Author Topic: Trojan Not Detected by AVAST  (Read 2955 times)

0 Members and 1 Guest are viewing this topic.

yy4

  • Guest
Trojan Not Detected by AVAST
« on: January 05, 2012, 08:32:41 PM »
Also, I think Avast should add a feature into the program to upload "false negatives" just like "false positives".

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: Trojan Not Detected by AVAST
« Reply #1 on: January 05, 2012, 08:36:05 PM »
Quote
Also, I think Avast should add a feature into the program to upload "false negatives" just like "false positives".
you can upload any file(s) detected or not detected from chest   ;)  




Moving files to the Virus Chest
http://support.avast.com/index.php?_m=knowledgebase&_a=viewarticle&kbarticleid=501#idt_03

Submitting files from the Virus Chest to avast! Virus Lab
http://support.avast.com/index.php?_m=knowledgebase&_a=viewarticle&kbarticleid=501#idt_07


or use the online form
http://www.avast.com/en-eu/contact-form.php?loadStyles



and last, the mail option.
Send sample in a password protected zip.file to  virus @ avast.com
Mail subject:  undetected sample or False positive
zip Password:  infected


use a zip program that also encrypt the content to avoid blocking from any scanner on mail server
winRAR or 7zip will do






« Last Edit: January 05, 2012, 08:43:42 PM by Pondus »

yy4

  • Guest
Re: Trojan Not Detected by AVAST
« Reply #2 on: January 05, 2012, 08:40:35 PM »
Thanks, I forwarded the bait email to virus@avast.com if that helps.

yy4

  • Guest
Re: Trojan Not Detected by AVAST
« Reply #3 on: January 05, 2012, 08:48:11 PM »
UPDATE: Def file 120105-1 already detects it. report was based on 120104.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33905
  • malware fighter
Re: Trojan Not Detected by AVAST
« Reply #5 on: January 05, 2012, 09:57:07 PM »
Hi Pondus,

Here is the Sophos analysis of this Troj/Bredo-OG: http://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/Troj~Bredo-OG/detailed-analysis.aspx
This also known as Trojan.Tenagour.9 (DrWeb) and is Zeus related malware,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!