Samples missed by avast (VirusTotal links only!)

Worm.Autorun

http://www.virustotal.com/file-scan/report.html?id=e3ae9d1d016589935718092f7df8df3f106dc7aa301340c4b19457c500ba98af-1288472531

http://www.virustotal.com/file-scan/report.html?id=a9ab8b6b0b74a9b0075caeeb544136aea9388db2e67f4c64246b590fad7a0a51-1288522576

http://www.virustotal.com/file-scan/report.html?id=8eab24201eeb1396aa717d0bd79d377b8f4c5ef5287b8f62cff2184ae8bd821a-1288522349

http://www.virustotal.com/file-scan/report.html?id=b546ce0a12dfafce59b2b2868248f5b5578235a6e4af52a8dd21fc9757561f33-1288523434

Sent to Avast Lab.

Here an user in the Spanish forum with an undetected sample.
http://forum.avast.com/index.php?topic=65848.msg555827#msg555827

here are some threats that avast did not find

http://www.virustotal.com/file-scan/report.html?id=b1fc3e6a913fa3c30be290f14affb9b2e55195a03a297f9ee519dc46796ccb79-1289284240

http://www.virustotal.com/file-scan/report.html?id=aa3419dadd52d3ee7b46c36dfed7542932ff4a813e16ee60474a17c6b3dc4bc8-1289282129

Your 1st is only detected by 2 scanners, one suspicious and the other a variant of, both of which are of a higher potential for FP.

Your 2nd one is missed by every one of 43 scanners and seems like some copycat comments at the bottom of the page.

However, all this is a moot point as links to VT alone are pointless as members of the avast virus labs have said on a number of occasions, they need the samples. So it is more important to submit samples to avast.

my bad

http://www.virustotal.com/file-scan/report.html?id=67ad1c93c546880ba311aad2e5c19eb33a2eeaa2f2b2906836f63b7715500bba-1289363902

http://www.virustotal.com/file-scan/report.html?id=3e82282ac240eb6a47dfa84d59ff942ce7c2369b5293d76e9fe86aabd264d80f-1289363896

http://www.virustotal.com/file-scan/report.html?id=9a4e65cd543b29d1f7fbad375686410fdc75212d8f76891c3f631484be0b8266-1289363574

http://www.virustotal.com/file-scan/report.html?id=6fe4f8e00d1d0ca5253fb0ab28a6bc3080b782ecc58b5dea21a1388f08b1723d-1289363907

http://www.virustotal.com/file-scan/report.html?id=67ad1c93c546880ba311aad2e5c19eb33a2eeaa2f2b2906836f63b7715500bba-1289363902

http://www.virustotal.com/file-scan/report.html?id=ce48d778550aaa27aec92531870abd30995e5475ad23b4c50e9685c2551bbd8b-1279900191

http://www.virustotal.com/file-scan/report.html?id=f41b88506655174076e2bd781f8285b360ed9d3267b2e81446f9daaebdf53c8f-1289442972

http://www.virustotal.com/file-scan/report.html?id=2bc9d22343dc407b627ff29801a604fc02d0b9c55647eed04e30d8d67bcb0948-1289443049

http://www.virustotal.com/file-scan/report.html?id=d8742493cee66ed81255dedc0aa99fa6c1e9125c123066e691ae4daea699cdb8-1289106634

http://www.virustotal.com/file-scan/report.html?id=4e9a3ad34db9ca541f08faee4bdd73cd2715ae8c88dcbca8f157e2243b5a1074-1289457086

http://www.virustotal.com/file-scan/report.html?id=68aa60a46a2d546b48cc98cb2c898c8765011c9f8e0e12353f724652869d6c37-1289456975

http://www.virustotal.com/file-scan/report.html?id=9a4e65cd543b29d1f7fbad375686410fdc75212d8f76891c3f631484be0b8266-1289457804

http://www.virustotal.com/file-scan/report.html?id=3f112fdc6ef8190b0bcc6798cc8f1decbfa54d7310ff9308f2cb60db041fb29e-1289458254

http://www.virustotal.com/file-scan/report.html?id=ab8147e4a3605e0051be24bc260425a32c7b6a529024e8f1419ff3b38a8ce4f3-1289458476

Are you submitting the samples to avast?
If not, you’re losing your time posting the links…

@Tech you can continue to submit VT links here.lol

http://forums.comodo.com/av-false-positivenegative-detection-reporting/malware-not-detected-2010-t49281.0.html

yes we are want to submit the samples to avast

Hi :slight_smile:

Possible undetected malwares: http://www.virustotal.com/file-scan/report.html?id=34da592c1e1339be43657cb072f767874a8dae598a97a591b88ec3b12ad1c12e-1289509350

http://www.virustotal.com/file-scan/report.html?id=1a096a4bfe803b54268d00f4bbbe88c8d3891a3f17781d164a35b938c1170f50-1289510065 (Avast detected this virus but Avast4 didn,t detect it)

And what is the relationship between avast and Comodo in this case?

Actually when you submit a malicious file to VT, VT will submit the undetected malware to both Avast and Comodo, so I do not understand why such a thread exist on both the Avast and Comodo forum.

Anyway I will not hijack this thread with a Comodo discussion.

Keep up with your submission guys.

Regards

Actually when you submit a malicious file to VT, VT will submit the undetected malware to both Avast and Comodo, so I do not understand why such a thread exist on both the Avast and Comodo forum.
exactly, and some of the avast! Guy`s have explained that a couple of time, but this tread refuses to die

Possible Trojan.

http://www.virustotal.com/file-scan/report.html?id=5fb3a5adaef0738d03433f988bb743f6dbfb97cf46bfad1d34cae4af15895d53-1289547163

Update: Now detected as Win32:Malware-gen

When you’re facing a sample that avast is not detecting… and you check with virustotal and yet avast does not detect… Or when you get infected because avast simple failed… well, you think you could have a place to say: Hey, avast detection rate could be better.

But it still achieves ‘nothing’ and as I keep saying if you don’t go back and modify your posts when it is added, then it is a totally one sided, unbalanced topic that helps ‘no one’ other than to allow someone to vent their spleen.

It is a total waste of time, avast will always be trying to improve detections. It is the nature of the beast that AVs will always be playing catchup. This is why the generic, algorithmic, behavioural and heuristic signatures/rules were introduced to help improve over just signature based detection.

I agree with David, this topic is useless.

Unless avast open a topic like MBAM has for posting malwares, this kind of topic is useless.

Just something else is about submitted malwares end, we never know what happened to malwares we have submitted, Delivered or not? Some of them are being added to database but what about those that are not detected? Are they clean or they are just being ignored?

avast! need more way for collecting malwares, a web-interface is essential, something that does not cost much for avast because they already have resource for that (A public FTP Folder with enough hosting, bandwidth etc) and just need time and a technical team work on that a few days. I don’t want post link to other vendors website because some people don’t like, if not, I could post some example :wink: