Hey guys,
The samples that were shared contains 2 fps and 1 vbs file that is about a year old that doesn’t do anything bad essentially.I tested it myself.I have submitted the vbs to avast.The other 2 files are clean.

https://www.virustotal.com/en/file/cb4bfa289b0a98a667713fd51d13651b9dd265b96675af0aefc69fdfeb391cff/analysis/1496797780/
First submission 2016-02-12 18:15:10 UTC ( 1 year, 3 months ago )
Last submission 2017-06-07 01:09:40 UTC ( 3 minutes ago )

I think most vendors detect it because of the normal signatures where they got the file that was already detected by other AV’s and so they detected it too.Its not the way avast works.

the 2 binaries:
https://www.virustotal.com/en/file/17f746d82695fa9b35493b41859d39d786d32b23a9d2e00f4011dec7a02402ae/analysis/1496797790/
First submission 2011-01-19 15:00:02 UTC ( 6 years, 4 months ago )
Last submission 2017-06-07 01:09:50 UTC ( 1 minute ago )
This file belongs to the Microsoft Corporation software catalogue. The file is often found with cmd.exe as its name.

https://www.virustotal.com/en/file/2160ba6829909eeb1d272ac4a5f43588750c0b4743477bf2b46952033b5d4b3b/analysis/1496797807/
First submission 2013-12-11 21:08:57 UTC ( 3 years, 5 months ago )
Last submission 2017-06-07 01:10:07 UTC ( 2 minutes ago )
This file belongs to the Microsoft Corporation software catalogue. The file is often found with wscript.exe as its name.

Read the additional information tab on VT.

I think this is not a miss considering the running binaries are harmless and are known trusted files except the trash vbs which triggered wscript.exe and that’s all.One of the reasons maybe why avast never detected the 2 binaries since they are associated with windows and its operations.The shortcuts the vbs creates is probably going to trigger the vbs over and over again when executed.Time to format the stick. :slight_smile: