Author Topic: potential malware not detected!!!  (Read 11902 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33925
  • malware fighter
Re: potential malware not detected!!!
« Reply #15 on: October 19, 2009, 08:11:30 PM »
Hi harman123,

Mal/Emogen-P is a malicious program for the Windows platform. This malcode bugger registers itself as a system service and collects certain essential information from the system. It is also a keylogger. What this means is that it runs continually and watches keystrokes and anything else that it finds useful and uses it for the creators devious purposes.

Detection for members of Mal/Emogen-P malware is behavior based. It is extremely important that users report detections of Mal/Emogen-P to avast and send a sample for analysis.

Now also read this here: http://www.pc1news.com/news/1003/remove-the-svchust-exe-file.html

Another variant: http://www.threatexpert.com/report.aspx?md5=f0b2de1086f03079f463b6b2254f3d03

and this: https://www.microsoft.com/Security/portal/Threat/Encyclopedia/Entry.aspx?Name=Worm:Win32/Lashplay.gen!A&ThreatID=-2147362362

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline harman123

  • Sr. Member
  • ****
  • Posts: 299
Re: potential malware not detected!!!
« Reply #16 on: October 19, 2009, 09:24:35 PM »
I'd already sent the sample to alwil and microsoft but they took forever to add these samples.
maybe I'm a little pushy but I want to help out as much as I can.

There is another site which most Chinese users know as hxxp://download.tech.qq.com/
in this site there are several potential unwanted programs and adware/spyware disguise programs.
« Last Edit: October 19, 2009, 09:47:09 PM by harman123 »

eplose

  • Guest
Re: potential malware not detected!!!
« Reply #17 on: October 19, 2009, 11:26:56 PM »
lol  ;D

well I've tried thier product support Live chat... you have to read this:

 Welcome to our site ! How can I be of assistance today?

you: hey...my antivirus software blocks my installation

Sam: Sorry for the inconvenience,

Sam: Can you please let me know, which company/software you are looking for?

you: what do you mean?

you: don't you serve one company only?

Sam: Yes we do

Sam: Our product name is AntiVirus Professional. Did you purchase our software (AntiVirus Professional)?

you: no. I am speaking about adware professional

Sam: I am transferring you to Adware Professional support guy. just a moment please.

Please wait while you're being switched (transferred) to 'Nicholas'.

You are now chatting with 'Nicholas'

Nicholas: Hello,

Nicholas: How can I help you?

you: hello... tried installing the software, but my AV detected it as malware

Nicholas: Can you kindly let me know the name and email address you used when ordering our software?

you: didnt order it, just downloaded it for trialing it.

Nicholas: ok.

Nicholas: Adware Professional is not a scam, is not a virus, and is in no way harmful to your PC.

Nicholas:

Nicholas: We have an excellent product that we stand behind 100%, and it's backed by our excellent support team that is here and happy to assist you with any troubles you might experience.

Nicholas: Our site obviously has nothing to do with the infection on your computer.

Nicholas: We sell an anti-spyware product, we don't infect people with anything, nor do we advertise our product using anything like you mentioned .Our site is heavily involved in anti-spyware legislation, and is one of the most widely used anti-spyware products on the market today.

Nicholas: So, please be not worried about the issue you concern just go ahead and install our software.

Nicholas: The free version of Adware Professional is for the free PC scan and is available at :

Nicholas: hxxp://www.adwareprofessional.com/download.html

Nicholas: But, Only scanning of your system is for free. To remove infected items, you have to purchase our product.

Nicholas:

Nicholas: We offer a free scan to show customers what we are able to detect and remove, and then should the customer wish, they can purchase our software.

Nicholas: To purchase our product, can you kindly try at:

Nicholas: hxxp://www.adwareprofessional.com/purchase

Nicholas: (It is available here for a sum of $27.00which is a yearly subscription amount with a 60 Days Money Back Guarantee).

you: hmm...so what should i do with my AntiVirus?

Nicholas: Please disable it first

Nicholas: After that try to download our software.

Nicholas: Using the above given links

you: obviously it won't work with your software...the moment i'll activate it, the files will be deleted.

you: can't you solve this problem with the antivirus company?

