Malware Alert from Avast AV Software on Win 8.1

Questions and Answers : Windows : Malware Alert from Avast AV Software on Win 8.1
Message board moderation

To post messages, you must log in.

AuthorMessage
Peter C. Equality Frank
Volunteer tester

Send message
Joined: 16 Oct 99
Posts: 1
Credit: 1,307,805
RAC: 0
United States
Message 1683624 - Posted: 24 May 2015, 7:38:55 UTC

I received an infection alert from my Avast AV software, advising that while contacting the server, BOINC attempted to download a file infected with malware. The connection was blocked and aborted. Here is the advisory that I received:

https://plus.google.com/+PeterCEqualityFrank/posts/DtLHFDLbRMB?pid=6152120900400253026&oid=106600597250549324874
ID: 1683624 · Report as offensive
Profile BilBg
Volunteer tester
Avatar

Send message
Joined: 27 May 07
Posts: 3720
Credit: 9,385,827
RAC: 0
Bulgaria
Message 1683658 - Posted: 24 May 2015, 11:14:49 UTC - in response to Message 1683624.  
Last modified: 24 May 2015, 11:54:55 UTC

Link to the file:
http://boinc2.ssl.berkeley.edu/beta/download/setiathome_7.06_windows_intelx86__opencl_intel_gpu_sah.exe

It is 'False Positive' from Avast - Please send the file or the above URL to Avast and say to them: 'False Positive' (so they can fix the detection/signatures)

Also BitDefender is in fault - all Antiviruses that (Falsely) reported "Gen:Variant.Fosniw" are using the BitDefender engine/signatures:
https://www.virustotal.com/en/file/0e3e5d238a68c92965fe38ad7d881406b4f511455b2327f3964b6646c1d00165/analysis/

(I use ESET-NOD32)


P.S.
I just reported to:

Ad-Aware / Lavasoft
http://lavasoft.com/support/securitycenter/report_false_positives.php

BitDefender
http://www.bitdefender.com/site/Main/automaticSampleUploader/

G DATA
https://su.gdatasoftware.com/us/sample-submission/


The following:

http://boinc2.ssl.berkeley.edu/beta/download/setiathome_7.06_windows_intelx86__opencl_intel_gpu_sah.exe

False Positive - Gen:Variant.Fosniw.1

https://www.virustotal.com/en/file/0e3e5d238a68c92965fe38ad7d881406b4f511455b2327f3964b6646c1d00165/analysis/

BitDefender is in fault - all Antiviruses that (Falsely) reported "Gen:Variant.Fosniw" are using the BitDefender engine/signatures



*** I get the links from this List of links to report to Antivirus vendors:
http://www.techsupportalert.com/content/how-report-malware-or-false-positives-multiple-antivirus-vendors.htm

Use Ctrl+F for Avast and you'll find:
http://www.avast.com/contact-us.php?subject=VIRUS-FILE
 


- ALF - "Find out what you don't do well ..... then don't do it!" :)
 
ID: 1683658 · Report as offensive
Profile BilBg
Volunteer tester
Avatar

Send message
Joined: 27 May 07
Posts: 3720
Credit: 9,385,827
RAC: 0
Bulgaria
Message 1683722 - Posted: 24 May 2015, 15:20:28 UTC - in response to Message 1683658.  

I also reported to Avast
https://support.avast.com/Tickets/Ticket/View/WSJ-428-96444

I will not bother to fix the:
"McAfee - Artemis"
"TrendMicro-HouseCall - TROJ_GEN"
"Symantec reputation - Suspicious.Insight" (on [Additional information] tab)

... as I find them stupid (these show on almost anything)
 


- ALF - "Find out what you don't do well ..... then don't do it!" :)
 
ID: 1683722 · Report as offensive
Profile BilBg
Volunteer tester
Avatar

Send message
Joined: 27 May 07
Posts: 3720
Credit: 9,385,827
RAC: 0
Bulgaria
Message 1684996 - Posted: 28 May 2015, 5:16:39 UTC - in response to Message 1683722.  
Last modified: 28 May 2015, 6:13:17 UTC

Avast fixed it:
https://www.virustotal.com/en/file/0e3e5d238a68c92965fe38ad7d881406b4f511455b2327f3964b6646c1d00165/analysis/

Now to see when BitDefender will.


Submitted also to:

F-Secure
https://analysis.f-secure.com/portal/login.html

MicroWorld-eScan
http://support.mwti.net/support/index.php
 


- ALF - "Find out what you don't do well ..... then don't do it!" :)
 
ID: 1684996 · Report as offensive
Profile BilBg
Volunteer tester
Avatar

Send message
Joined: 27 May 07
Posts: 3720
Credit: 9,385,827
RAC: 0
Bulgaria
Message 1685367 - Posted: 28 May 2015, 23:30:24 UTC - in response to Message 1684996.  

OK, BitDefender is fixed (which fixes also 6-7 Antiviruses depending on it)

If somebody uses one of the remaining (McAfee, Ikarus, Norman, ...) - you already have enough info to know what to do ...
 


- ALF - "Find out what you don't do well ..... then don't do it!" :)
 
ID: 1685367 · Report as offensive
Profile BilBg
Volunteer tester
Avatar

Send message
Joined: 27 May 07
Posts: 3720
Credit: 9,385,827
RAC: 0
Bulgaria
Message 1685919 - Posted: 30 May 2015, 5:11:33 UTC

ID: 1685919 · Report as offensive

Questions and Answers : Windows : Malware Alert from Avast AV Software on Win 8.1


 
©2024 University of California
 
SETI@home and Astropulse are funded by grants from the National Science Foundation, NASA, and donations from SETI@home volunteers. AstroPulse is funded in part by the NSF through grant AST-0307956.