36/42 (85.72%): http://www.virustotal.com/analisis/c195161d74d85d2c529338d720abd554b8feb97185dcbdb9e32653e4f2edcb2e-1269866973
wow & oh no… ![]()
thanx 4 posting! ![]()
Another Result: 28/42 (66.67%):
http://www.virustotal.com/analisis/d478dba9c3f48b81fe7c904ac715628ee9a82b06ff43da2d07c67969e52d8c11-1269867705
Hi Tech,
The infected file was names crack.exe
http://www1.virscan.org/report/4d9b96b5063b02ee2b3387e6b3fa6813.html
Even with a generic flag avast should not miss a term like crack.exe
Should come added:
Trojan.Agent.AOID
Threat Name:Trojan.Agent.AOID
Category:Trojan;Trojan.Agent
First seen:03-03-2010
Spread Level:1
Harmful Index:2
Reported By:Rising;Jiangmin;A-Squared;
Infected Countries:Denmark;Singapore;Ukrainian;
Advice:Uninstall;
Total Report:74737
And yet another missed one for malcode coming for a link in a “scare” mail (alleged copyright case document which is a trojan downloader - re: http://blog.chackraview.net/tag/rtf-embedexe-gen/
Result: 7/42 (16.67%))
http://www.virustotal.com/analisis/9b762ff9d2103022bf1476f2c55db91475f31526522716e827875801f92a0d87-1269486837
polonus
Probably both files are packed with some strong packer. AV give too much FP during analisys of cracks and patches. The reason is obvious - malware and cracks are using the same packers and “detect” is really packer detect only.
I can’t believe this files aren’t recognized yet…
Is there any worth on submitting samples anyway? :![]()
yep, that’s not good, not good at all… :
even AVG gets them…but MSE doesn’t ??? edit: MSE does catch one of them.
This is happening a lot of times with avast… Why are you missing so much samples?
http://www.virustotal.com/analisis/edf585579bc158ef416b191f2698c6d3cd305ef0ded17a5996d32cf126884665-1271163036
http://www.virustotal.com/analisis/ef4b724b9203a2f680ecb941f074c9f875c9a54c8387f934aba85286ebda7c76-1271163016
http://www.virustotal.com/analisis/d5c13c3830534f1e8f755ca71b3efd6853c8de177d34c398452560e6220fbe5b-1271162969
This first samples AREN’T BEING DETECTED yet!
Didn’t anyone send them to avast, yet…???
asyn
i suspect the detections are packer-based, not content based, but i may be wrong (anyway, Milos will try to revisit them)
Thanks a lot, Maxx…!! ![]()
Hello,
I didn’t find the samples in our database. Can you send us them, please? If they are big you can upload them to ftp.avast.com/incoming and post here the uploaded name(s).
Milos
I’ll try to find the samples again… Can’t you get them from Virus Total?
I’m very bad surprised how many samples does avast miss…
Here are more two of them:
http://www.virustotal.com/analisis/37aed9fb460d839a19a35489376f7568c874c6e3ae04ec991e67336f0fde267d-1271512515
http://www.virustotal.com/analisis/913d463352eee7bd9f8c4d2e341aeaf1396d22f2e6b90d47c3b8f110c0efdeb7-1271468500
I’ve submitted 4 files from Chest… Did a manual update…
Are this way of submitting really working? I can’t see any information while updating that the files are being uploaded ???
Avast is loosing a lot of samples… C’mon, they’re just cracks and keygens… a little P2P digging will find a lot of them… Isn’t there anybody that loves to play with fire among you? ![]()
I also hope this works, i have told customers to do so…
asyn
Not all crack.exe and keygen.exe are real malware.
Some of them are just cracks and keygens
hi,
here is one didn’t detect by avast, but windows smart screen Aleart me.
If you open the UI, and the update progress, you should see the submission. (Like my image, a site blocked by network shield being submitted, works when you submit a file too.)
-Scott-
Thanks, Scott…!! ![]()