Author Topic: Submitting file to avast through web form  (Read 3206 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Submitting file to avast through web form
« on: January 07, 2015, 08:51:16 PM »
I've tried twice to submit a file to avast through the web form at;

ht tp s://ww w.av ast.com/en-us/contact-us.php?subject=VIRUS-FILE

And I get a nice reply in my stated email from the automated service:

"Your email was deleted, if you need to contact us please use web form ..."

Any ideas, or should I just take an asprin and go to bed?

Mikael Fors
Sweden

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: Submitting file to avast through web form
« Reply #1 on: January 07, 2015, 08:58:41 PM »
Try this   https://support.avast.com

Or send in a password protected zip file to virus@avast.com
Password:  infected


Have you checked the file at www.virustotal.com / www.metascan-online.com

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Re: Submitting file to avast through web form
« Reply #2 on: January 07, 2015, 09:00:00 PM »
Try here (select avast virus lab) https://support.avast.com/
Or in a password protected zip file to virus@avast.com
Use "virus" as your password. This will give the virus lab an opportunity
to determine if it is or is not infectious.

You may also submit files to be checked at...
https://www.metascan-online.com/
http://virusscan.jotti.org/nl
http://www.virscan.org/
https://www.virustotal.com/en/#url

edit: word change
« Last Edit: January 07, 2015, 11:23:13 PM by Para-Noid »
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

REDACTED

  • Guest
Re: Submitting file to avast through web form
« Reply #3 on: January 07, 2015, 10:35:57 PM »
I managed to send the files and the registry to avast. Eventually.

MSIL.Krypt (B) or something.

I have only the executable and a dll. I don't know how I got infected, nor where it came from, only thing I know is it wasn't supposed to be in my computer, especially not under %WINDIR%\SysWow64 :-D
« Last Edit: January 07, 2015, 10:39:38 PM by swextal »

REDACTED

  • Guest
Re: Submitting file to avast through web form
« Reply #4 on: January 07, 2015, 10:48:12 PM »
metascan reported that 7 of 43 found a threat, virustotal 15 of 56 in "pylarcairnboozy.exe".

metascan 2 of 43, virustotal 4 of 56 in "toadsorgypeek.dll"....

They must have fun creating the names of stuff  ;D

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: Submitting file to avast through web form
« Reply #5 on: January 07, 2015, 10:52:36 PM »
If you want to share, you may post link to scan result ...... there is lots of extra info we cant see unless you post the link    ;)

« Last Edit: January 07, 2015, 10:56:27 PM by Pondus »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: Submitting file to avast through web form
« Reply #6 on: January 07, 2015, 11:04:16 PM »
Quote
    They must have fun creating the names of stuff  ;D 
https://forum.avast.com/index.php?topic=149952.0


REDACTED

  • Guest
Re: Submitting file to avast through web form
« Reply #7 on: January 08, 2015, 08:13:38 PM »
The virus naming convention am I aware of. It's the filenames i wonder how they come up with...

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Re: Submitting file to avast through web form
« Reply #8 on: January 08, 2015, 10:39:14 PM »
Could you please post the link(s) to your scan results?  ???
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

REDACTED

  • Guest
Re: Submitting file to avast through web form
« Reply #9 on: January 14, 2015, 12:02:53 PM »
These are the scan results for the two files combined in a zip archive (before the Avast sig was updated) made about the date of the original post

https://www.virustotal.com/sv/file/21508f4d8e6b7f7bc00025450ff60241d0732a5297d3c15983797b56d41b8334/analysis/

This is for toadsorgypeek.dll today:

https://www.virustotal.com/sv/file/763d3d43a15103233ee0f3426a6cd1e7b27a67c9f601badc16517f94fcc39012/analysis/

This is pylarcairnboozy.exe (internal fake name: stub.exe) rechecked today:

https://www.virustotal.com/sv/file/f4a4192593ffc0e08f08197b3a5eb55152dabc8024f507f93f26b0ebfb091c4a/analysis/1421232977/

The exe hides from task manager, but I had processexplorer running so it popped up there. Created a service called "IdaTriorFluor", with displayed name of service as "Chanc Thigh Swans", not visible from services.msc. Disabled through manual regedit of the start dword from 2 (Automatic) to 3 (Manual). (And renaming the .exe and .dll so it couldn't respawn itself after being killed....)

The service was visible through tasklist though (they probably never expect users to use those commands for some reason) and killable through taskkill.