This instance of virut infector going under the av radar?

Hi malware fighters,

Infected site info : http://safeweb.norton.com/report/show?url=http%3A%2F%2F74.52.90.50%2FVirtobCleaner.exe&x=12&y=2
Reported from: htxp://74.52.90.50/VirtobCleaner.exe
https://www.virustotal.com/analisis/dba197176905a99f29bc2414efd540ba90db2be84d422b55eb2485db5a70926e-1275424038
Another part of the malcode story of this IP-range here: http://www.botsvsbrowsers.com/ip/74.52.90.5/index.html
http://forums.malwarebytes.org/index.php?s=25f9e53464195b1a751bda0104383485&showtopic=52526&pid=260551&st=0&#entry260551

polonus

Sorry Mr.D but that is a FalsePositive from Norman, i got it confirmed today

quote:
This a virus cleaning tool created by some researcher which uses some pattern used by Virut virus, hence its detected as Virut. This will not do any malicious activity hence removing it from detection.

Thanks & Regards,
Sukumar

Files:
VirtobCleaner.exe : Processed - KC-Virut.GN

For analysis, sdo

If you scroll down to the end of the VirusTotal result, you will find this

sigcheck: publisher…: Message Labs Pvt. Ltd.
copyright…: Copyright (c) 2008
product…: Message Labs Pvt. Ltd. Clean
description…: Virtob Cleaner
original name: Clean.exe
internal name: Clean
file version.: 1, 0, 0, 8
comments…: Virtob ZVMonNT Event SynChronization
signers…: -
signing date.: -
verified…: Unsigned

and Message Labs is a security company owned by Symantec…

also confirmed CLEAN from Avira

A listing of files alongside their results can be found below:

File ID Filename Size (Byte) Result
25336176 VirtobCleaner.exe 116.07 KB CLEAN

Please find a detailed report concerning each individual sample below:

Filename Result
VirtobCleaner.exe CLEAN

The file ‘VirtobCleaner.exe’ has been determined to be ‘CLEAN’. Our analysts did not discover any malicious content.

http://www.mywot.com/en/scorecard/74.52.90.50

Hi Pondus,

Thanks for the heads-up on this Norman NSW’s “Alice in Wonderland” detection. How is the average user to trust these scan details? I always thought reputation scanners weren’t all that reliable, some do not scan deep enough, some get “curious” user input, and the content of websites is sometimes changing from reliable to suspicious to hacked and even to dangerous.

You again demonstrated to us, how important it is not to go on first sight appearances, but to question and establish the facts, thanks for that, By the way there are certainly malicious software instances on mentioned site, so do not venture out there folks…keep your visors up! The source of the virtob cleaner seems to reside here: http://www.unmaskparasites.com/web-page-options/?url=http%3A//www.computerdelhi.com
External references lead me to this conclusion:
\activation.indiaantivirus.com safe? - displaying 1 of 1

*  Here - htxp://activation.indiaantivirus.com:81/1.htm
  • wXw.indiaantivirus.com safe? - displaying 2 of 2

    • hxtp://www.indiaantivirus.com - htxp://www.indiaantivirus.com
    • Paid av- - htxp://www.indiaantivirus.com/OnlinePurchase.asp?tp=PCO
  • 74.52.90.50 safe? - displaying 3 of 3

    • Download 1 - htxp://74.52.90.50/upgradeall.exe
    • InstallNP2010.exe - htxp://74.52.90.50/installnp2010.exe
    • InstallNP0.exe - htxp://74.52.90.50/installnp0.exe
  • wXw.computermumbai.com safe? - displaying 1 of 1

    • lnk.exe - htxp://www.computermumbai.com/lnk.exe
      was checked by someone here, because Google came up with this reference:
      htxp://jsunpack.jeek.org/dec/go?report=eba729c97a86b1816ec67da9ac321227c1846d94

Damian

Hi malware fighters,

Very strange link, binded with malware, so stay away from this link: htxp://www.computerdelhi.com/vundo.exe

Definitely malcoded.

See results of my recent scan here:
http://scanner.novirusthanks.org/analysis/01156c68e0ff326e131d9c09b8e23feb/dnVuZG8uZXhl/
http://wepawet.iseclab.org/view.php?hash=80450c9aa3c9b8af05af852f18f7e56b&t=1275513262&type=js
See: http://anubis.iseclab.org/?action=result&task_id=1fa1978dc0cbceb74f977922a97d5a6fa&format=html

Why does not avast detect this?

polonus