Nicholas: Several companies have raised issues with the fact that (*the name of the product i mentioned*) will, in many cases, identify legitimate programs as malicious purely as an anti-competitive measure. We are in the process of working with (*the name of the product i mentioned*)  to have this error repaired on their end.

Nicholas: So, please be not worried about the issue  you concern.

you: ok. thank you.

Nicholas: Thank you very much for chatting with us today. We hope the rest of your day is an excellent one.

Nicholas: Please Feel free to come back, for any further assistance !

 Wot a scam ::)

I simply don't get it. They have opened a support center for a fake software? wow, they are getting smarter and smarter. They almost convinced me.
« Last Edit: October 19, 2009, 11:35:36 PM by eplose »

Offline harman123

  • Sr. Member
  • ****
  • Posts: 299
Re: potential malware not detected!!!
« Reply #18 on: October 19, 2009, 11:36:16 PM »


If you search avast or avg on google, on top of google sponsor , it say avast antivirus, but when you click on it, it link their site selling their product and trick user installing it.

hxxp://www.adwareprofessional.com

http://www.virustotal.com/analisis/1b27b8c81e763d1eeb61a8ed054575a476f4688b9c3907283492786d1af2fc89-1255988320

http://virusscan.jotti.org/en/scanresult/1c80f8cdcb500c2d877040e1050a77940799e9aa
« Last Edit: October 19, 2009, 11:49:40 PM by harman123 »

Offline harman123

  • Sr. Member
  • ****
  • Posts: 299
Re: potential malware not detected!!!
« Reply #19 on: October 21, 2009, 03:19:46 AM »
finally
adware professional is detect by avast  ;D

but baidu sobar not detected by avast

baidu toolbar are found in hxxp://bar.baidu.com/sobar/promotion.html

http://www.virustotal.com/analisis/49407fa162c65df6eefa36a8e89c45b16945ea84463e78842c02306e34315426-1256087904  :'(

« Last Edit: October 21, 2009, 03:21:21 AM by harman123 »

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2294
Re: potential malware not detected!!!
« Reply #20 on: October 21, 2009, 03:41:58 PM »
finally
adware professional is detect by avast  ;D

but baidu sobar not detected by avast

baidu toolbar are found in hxxp://bar.baidu.com/sobar/promotion.html

http://www.virustotal.com/analisis/49407fa162c65df6eefa36a8e89c45b16945ea84463e78842c02306e34315426-1256087904  :'(



Hi,
thanks for feedback, but baidu sobar don't seems to be bad.

Milos

Offline harman123

  • Sr. Member
  • ****
  • Posts: 299
« Last Edit: October 21, 2009, 04:31:12 PM by harman123 »

Offline harman123

  • Sr. Member
  • ****
  • Posts: 299
Re: potential malware not detected!!!
« Reply #22 on: October 21, 2009, 04:38:31 PM »
avast! Professional Edition Failed to block the following Rogue Software samples:
Computer Defender 2009, Error Wiz, Optimizer Easy, Windows Antivirus Pro, PC Doc Pro, PC On Point, Perfect Optimizer, Registry Fix Program, Adware Spyware Remover, Registry Repair, Advanced Audio CD Burner, Advanced Audio DJ Mixer, Advanced Audio CD Ripper,Advanced Video Editing, Advanced Audio Extractor, Clean N' Optimize, Audio Converter Extractor Mix, Software Depo DVD Player, Software Depo DVD Ripper, FTP and Download helper,Software Depo FLV Player, Advanced Icon Editor, Software Depo iPodManager, Advanced Image Viewer, Advanced MP3-WAV Converter, Free Internet Speedd Up Lite, Advanced Net Speed Up, Advanced DVD Rip and Burn, SWD Spy Message, Advanced System TuneUp, Video Converter Max, Advanced Video Editor, MySpace.com Video Grabber, Video Cutter Max, Reg Genie, Reg Tool, Antivirus Pro, Windows Security Suite, Error Fix, Antispyware 2009, Adware Alert, Spyware STOP, SPYware REMOVER, Malware Removal Bot, Registry Smart, Antispyware Bot, Macro Virus.

above is from malware research group rogue test and avast did not detected above samples :o

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2294
Re: potential malware not detected!!!
« Reply #23 on: October 21, 2009, 05:06:21 PM »
Hi,
send us the samples (virus@avast.com) or link to download whole archive, please.

