Two trojans not detected by Avast! [SOLVED]

I’m going to share the links from Virustotal.com and hopefully detection will be added soon.

  1. http://www.virustotal.com/file-scan/report.html?id=245d4e58ec674d98683980572f998ca84a43d6c29e115c5c99f3667f06d5d66d-1299618662

  2. http://www.virustotal.com/file-scan/report.html?id=1c345270e78e267a734772afb901ea9f3290e755149dc95c3c1f1eabc644fa2e-1299618529

Links to virustotal are worthless unfortunately as that doesn’t provide a sample for analysis. Whilst samples missed by AVs are sent to the respective Av this doesn’t happen in a timely fashion and are bundled together with others.

Send the sample/s to avast as a Undetected Malware:
Open the chest and right click in the Chest and select Add, navigate to where you have the sample and add it to the chest (see image). Once in the chest, right click on the file and select ‘Submit to virus lab…’ complete the form and submit, the file will be uploaded during the next update.
Or
Send the sample to virus (at) avast (dot) com zipped and password protected with the password in email body, a link to this topic might help and undetected malware in the subject.

Appreciate the posting, because it reveals where avast should get the samples as the sources are ready available online,
so these postings should be welcomed as general information on avast not detecting, and I agree with DavidR that the sending of samples should be stimulated, I agree there,
furthermore I found some interesting info on the first and second malware online here:
http://hphosts.blogspot.com/2011/02/money-mules-downloads-and-portlane.html

and will add a quote from there:

The servers are extremely slow at present, so struggling to grab samples,
but I’ve been advised of 3 more of these. The URLs are in the same format as previously;

schwartz-brothers-llc. net/registration/need_quiz/?reg
schwartz-brothers-llc. net/files/schwartzbrothersllc.exe

generalabbrialgroup-ltd. net/registration/need_quiz/?reg
generalabbrialgroup-ltd. net/files/generalabbrialgroupltd.exe

generalabbrial-group-ltd. cc/registration/need_quiz/?reg
generalabbrial-group-ltd. cc/files/generalabbrialgroupltd.exe


Source of quote: MYSTERYFCM
from the same source, found on http://hphosts.blogspot.com/ is the following quote taken,

Just came across another lovely lot, all created March 7th, all registered using eNom (surprise surprise), all registered to Vlad Marks / vladmarks at yahoo.ca, and all with the same content and MO as the last lot.
source of quote: MYSTERYFCM

malware detected here: http://www.urlvoid.com/scan/schwartz-brothers-llc.net

The second one also here: http://malc0de.com/database/index.php?search=193.105.134.230&IP=on
also see malcode analysis here:
http://info.prevx.com/aboutprogramtext.asp?PX5=2503952252D75EF441820400EF3F08007AA77492

polonus

Samples uploaded to avast :wink:

Both files are detected by Malwarebytes as Trojan.Dropper

The samples were already uploaded several times in the past 3,4 days through virus chest option in Avast (it’s not the first time for me to upload malware samples to Avast lab, thanks to @DavidR for his detailed explanation though), but I saw that definitions for their detection were not added, that’s why I decided to post the links here.
Things do change when issue is posted on Avast forums :slight_smile:
Thanks for the quick reply guys, keep it up!

justin bieber phone number
I’ve had this problem too. I’m kinda new to avast and don’t know how to report this kind of thing…I’m used to using another av program. How do I report a virus that I’ve found in the software itself and not the forum?

edit*
oh wait- I found it. I’m dumb. Nevermind. :stuck_out_tongue:

Latest definition update (110309-1) detects these two trojans as Win32:Trj:FakeTest.
Thanks Avast! team, Good job as always! :slight_smile: