Virus from news site

What exactly does virustotal do with them? Is there any collaboration between AV vendors?

*Edit* still unable to upload to virustotal - am now trying my ghost account...
Am I supposed to get an email acknowledgement from virustotal after an email send?
 
Last edited:
What exactly does virustotal do with them?

Vriustotal scans the file with:

* AhnLab (V3)
* Antiy Labs (Antiy-AVL)
* Aladdin (eSafe)
* ALWIL (Avast! Antivirus)
* Authentium (Command Antivirus)
* AVG Technologies (AVG)
* Avira (AntiVir)
* Cat Computer Services (Quick Heal)
* ClamAV (ClamAV)
* Comodo (Comodo)
* CA Inc. (Vet)
* Doctor Web, Ltd. (DrWeb)
* Emsi Software GmbH (a-squared)
* Eset Software (ESET NOD32)
* Fortinet (Fortinet)
* FRISK Software (F-Prot)
* F-Secure (F-Secure)
* G DATA Software (GData)
* Hacksoft (The Hacker)
* Hauri (ViRobot)
* Ikarus Software (Ikarus)
* INCA Internet (nProtect)
* K7 Computing (K7AntiVirus)
* Kaspersky Lab (AVP)
* McAfee (VirusScan)
* Microsoft (Malware Protection)
* Norman (Norman Antivirus)
* Panda Security (Panda Platinum)
* PC Tools (PCTools)
* Prevx (Prevx1)
* Rising Antivirus (Rising)
* Secure Computing (SecureWeb)
* BitDefender GmbH (BitDefender)
* Sophos (SAV)
* Sunbelt Software (Antivirus)
* Symantec (Norton Antivirus)
* VirusBlokAda (VBA32)
* Trend Micro (TrendMicro)
* VirusBuster (VirusBuster)
 
What else can one do? I kept the EXE and now three days later I have had no feedback from Eset (Nod32) and the file still scans as clean.

Yeah Eset doesn't really reply much. Some of the files I've sent through get detected after a few days, others still aren't being detected months later.

Send it to [email protected], replies are normally the same day.
 
I would but I no longer use AVG lol... I don't think AVG would share info with Eset or am I mistaken?
I already know it's malicious and fairly widespread...
 
Haven't tested this recently, but in the past I've seen up to 10 more detections on Virustotal a day after submitting the file to AVG. Whether Virustotal distributes the files, or AVG shares the info, or the files I submitted suddenly got very popular, I'm not sure...
 
I'd love to know the answer to that - wouldn't it be great if they agreed to work together - who cares what flav of AV you have... prolly too much competition to ask for that tho... maybe virustotal runs a subscription service that the AV providers pay for? Perhaps they are just one of many such services... like all those sites that offer assistance with hijackthis log analysis.
 
Finally got the report from virustotal. First submission was on the 10th July. Seems some products detect it as at todays update:
http://www.virustotal.com/analisis/...898e8b938495bf580fc49df52ba25c0025-1247589682
Antivirus Version Last Update Result
a-squared 4.5.0.22 2009.07.14 Riskware.PSWTool.Win32.NetPass!IK
AhnLab-V3 5.0.0.2 2009.07.14 -
AntiVir 7.9.0.204 2009.07.14 SPR/Tool.ProdKey.1
Antiy-AVL 2.0.3.1 2009.07.14 -
Authentium 5.1.2.4 2009.07.14 -
Avast 4.8.1335.0 2009.07.13 -
AVG 8.5.0.387 2009.07.14 -
BitDefender 7.2 2009.07.14 -
CAT-QuickHeal 10.00 2009.07.14 -
ClamAV 0.94.1 2009.07.14 -
Comodo 1648 2009.07.14 -
DrWeb 5.0.0.12182 2009.07.14 Tool.PassView.135
eSafe 7.0.17.0 2009.07.14 Win32.SPRTool.ProdKe
eTrust-Vet 31.6.6612 2009.07.14 -
F-Prot 4.4.4.56 2009.07.13 -
F-Secure 8.0.14470.0 2009.07.14 -
Fortinet 3.120.0.0 2009.07.14 -
GData 19 2009.07.14 -
Ikarus T3.1.1.64.0 2009.07.14 not-a-virus:PSWTool.Win32.NetPass
Jiangmin 11.0.706 2009.07.14 -
K7AntiVirus 7.10.792 2009.07.14 -
Kaspersky 7.0.0.125 2009.07.14 -
McAfee 5676 2009.07.14 -
McAfee+Artemis 5676 2009.07.14 Artemis!0017E649EBC6
McAfee-GW-Edition 6.8.5 2009.07.14 -
Microsoft 1.4803 2009.07.14 -
NOD32 4242 2009.07.14 -
Norman 6.01.09 2009.07.14 -
nProtect 2009.1.8.0 2009.07.14 -
Panda 10.0.0.14 2009.07.14 -
PCTools 4.4.2.0 2009.07.14 -
Prevx 3.0 2009.07.14 -
Rising 21.38.14.00 2009.07.14 -
Sophos 4.43.0 2009.07.14 -
Sunbelt 3.2.1858.2 2009.07.14 Win32-Trojan-gen {Other}
Symantec 1.4.4.12 2009.07.14 -
TheHacker 6.3.4.3.366 2009.07.14 -
TrendMicro 8.950.0.1094 2009.07.14 -
VBA32 3.12.10.8 2009.07.14 -
ViRobot 2009.7.14.1835 2009.07.14 -
VirusBuster 4.6.5.0 2009.07.14 -
Looking at that list, it seems very few of the big guns are on it... by big guns, I mean commercially.
 