Thanks,
Milos

caseyv

  • Guest
Re: potential malware not detected!!!
« Reply #24 on: October 21, 2009, 08:14:35 PM »
Avast 5.0.167 detects this as Win32:Trojan-gen ;D

How were you able to get Avast 5.0.167?  Am I missing it somewhere?  Because 4.8 is starting to miss a lot of viruses.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89164
  • No support PMs thanks
Re: potential malware not detected!!!
« Reply #25 on: October 21, 2009, 08:58:40 PM »
It is a beta build of the new avast version 5.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline harman123

  • Sr. Member
  • ****
  • Posts: 299
Re: potential malware not detected!!!
« Reply #26 on: October 21, 2009, 09:34:08 PM »
rogue-ware:

hxxp://www.pcdocpro.com

hxxp://www.pconpoint.com/

hxxp://www.perfectoptimizer.com/

hxxp://www.registryfix.com/

Advanced Audio CD Burner ->multiple source google it

Advanced Audio DJ Mixer ->multiple source google it

Advanced Audio CD Ripper ->multiple source

hxxp://www.softwaredepo.com/v-editing.html

hxxp://www.softwaredepo.com/audio_extractor.html

Clean N' Optimize ->multiple source on google

Audio Converter Extractor Mix ->multiple source on google

hxxp://www.softwaredepo.com/

Advanced Icon Editor ->multiple source on google

hxxp://www.creabit.com/viewer/

hxxp://www.softwaredepo.com/mp3.html

Free Internet Speed Up Lite->multiple source on google

Advanced Net Speed Up->multiple source on google

Advanced DVD Rip and Burn->multiple source on google

SWD Spy Message->multiple source on google

Advanced System TuneUp->multiple source on google

Video Converter Max->multiple source on google

Advanced Video Editor->multiple source on google

hxxp://www.softwaredepo.com/v-grabber.html

Video Cutter Max->multiple source on google

hxxp://www.reggenie.com/

hxxp://www.regtool.com/

hxxp://www.errorfix.com/download_now.php

hxxp://www.adwarealert.com/

hxxp://spywarestop.com/

hxxp://www.malwareremovalbot.com/

hxxp://registrysmart.com/

hxxp://www.antispywarebot.com/

hxxp://www.trackzapper.com/spyware.html

wow long list so happy hunting  ;)

Offline Yanto.Chiang

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1371
  • Soli Deo Gloria
    • PT Garuda Sinatriya Globalindo
Re: potential malware not detected!!!
« Reply #27 on: October 22, 2009, 09:15:22 AM »
Hi Harman,

I don't think all of them was infected by malware, sometimes ecah antivirus vendor would detected another antivirus vendor as malware.
To sure you could check with Unmaskparasites and Norton Safe Web

It could be a false positive..

Regards,
Yanto Chiang
Yanto Chiang | IT Security Consultants | AVAST Premium Security | GarudaSinatriya

Offline harman123

  • Sr. Member
  • ****
  • Posts: 299
Re: potential malware not detected!!!
« Reply #28 on: October 22, 2009, 06:33:12 PM »
hxxp://www.pcdocpro.com

hxxp://www.pconpoint.com/

hxxp://www.perfectoptimizer.com/

hxxp://www.registryfix.com/

hxxp://www.softwaredepo.com/------------------->multiple programs within this site contain adware and keylogger

hxxp://www.reggenie.com/

hxxp://www.regtool.com/

hxxp://www.errorfix.com/download_now.php

hxxp://www.adwarealert.com/

hxxp://spywarestop.com/

hxxp://www.malwareremovalbot.com/

hxxp://registrysmart.com/

hxxp://www.antispywarebot.com/

Offline harman123

  • Sr. Member
  • ****
  • Posts: 299
Re: potential malware not detected!!!
« Reply #29 on: October 24, 2009, 04:16:34 AM »
hxxp://www.antispywarebot.com/

avast detected as trojan-gen  ;D

the rests still not detected  :'(
« Last Edit: October 24, 2009, 04:19:34 AM by harman123 »