Author Topic: CyberCapture  (Read 133838 times)

0 Members and 1 Guest are viewing this topic.

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: CyberCapture
« Reply #135 on: July 16, 2016, 12:12:06 AM »
@Vlk , has CyberCapture policy changed recently? It just locked Crystal Security main EXE which was already installed and active when I've installed avast!. It picked up the Crystal Security EXE on system reboot. Waiting for verdict, but I found it interesting since it wasn't a download, it was EXE already on disk.
Visit my webpage Angry Sheep Blog

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
Re: CyberCapture
« Reply #136 on: July 16, 2016, 04:34:34 AM »
@Vlk , has CyberCapture policy changed recently? It just locked Crystal Security main EXE which was already installed and active when I've installed avast!. It picked up the Crystal Security EXE on system reboot. Waiting for verdict, but I found it interesting since it wasn't a download, it was EXE already on disk.
It is a FP.
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: CyberCapture
« Reply #137 on: July 16, 2016, 08:40:03 AM »
It's not a FP. The verdict came clean afterwards by CC. What surprised me is that it was even processed by CyberCapture considering it was a local file and not a download from web!
Visit my webpage Angry Sheep Blog

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: CyberCapture
« Reply #138 on: July 16, 2016, 08:51:09 AM »
What surprised me is that it was even processed by CyberCapture considering it was a local file and not a download from web!
Hmmm, interesting, let's hope we get some input from the devs here soon.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: CyberCapture
« Reply #139 on: July 17, 2016, 08:10:01 PM »
I hate this damn radio silence from avast! team...
Visit my webpage Angry Sheep Blog

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48562
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: CyberCapture
« Reply #140 on: July 17, 2016, 08:12:06 PM »
I hate this damn radio silence from avast! team...
I'll feel the same way if no reply by tomorrow. I consider this a holiday since it's Sunday. :)
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: CyberCapture
« Reply #141 on: July 17, 2016, 08:16:16 PM »
There was no reply to anything for days, not just during Sundays...
Visit my webpage Angry Sheep Blog

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48562
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: CyberCapture
« Reply #142 on: July 17, 2016, 10:10:15 PM »
There was no reply to anything for days, not just during Sundays...
Trying to be kind. :)
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2294
Re: CyberCapture
« Reply #143 on: July 18, 2016, 02:15:04 PM »
@Vlk , has CyberCapture policy changed recently? It just locked Crystal Security main EXE which was already installed and active when I've installed avast!. It picked up the Crystal Security EXE on system reboot. Waiting for verdict, but I found it interesting since it wasn't a download, it was EXE already on disk.
Hello RejZoR,
can you post sha256 of the file so we can find more info on our backends?

Thanks,
Milos

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: CyberCapture
« Reply #144 on: July 18, 2016, 03:18:21 PM »
SHA-256:
10161446bd995d4ff6dcf5cf0b693dcab8b7e795d4805f7544be911de30b6d5b

Crystal Security.exe
Visit my webpage Angry Sheep Blog

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2294
Re: CyberCapture
« Reply #145 on: July 18, 2016, 05:36:32 PM »
Hello RejZoR,
we see that there is a http source: hxtp://www.crystalsecurity.eu/updates/crystal_security._xe and from the date we saw this sha256 for the first time, it looks that your file was updated recently.

Milos

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: CyberCapture
« Reply #146 on: July 18, 2016, 06:31:06 PM »
It's possible I've re-downloaded a modified EXE to generate the has. But at the time I've got CyberCapture dialog, it was a 100% local file, because it was already on the disk when I installed avast!. Meaning avast! could only see it as local file.

Do you have any ability to search based on file name?
Visit my webpage Angry Sheep Blog

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2294
Re: CyberCapture
« Reply #147 on: July 19, 2016, 09:31:04 AM »
Yes, we have ability to search by file name.

Milos

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: CyberCapture
« Reply #148 on: July 19, 2016, 09:41:40 AM »
I just find it strange that it was originally said as CyberCapture only processing files obtained from web. Which means the program has to detect its origin somehow (with Web Shield).

However, in my case, the file was local from start.

1. Windows Defender (No AV).
2. Installed "Crystal Security"
3. Installed avast!
4. avast! detected Cyber Security main EXE on next system reboot and processed it via CyberCapture. The verdict CLEAN arrived next morning as this was "locked" by CC in the evening.

Considering avast! was introduced to the system AFTER Crystal Security has already been installed, this means CyberCapture is now also processing local files, there was no other way for it to detect that EXE as "downloaded from web". That's what I'm wondering really. You guys always said it doesn't process local files, just downloads. Has that changed recently and no one mentioned it?
Visit my webpage Angry Sheep Blog

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2294
Re: CyberCapture
« Reply #149 on: July 19, 2016, 09:48:52 AM »
I think that the steps could be:

1. Windows Defender (No AV).
2. Installed "Crystal Security"
3. Installed avast!
4. "Crystal Security" updated itself (info about download from web was added "hxtp://www.crystalsecurity.eu/updates/crystal_security._xe")
5. avast! detected "Crystal Security" main EXE on next system reboot (is "Crystal Security" scheduled to run after boot?) and processed it via CyberCapture.

Milos