Author Topic: Does avast detect variant of Win32/Rozena.AH ?SOLVED  (Read 2247 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Does avast detect variant of Win32/Rozena.AH ?SOLVED
« on: March 09, 2011, 06:46:51 PM »
See online binary analyzer: http://www.xandora.net/xangui/malware/view/bafbc776af8e2534c81248e7cad58126

should be detected as Win32:Dropper-gen [Drp] by avast, is detected as Win32:Malware-gen, so SOLVED

polonus



« Last Edit: March 09, 2011, 07:01:09 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37582
  • Not a avast user
Re: Does avast detect variant of Win32/Rozena.AH ?
« Reply #1 on: March 09, 2011, 06:55:48 PM »
The malware in your first link and the VT result does not have the same MD5.
That scan is also from 21/11-2010 so it may be detected now ?

Here is the result for the one in your fist link.....and avast! detect

VirusTotal - 28/42 - scanned 5/2-2011
http://www.virustotal.com/file-scan/report.html?id=43e7b4b73680c71625fb776f2a9c5f2e3f6fff1aad3852e8db790f35cb372ade-1296966032
« Last Edit: March 09, 2011, 06:59:08 PM by Pondus »