Author Topic: A-Squared Found TWO Trojans That AVAST! Missed  (Read 5330 times)

0 Members and 1 Guest are viewing this topic.

Ickyma

  • Guest
A-Squared Found TWO Trojans That AVAST! Missed
« on: March 25, 2010, 03:14:39 PM »
I have AVAST! on my computers and it runs every morning at 2:00am...  It updates all the time so it has the most current definitions, etc...

It has come up clean every time...  but my computer was still running very slowly and acting strangely...

So, I went back to an old program I like to use called  A-SQUARED by Emsi Soft...  I think it's a pretty good program.

I updated it's definitions and ran a scan....   VOILA!    It found TWO Trojans that AVAST! Missed

Trojan.Win32.Patcher.fl!A2
-  c:\WINDOWS\$NtServicePackUninstall$\ntkrnlmp.exe.ooo


and

Trojan.Win32.Genome.gofh!A2
-  c:\WINDOWS\System32\dllcache\find.exe
-  c:\WINDOWS\System32\find.exe


Wonder why AVAST! didn't pick up on these?

Haven't tried to remove them yet... (Scan isn't quite finished) ...  I'll let you know how that goes as soon as I can.



Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11856
    • AVAST Software
Re: A-Squared Found TWO Trojans That AVAST! Missed
« Reply #1 on: March 25, 2010, 03:16:05 PM »
Most likely because they're all false positives?

Ickyma

  • Guest
Re: A-Squared Found TWO Trojans That AVAST! Missed
« Reply #2 on: March 25, 2010, 03:19:04 PM »
Found this comment from somebody who had Genome:
Quote
ESO  March 3rd, 2010 at 11:02 pm  2

I’m not sure why it’s labeled “LOW RISK” – when I quarantined this last night it took important drivers with it, and crashed my machine.

Mine is labeled "HIGH RISK" ... wonder if I should quarantine or remove it when the time comes?  ???

Altarir.

  • Guest
Re: A-Squared Found TWO Trojans That AVAST! Missed
« Reply #3 on: March 25, 2010, 03:31:57 PM »
Found this comment from somebody who had Genome:
Quote
ESO  March 3rd, 2010 at 11:02 pm  2

I’m not sure why it’s labeled “LOW RISK” – when I quarantined this last night it took important drivers with it, and crashed my machine.

Which means that "trojans" most likely were legimate system files without which drivers failed to work.

Check files a-squared detects as trojans at virustotal.com
« Last Edit: March 25, 2010, 03:33:31 PM by Altarir. »

Ickyma

  • Guest
Re: A-Squared Found TWO Trojans That AVAST! Missed
« Reply #4 on: March 25, 2010, 03:54:42 PM »
Cool.  Thanks... I'll try that.

Incidentally, I was able to quarantine them without any trouble...  :-\


Ickyma

  • Guest
Re: A-Squared Found TWO Trojans That AVAST! Missed
« Reply #5 on: March 25, 2010, 03:57:45 PM »
Found this comment from somebody who had Genome:
Quote
ESO  March 3rd, 2010 at 11:02 pm  2

I’m not sure why it’s labeled “LOW RISK” – when I quarantined this last night it took important drivers with it, and crashed my machine.

Which means that "trojans" most likely were legimate system files without which drivers failed to work.

Check files a-squared detects as trojans at virustotal.com
I went to VirusTotal and ran it through.... Do you want me to post what it says?  (There's a BUNCH of stuff.)

Ickyma

  • Guest
Re: A-Squared Found TWO Trojans That AVAST! Missed
« Reply #6 on: March 25, 2010, 04:01:16 PM »
This is the first thing I see...
Quote
File has already been analysed:
MD5:    626309040459c3915997ef98ec1c8d40
First received:    2009.05.22 20:37:29 UTC
Date:    2010.02.24 19:34:40 UTC [>28D]
Results:    0/41
Permalink:    analisis/f5227376ec2b6a4fc3b4a01ee2bc6b9fd01b1cabf5f2cd6dc68d2f8ec5d3f7c5-1267040080
I click on the permalink and this is the first thing I see...
Quote
File ntoskrnl.exe received on 2010.02.24 19:34:40 (UTC)
Current status: finished
Result: 0/41 (0.00%)



Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89210
  • No support PMs thanks
Re: A-Squared Found TWO Trojans That AVAST! Missed
« Reply #7 on: March 25, 2010, 04:10:11 PM »
When you are presented with the "this file has been scanned before," or words to that effect always have VT rescan it as that permalink shows the last scan was over a month ago, which is a very long time in virus terms. However since it has the same MD5 as the one you uploaded, 0/41 is a pretty clear indication of a false positive by a-squared.

Just post the link (URL) to the virustotal results page, the one that appears in the browser address bar.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security


Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89210
  • No support PMs thanks
Re: A-Squared Found TWO Trojans That AVAST! Missed
« Reply #9 on: March 25, 2010, 04:46:41 PM »
Yes, a big fat false positive by a-squared (on your system) but strangely (well not so strange) it isn't detected by a-squared on that set of results. Here is why, as I said it is an old submission "File ntoskrnl.exe received on 2010.02.24" and you really should have had VT scan the file again.

This looks like a-squared have updated their virus database and now detect that file as infected (still I believe an FP if no other scanners detect anything), a-squared does have a lot of false positives.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security