Win32/FakeSysdef arg50300.exe

My computer was infected with this Trojan but was not detected by avast but by Windows defender why didn’t avast protect my computer from this threat.

Put the sample in the virus chest of avast and send it to the virus lab.

these fake AV varients come out reguraly…so no AV can get all of them…no AV is perfect :wink:

no security program have 100% detection

how was it found…during a scan or real time detection?

where was the file found ?

It was a realtime detection by windows defender while I was visiting a web page about the johnson motor

do you have the URL ?

post it none clickable http as hxxp / www as wxw

A rogue related to System Defender. If it has not been cleansed from your computer, you need help from a qualified remover,

polonus

not sure maybe hxxp://johnsonmotorsblog.com/ hxxp://freeenergynews.com/Directory/Howard_Johnson_Motor/Blueprints/index.html hxxp://wsw.hojomotorreviewz.com/johnson-motor-review-perpetual-motion-machine-that-save-energy/

maybe hxxp://this.content.served.by.adshuffle.com/p/kl/46/799/r/12/4/8/ru/dXNuZXdzLm1zbmJjLm1zbi5jb20=/332299434/v/576462397116308777/ac/781370/b/283941/c/562288/click.html hxxp://johnmot12.kaiax.revenuewire.net/johnson-motor/homepage?foxsports&debc7b7052484273bcc18038829335f5 hxxp://wsw.johnsonmotor.org/rw/index.php

found it, and it seems to bee brand new

HTML scan
https://www.virustotal.com/file/cab68d409a5b7d9b7085430fb1e3da6913d03adbcf7ddf35e8d08a4eaa9207b1/analysis/1332691696/

file scan - First seen by VirusTotal - 2012-03-25 16:09:51 UTC ( 5 minutter ago )
https://www.virustotal.com/file/10a5fffb37675a8112e5f53f434be89949412d28f1f6395bcc0761250960cd94/analysis/1332691791/

Malwarebytes - Rogue.FakeHDD

in about 2 minutes it will be in avast lab inbox :wink:

Thanks

Brightcloud came up with a yellow 40 - There is a higher than average probability that the user will be exposed to malicious links or payloads.

Nice find, and good jel7035 reported it,

polonus