New worm undetected by Avast! (Skype virus)

Hi. [b][font=arial]Ive detected a virus from a friend, and i tried to test what is. i ran Antivirus and nothing. Then the Windows Defender told that i have been infected by a Worm ._. Id like to show you the worm and please add it to virus list. Thanks
Peri
PD: Ill upload to my server, PLEASE DONT REPORT IT, SEND ME AN EMAIL TO REMOVE IT. Thanks ^[1][/font]yo

htxp://perikiyoxd.tk/virus , is the .exe

EDIT:Thanks all of you for this service :smiley:


  1. /b â†Šī¸Ž

Lets check that.

Please make the http to htxp, the link is live now.

One malicious file was trying to reach out to an malicious URL which was blocked by Avast.

And it set an Autorun key.

File is reported to Avast.

Virustotal Scan: https://www.virustotal.com/de/file/aa2584d268bc715aa9a0bddb8c0a58bcdef5e61c78bd585f5b011adeb6af4a78/analysis/

File is really new.

Norman G2 analyzer auto added signature as Malware.AJFUI

Thanks for the information Pondus. :wink:

Sent to Malwarebytes / Comodo.

Already saw your comment on Virustotal. :wink:

Sent to Avira, GData and Symantec.

Avast is now detecting it as Win32:Dropper-Gen.

https://www.virustotal.com/de/file/aa2584d268bc715aa9a0bddb8c0a58bcdef5e61c78bd585f5b011adeb6af4a78/analysis/1384444709/

How is it Windows Defender detected it in the beginning? SO many people said Defender was useless -
perhaps not ?

Defender is not useless, but it has a bad detection rate and its interfearing with other AVs.

Yes, but in the first post above, the user mentioned WD detected the malware when his installed AV did not.

Did WD somehow inhibit the installed AV from recognizing that in fact, malware was active?
Or did WD just have better detection and/or technology ?

File is now detected as RTF:Obfuscated-gen [Trj].