Last edited:
Finally got the report from virustotal. First submission was on the 10th July. Seems some products detect it as at todays update:
http://www.virustotal.com/analisis/...898e8b938495bf580fc49df52ba25c0025-1247589682

Looking at that list, it seems very few of the big guns are on it... by big guns, I mean commercially.

Seems that most of these antivirus software classify it as a password tool/password view tool judging by the name they come up with for the virus. What I don't understand is how diffident versions of Mcafee seems to have different conclusions (I have seen this before as well).
 
Seems that most of these antivirus software classify it as a password tool/password view tool judging by the name they come up with for the virus. What I don't understand is how diffident versions of Mcafee seems to have different conclusions (I have seen this before as well).

That last point is a good one - it's a mystery how these guys should be working together but don't. That brings me to my next point....
Why don't the AV guys just notify the site host and have it shut down? Or is that defeating the object and taking their business away? Did I do them an injustice by closing down the FTP? Perhaps it just forces the hacker to adjust the code, effectively making another product, or perhaps it just makes it harder for 'cops' if there are any out there, to investigate... thoughts?

I did get a kick from leaving that message and shutting it down, I must admit. I would rather have had the guy arrested for fraud though... teach him a life lesson.
 
Give me a few and I'll post it here... No, eset still says 'no virus'

The file was not a virus. It did what any software which "calls home" does.

You need a good firewall which will intercept such attempts (eg Comodo), even when they are spoofed - some trojans use your browser to connect to the internet - Comodo detects those attempts too. Weaker firewalls will not warn you, because your browser is authorised and running in memory already. A firewall with HIPS is best, but can get very technical.

Most important - DON'T RUN EXEs! If you must- run them in some virtual os- or have a dedicated system where you don't do anything but run trojan horses.

Don't trust AV to detect these.
 
Just to clarify - VirusTotal does not submit files to different AV companies. It merelt scans the uploaded file with the different AV products and reports on whatever the products find.

IIRC, AV vendors are obligated to share samples with other vendors, but this obligation is only takes effect 2 or 3 days after the sample was first recieved. So a particular vendor may have exclusive detection for a day or two before the other companies are able to recieve it from them (if the other companies haven't already obtained a sample from one of their honeypots).

As for the different naming conventions by the same product - the AV product you mentioned is not the only one that does it. This generally occurs when newer versions of the product contain a rebuild of the scanning engine/s with different features and /or detection "sequences". When a virulent sample gets submitted, the newer engine is able to detect it in a certain way. If the sample is not able to be detected in the same way by the older engine, then a different means of detecting the sample is added to the older engine, and this is usually a different name (which goes according to the family of viruses that exhibits similar characteristic detection).

Another possibility is the fact that certain viruses are injectors - injecting their code into existing files. It may so happen that a particular virus injects its code into an existing virulent executable. So now, there's two viruses in one exe :) You then notice different names based on what your AV detects first.

Hope this simple explanation helps...
 
Wishblade, that's some awesome insight...
Peter - I'm trying out smoothwall express 3.0 and dansguardian... I will see if it is capable of alerting me...
 
Wishblade, that's some awesome insight...
Peter - I'm trying out smoothwall express 3.0 and dansguardian... I will see if it is capable of alerting me...

Comodo will. I did a post on this a couple months back in the Security forum with some examples.
 
Very interesting. Seems that the more unknown anti-virii apps are detecting it.

Just one point.

What are or is a "virii"?

Virus originates from Latin. The plural is therefore viruses. Virii is not plural for viruses.
 
Top
Sign up to the MyBroadband newsletter
X