Author Topic: All about infected files  (Read 10281 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: All about infected files
« Reply #15 on: May 03, 2015, 10:55:07 PM »
There is no difference malware is malware played, see also: http://www.techrepublic.com/blog/it-security/dropsmack-using-dropbox-to-steal-files-and-deliver-malware/
The cloud should not be inherently safer for your example.
Anyways a pre-scan is your best bet.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline ehmen

  • Poster
  • *
  • Posts: 498
Re: All about infected files
« Reply #16 on: May 04, 2015, 01:58:27 AM »
How do you submit a file on Google Drive to virustotal.com? You submit the URL after you click on said file (which will make VR scan just that video but not the general website it's on)?

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48551
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: All about infected files
« Reply #17 on: May 04, 2015, 03:04:14 PM »
How do you submit a file on Google Drive to virustotal.com? You submit the URL after you click on said file (which will make VR scan just that video but not the general website it's on)?
First you need to make sure that the link to that file is sharable.
If only you have access, then it can't be scanned by virustotal or any one else.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: All about infected files
« Reply #18 on: May 04, 2015, 04:21:43 PM »
or you download and save the file on your computer (dont run it) then upload to Virustotal or Metascan


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: All about infected files
« Reply #19 on: May 04, 2015, 04:33:54 PM »
Or even more secure never even download just download to be pre-scanned by Meta-scan extension in a browser running sandboxie and then choose to do not restore the file. The scan results will give you an indication of what is there.

polonus
P.S. The scan extension resides here: you should give the link to metascan for chrome
https://chrome.google.com/webstore/detail/metascan-online-for-chrom/fjampemfhdfmangifafmianhokmpjbcj


there is also a VT uploader
https://www.virustotal.com/nb/documentation/desktop-applications/virustotal-uploader

Thanks to pondus for reminding me...

Damian
« Last Edit: May 04, 2015, 04:50:22 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline ehmen

  • Poster
  • *
  • Posts: 498
Re: All about infected files
« Reply #20 on: May 04, 2015, 08:08:46 PM »
Is submitting the link to VR after making it sharable just as effective as downloading and then uploading to VR?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: All about infected files
« Reply #21 on: May 04, 2015, 08:27:32 PM »
Is submitting the link to VR after making it sharable just as effective as downloading and then uploading to VR?
depends what you mean by effective? ... if the file is scanned, it is scanned



Offline ehmen

  • Poster
  • *
  • Posts: 498
Re: All about infected files
« Reply #22 on: May 05, 2015, 01:35:41 AM »
depends what you mean by effective? ... if the file is scanned, it is scanned
Than it's just as effective as downloading and uploading. So I'll just submit the URL once it's sharable.

Offline ehmen

  • Poster
  • *
  • Posts: 498
Re: All about infected files
« Reply #23 on: May 05, 2015, 03:41:45 AM »
How do you submit a file on Google Drive to virustotal.com?...
First you need to make sure that the link to that file is sharable.
If only you have access, then it can't be scanned by virustotal or any one else.
tried it, didn't work.
First I scanned a Ccleaner installer and it was flagged by ESET-online.
(https://www.virustotal.com/en/file/b5de4b21e2abc79b4d7cfefc16c0b092f84d37e08c9fb5cd03aa616bcbeee87e/analysis/1430789605/)
And then I uploaded it to Google Drive as a test, and scanned the URL (after allowing anyone with the link to access), and it came up squeaky clean.
« Last Edit: May 12, 2015, 04:23:46 AM by ehmen »

Offline ehmen

  • Poster
  • *
  • Posts: 498
Re: All about infected files
« Reply #24 on: May 06, 2015, 12:34:54 AM »
Apparently it VR scans the cloud website and not the individual file, as I've indicated above.
« Last Edit: May 12, 2015, 04:23:26 AM by ehmen »

Offline ehmen

  • Poster
  • *
  • Posts: 498
Re: All about infected files
« Reply #25 on: May 12, 2015, 04:22:21 AM »
So is there another way to scan files online without downloading them?

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: All about infected files
« Reply #26 on: May 12, 2015, 08:14:31 AM »
That is MetaScan and you can have it as an extension inside your browser,
you can even pre-scan downloading inside sandboxie, but later you cancel restore file.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline ehmen

  • Poster
  • *
  • Posts: 498
Re: All about infected files
« Reply #27 on: May 17, 2015, 05:52:13 PM »
Can a infected (document, media, etc.) file infect other similar or non similar files in the same folder or even computer just by being there?

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: All about infected files
« Reply #28 on: May 17, 2015, 06:23:36 PM »
An example that this is throughout possible: http://blog.trendmicro.com/trendlabs-security-intelligence/word-and-excel-files-infected-using-windows-powershell/ 
Quote
The downloaded PowerShell script also contains the necessary code to infect other Word and Excel documents with the malicious CRIGENT code. To do this, it uses PowerShell scripts to modify registry entries, which lowers the security settings of Microsoft Office.
Mind you always have to run that code for it to infect other docs .... simply storing it in the same folder as a clean will not infect. Additional info. thanks Pondus.

polonus
« Last Edit: May 18, 2015, 12:34:25 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline ehmen

  • Poster
  • *
  • Posts: 498
Re: All about infected files
« Reply #29 on: May 17, 2015, 06:37:50 PM »
But that affects general settings, or also infects specific files as well?