Author Topic: aswMBR false positive?  (Read 1795 times)

0 Members and 1 Guest are viewing this topic.

zapster

  • Guest
aswMBR false positive?
« on: April 02, 2012, 12:02:15 AM »
aswMBR with the latests virus def update is reporting two infections:

20:10:51.046    File: C:\Documents and Settings\gandolph\Local Settings\Application Data\Google\Update\1.3.21.111\GoogleCrashHandler.exe  **INFECTED** Win32:Malware-gen

20:10:51.218    File: C:\Documents and Settings\gandolph\Local Settings\Application Data\Google\Update\1.3.21.111\GoogleUpdate.exe  **INFECTED** Win32:Trojan-gen

When I run them through virustotal.com only ByteHero finds and infection (even the Avast engine reports clean).

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: aswMBR false positive?
« Reply #1 on: April 02, 2012, 12:04:55 AM »
aswMBR looks at the files slightly differently as it is more concerned with a rootkit/bootkit type infections, so the parameters are slightly different

If the standard Avast scan checks them out OK then they should be good