Author Topic: Help! Shockwave virus or possible false positive  (Read 8486 times)

0 Members and 1 Guest are viewing this topic.

EagleGhost

  • Guest
Help! Shockwave virus or possible false positive
« on: December 27, 2010, 05:27:58 PM »
I ran Avast virus check today and it found a virus called "Win32:Malware-gen" from the "C:\Windows\SysWOW64\Adobe\Shockwave 11\Xtras\Multiusr.x32" path. Yesterday Avast found nothing. Today the Facebook frore when I was watching my friend's pictures. Is that involved with this? I have heard that the viruses can spread through Facebook picture albums. Now I'm really worried about this. Is this a real virus or a false positive?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Help! Shockwave virus or possible false positive
« Reply #1 on: December 27, 2010, 05:30:43 PM »
Quote
Is this a real virus or a false positive?
Upload the file to www.virustotal.com and test it with 43 malware scanners
when you have the result, copy the URL in the address bar and post it here


you may also scan your computer with this

Malwarebytes Anti-Malware 1.50.1   http://filehippo.com/download_malwarebytes_anti_malware/
always update the program before you scan, so you have the latest database
click the remove selected button to quarantine anything found
if anything is found please post the scan log here
 
« Last Edit: December 27, 2010, 05:36:26 PM by Pondus »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Help! Shockwave virus or possible false positive
« Reply #2 on: December 27, 2010, 05:36:07 PM »
Quote
Is this a real virus or a false positive?
Upload the file to www.virustotal.com and test it with 43 malware scanners
when you have the result, copy the URL in the address bar and post it here

He reposted it here...
http://forum.avast.com/index.php?topic=68311.msg574374#msg574374
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

EagleGhost

  • Guest
Re: Help! Shockwave virus or possible false positive
« Reply #3 on: December 27, 2010, 05:43:55 PM »
Quote
Is this a real virus or a false positive?
Upload the file to www.virustotal.com and test it with 43 malware scanners
when you have the result, copy the URL in the address bar and post it here


you may also scan your computer with this

Malwarebytes Anti-Malware 1.50.1   http://filehippo.com/download_malwarebytes_anti_malware/
always update the program before you scan, so you have the latest database
click the remove selected button to quarantine anything found
if anything is found please post the scan log here
 


Here is the Virustotal report: http://www.virustotal.com/file-scan/report.html?id=a076220ea59e457b23588b24edc034b8f3ca7f68c7c4f74c8f761bbe6266f0e9-1293467657. I will post the Malwarebytes report later. I'm sorry for the double post. I don't like my mother tongue teacher, because she should have taught me better. ;)

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Help! Shockwave virus or possible false positive
« Reply #4 on: December 27, 2010, 06:05:07 PM »
only detected by avast! and GData using avast virus engine, so this can be a False Positive

send the file in a password protected zip.file to  virus @ avast . com
Subject: False positive   Password: infected

you may add a link to this topic in the mail

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Help! Shockwave virus or possible false positive
« Reply #5 on: December 27, 2010, 06:09:25 PM »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: Help! Shockwave virus or possible false positive
« Reply #6 on: December 27, 2010, 06:13:35 PM »
Or - Send the sample to avast as a False Positive:
Open the chest and right click on the file and select 'Submit to virus lab...' complete the form and submit, the file will be uploaded during the next update.

- In the meantime (if you accept the risk), add the full path to the file to the exclusions lists:
File System Shield, Expert Settings, Exclusions, Add and
avast Settings, Exclusions

Restore it to its original location, periodically check it (scan it in the chest), there should still be a copy in the chest even though you restored it to the original location. When it is no longer detected then you can also remove it from the File System Shield and avast Settings, exclusions lists.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

EagleGhost

  • Guest
Re: Help! Shockwave virus or possible false positive
« Reply #7 on: December 27, 2010, 06:36:08 PM »
Big thanks for helping me! :) I updated Malwarebytes and ran it and it found nothing. I also sent a false positive report to Avast and they will contact me soon.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Help! Shockwave virus or possible false positive
« Reply #8 on: December 27, 2010, 06:56:39 PM »
Big thanks for helping me! :) I updated Malwarebytes and ran it and it found nothing. I also sent a false positive report to Avast and they will contact me soon.

You're welcome..!
And thanks for your feedback..!!
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2294
Re: Help! Shockwave virus or possible false positive
« Reply #9 on: December 27, 2010, 08:32:42 PM »
Hello,
it should be fixed in current VPS (101227-1).

Milos

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Help! Shockwave virus or possible false positive
« Reply #10 on: December 27, 2010, 08:35:10 PM »
Thanks for the info   ;)