Try here (select avast virus lab) https://support.avast.com/
Or in a password protected zip file to virus@avast.com
Use “virus” as your password. This will give the virus lab an opportunity
to determine if it is or is not infectious.
I managed to send the files and the registry to avast. Eventually.
MSIL.Krypt (B) or something.
I have only the executable and a dll. I don’t know how I got infected, nor where it came from, only thing I know is it wasn’t supposed to be in my computer, especially not under %WINDIR%\SysWow64
The exe hides from task manager, but I had processexplorer running so it popped up there. Created a service called “IdaTriorFluor”, with displayed name of service as “Chanc Thigh Swans”, not visible from services.msc. Disabled through manual regedit of the start dword from 2 (Automatic) to 3 (Manual). (And renaming the .exe and .dll so it couldn’t respawn itself after being killed…)
The service was visible through tasklist though (they probably never expect users to use those commands for some reason) and killable through taskkill.