yea…but he is already very angry ;D
I am very angry !
just a question: I’m not testing samples and I won’t, but for those who do post about stuff missed by Avast, does it make a difference (or not) if heuristic sensitivity is set to high in the web and file system shields?
edit: would be nice if people didn’t just post the VT results, but also their own and specify their settings (yeah, I know, this supposes a VM or sandbox…that’s just a suggestion).
The list came from VirusTotal’s Top10 file submissions (Yesterday)
http://www.virustotal.com/file-scan/report.html?id=9ef6116b0e3e1f663e48b76dc2957d97187f7414be0024b721569d67d378ff56-1285448595
This could be a false positive:
http://www.virustotal.com/file-scan/report.html?id=017c62ee87dfc53f32b774d867f11be1c94911735d051312979861174a7020b0-1285270314
Fake ZillaTube:
http://www.virustotal.com/file-scan/report.html?id=c2b7e07688acdcd107fd236532d7156fe0b324b597c0623653e8a1a14958caed-1285510931
Another VirusTotal’s Top10 file submissions(Yesterday)
http://www.virustotal.com/file-scan/report.html?id=9ef6116b0e3e1f663e48b76dc2957d97187f7414be0024b721569d67d378ff56-1285475821
Could be false positive:
http://www.virustotal.com/file-scan/report.html?id=f609efee5fa8df832ce7708ed58f32021d928089404689eb90ddc1f73d8cd32f-1285105620
i Have one link from Virustotal, Avast found it, i Have on link from Jotti’s malware scan Avast dont Find it on Same virus sample why?
http://www.virustotal.com/file-scan/report.html?id=9266c4084e41982ddf7e365be679e53842da37c1bccc5269d2723fdfabeee420-1285516483
Have one link from Virustotal, Avast found it, i Have on link from Jotti's malware scan Avast dont Find it on Same virus sample why?VT and Jotti may not be on the same update yet ?
ahh now i see last update on malware jotti was 2010-09-14 for Every AV there ![]()
now They updated
avast Detect it !
Jotti also uses Linux versions of AVs I believe, not to mention has nowhere near the number of scanners of virustotal (currently 43), so personally that is the only multi-scanner site I would use.
Hi DavidR,
But the folks that report missed samples through VT links, should check there again for more recent results, also sometimes results are found to be false positives, see the link Left123 gave above. So do your homework properly.
polonus
Trojan.
Fake Codec Pack.
Fake Antivirus Program.
Send a password protected zip file ( Password: virus) to virus@avast.com with the subject “Undetected Malware”, Put the password in the body of the e-mail.
Possible Trojan.
Another Trojan.
Another fake AV.
http://www.virustotal.com/file-scan/report.html?id=9fcfe985ff93d493ae8c091566b6524deb114748a5a5018f80d797c658311e14-1285836908
http://www.virustotal.com/file-scan/report.html?id=6a17b1626a22aaaf87bb8b1ad173f91b85f2ab4a863a4b4ec5227e8ba4f02879-1285831256
backdoor: winlogon.exe connected to 74.55.58.173 under weird url like 2-3-v-5-6-l-w-1-q-9-j-n-6-2-n-8-…
avast disabled by: programs will be disabled or shall we say redirect to this winlogon.exe at this registry [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
programs running: winlogon.exe under windows current user name with svhost.exe child process
version: 206
how to keep your programs running?
put all access to this registry in read only…
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
this is the 3rd time same virus variant undetected but every time I’ve uploaded to avast virus-lab It took a week before avast detects(update config every 5mins).
off topic: a link for you marc57 http://www.youtube.com/watch?v=ce87ckRKrzk kiss madiam won greece got talent,well done ;D ;D
Thanks for the link Left123.