Does avast detect adware here or only in PUP-mode?

Re: https://urlquery.net/report/f8164b15-6d54-4cdd-b416-f034c1752108
See: https://www.virustotal.com/nl/url/69a65ddbb26ab63b0fa340274d1fae7442a3eccacfe03bcad67cf7fbb54f137e/analysis/1518534817/
downloade file scan results: https://www.virustotal.com/nl/file/8dad97c222995e9dcf779dbbbc4c1b0d5b97c0051d75edc18e96f62880210698/analysis/1508057784/

Read: https://www.bleepingcomputer.com/startups/duck.exe-7464.html

polonus

Your file scan is 4 months old > Analysis date: 2017-10-15 08:56:24 UTC ( 4 months ago )

Have you tried doing a fresh scan? Yea I know I am a fresh scan nag ;D

Since you use old VT there is no rescan button, so here is how to do it

Copy the SHA from top of your file scan result (not url scan), then go to new VT www.virustotal.com click search tab and paste in SHA then search

When result show, click the blue button at top right and select rescan and you get fresh result Last analysis 2018-02-13 15:43:14 UTC :wink:

https://www.virustotal.com/#/file/8dad97c222995e9dcf779dbbbc4c1b0d5b97c0051d75edc18e96f62880210698/detection

Hi Pondus,

Latest: https://www.virustotal.com/nl/url/69a65ddbb26ab63b0fa340274d1fae7442a3eccacfe03bcad67cf7fbb54f137e/analysis/1518536670/
and https://www.virustotal.com/nl/file/8dad97c222995e9dcf779dbbbc4c1b0d5b97c0051d75edc18e96f62880210698/analysis/1518536594/

pol

Why does your VT link always show the old VT interface ?

I can only guess it has to do with the /nl/ at the end. Different webpage that may not have been fully translated and updated yet.

Edit: Google (Alphabet Inc.) owns VT? I had no idea.

Yepp

This goes to new www.virustotal.com

This goes to old www.virustotal.com/en