I’m going to share the links from Virustotal.com and hopefully detection will be added soon.
Links to virustotal are worthless unfortunately as that doesn’t provide a sample for analysis. Whilst samples missed by AVs are sent to the respective Av this doesn’t happen in a timely fashion and are bundled together with others.
Send the sample/s to avast as a Undetected Malware:
Open the chest and right click in the Chest and select Add, navigate to where you have the sample and add it to the chest (see image). Once in the chest, right click on the file and select ‘Submit to virus lab…’ complete the form and submit, the file will be uploaded during the next update.
Or
Send the sample to virus (at) avast (dot) com zipped and password protected with the password in email body, a link to this topic might help and undetected malware in the subject.
Appreciate the posting, because it reveals where avast should get the samples as the sources are ready available online,
so these postings should be welcomed as general information on avast not detecting, and I agree with DavidR that the sending of samples should be stimulated, I agree there,
furthermore I found some interesting info on the first and second malware online here:
http://hphosts.blogspot.com/2011/02/money-mules-downloads-and-portlane.html
and will add a quote from there:
The servers are extremely slow at present, so struggling to grab samples,
but I’ve been advised of 3 more of these. The URLs are in the same format as previously;schwartz-brothers-llc. net/registration/need_quiz/?reg
schwartz-brothers-llc. net/files/schwartzbrothersllc.exegeneralabbrialgroup-ltd. net/registration/need_quiz/?reg
generalabbrialgroup-ltd. net/files/generalabbrialgroupltd.exegeneralabbrial-group-ltd. cc/registration/need_quiz/?reg
generalabbrial-group-ltd. cc/files/generalabbrialgroupltd.exe
Source of quote: MYSTERYFCM
from the same source, found on http://hphosts.blogspot.com/ is the following quote taken,
Just came across another lovely lot, all created March 7th, all registered using eNom (surprise surprise), all registered to Vlad Marks / vladmarks at yahoo.ca, and all with the same content and MO as the last lot.source of quote: MYSTERYFCM
malware detected here: http://www.urlvoid.com/scan/schwartz-brothers-llc.net
The second one also here: http://malc0de.com/database/index.php?search=193.105.134.230&IP=on
also see malcode analysis here:
http://info.prevx.com/aboutprogramtext.asp?PX5=2503952252D75EF441820400EF3F08007AA77492
polonus
Samples uploaded to avast
Both files are detected by Malwarebytes as Trojan.Dropper
The samples were already uploaded several times in the past 3,4 days through virus chest option in Avast (it’s not the first time for me to upload malware samples to Avast lab, thanks to @DavidR for his detailed explanation though), but I saw that definitions for their detection were not added, that’s why I decided to post the links here.
Things do change when issue is posted on Avast forums
Thanks for the quick reply guys, keep it up!
justin bieber phone number
I’ve had this problem too. I’m kinda new to avast and don’t know how to report this kind of thing…I’m used to using another av program. How do I report a virus that I’ve found in the software itself and not the forum?
edit*
oh wait- I found it. I’m dumb. Nevermind.
Latest definition update (110309-1) detects these two trojans as Win32:Trj:FakeTest.
Thanks Avast! team, Good job as always!