3.1.1.49.0    2009.05.19    Packed.Win32.Klone
K7AntiVirus    7.10.739    2009.05.19    Virus.Win32.Sality.AA
Kaspersky    7.0.0.125    2009.05.19    Packed.Win32.Klone.bj
McAfee    5619    2009.05.18    W32/Autorun.worm.zf.gen
McAfee+Artemis    5619    2009.05.18    W32/Autorun.worm.zf.gen
McAfee-GW-Edition    6.7.6    2009.05.19    Riskware.AutoIt.Gen
Microsoft    1.4602    2009.05.19    Worm:AutoIt/Renocide.gen!A
NOD32    4087    2009.05.19    Win32/Packed.Autoit.Gen
Norman    6.01.05    2009.05.18    -
nProtect    2009.1.8.0    2009.05.19    -
Panda    10.0.0.14    2009.05.18    -
PCTools    4.4.2.0    2009.05.18    -
Prevx    3.0    2009.05.19    High Risk Cloaked Malware
Rising    21.30.14.00    2009.05.19    -
Sophos    4.41.0    2009.05.19    -
Sunbelt    3.2.1858.2    2009.05.18    -
Symantec    1.4.4.12    2009.05.19    W32.Harakit
TheHacker    6.3.4.1.327    2009.05.19    -
TrendMicro    8.950.0.1092    2009.05.19    -
VBA32    3.12.10.5    2009.05.19    Trojan.Autoit.FINT
ViRobot    2009.5.19.1740    2009.05.19    -
VirusBuster    4.6.5.0    2009.05.19    -
Additional information
File size: 616251 bytes
MD5   : 1b5083873432ce629244801a59f5fc3b
SHA1  : 265cfcb8238070a7a95bc54571b7bcfc3dc5dc9b
SHA256: 8d5ba610dad2d60901117e81a4698a5950889972260e9fe5e2bb5ccee2d07f5d
TrID  : File type identification
RAR Archive (83.3%)
REALbasic Project (16.6%)
ssdeep: 12288:hmXfQSajBmLd1wy1+pDMte27JIaiyzxil+UKE+vgTjiokMTYYsqWUPUcCR8JdCZp:MXfZajompwHNzxrUKE+OzHTYVVACmJdu
PEiD  : -
packers (Kaspersky): PE_Patch.UPX, UPX
packers (F-Prot): UPX
packers (Authentium): UPX
RDS   : NSRL Reference Data Set

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: unknown virus
« Reply #1 on: May 22, 2009, 03:53:59 PM »
Yeah, a lack of detection.
Can you send it for analysis?
Right click it within Chest and send it to Alwil for analysis (email to Alwil Software).
It will be uploaded (not actually emailed) to avast when the next avast auto (or manual) update is done.
The best things in life are free.

waleed101

  • Guest
Re: unknown virus
« Reply #2 on: May 22, 2009, 04:04:49 PM »
I did this yesterday and after the update today avast did not catch it