I have found a really annoying malware sample. I tested Avast free on
Virtualbox with Windows XP 32-Bit.
Avast detected a strange behavior when I ran the malware sample:
http://s1.bild.me/bilder/030611/thumb_5446257Bild_2.png
I told Avast to block the program which causes the system to crash after this error message:
http://s1.bild.me/bilder/030611/thumb_1486767Bild_4.png
After that I made a full system scan but Avast didn’t find anything.
I also tested Comodo with this sample but the result is the same.
How is it possible that the system crashes just by terminating the program? Does this
mean that the malware could modify the system before Avast or Comodo noticed it?
The system was totally clean before I started the test.
The sample is digitally signed as Ashampoo Firewall Setup
Virustotal results:
http://s1.bild.me/bilder/030611/thumb_4944160Bild_7.png