Author Topic: False positive or Behaviour Shiled incompatibility?  (Read 7410 times)

0 Members and 1 Guest are viewing this topic.

Offline Bellzemos

  • Avast Evangelist
  • Poster
  • ***
  • Posts: 621
False positive or Behaviour Shiled incompatibility?
« on: October 30, 2013, 05:20:50 PM »
Hello!

Since yesterday Avast finds a FP in a game file executable (sw.exe) - Shadow Warrior (2013, GOG Edition) is the game in question (I had it installed long before and all was always fine).

The file itself has 0/47 (zero) detections on VirusTotal.com (even Avast doesn't detect it), but on my computer it says that it's a suspicious file when I try to run it and Avast blocks it so I can't use it. This is happening from the VPS update 131029-0 on (before that it was all fine). This is the name it displays when it detects it: Win32:Evo-gen [Susp].

I have sent the file to Avast submit virus mail yesterday but got no reply. The problem is still here with the new VPS update. Since Avast doesn't detect this as a virus when I manually scan it but only when I try to run it - could that mean that it's the Behaviour Shield detecting it? Mayne it's some incompatibility issue with Sandboxie instead of the VSP FP, it's possible, right?

Where can I disable Behaviour Shield in the new Avast v9 (2014)? I want to try and solve this problem ASAP.

Thank you!
Intel Core i7 Q 740 @ 1.73 GHz, 6 GB RAM, Windows 7 Ultimate x64 SP1, Avast! Free Antivirus, Malwarebytes Anti-Malware (free version) and Sandboxie (paid version).

Omega X

  • Guest
Re: False positive or Behaviour Shiled incompatibility?
« Reply #1 on: October 30, 2013, 05:53:18 PM »
I think its in Settings > Active Protection.

I've been getting too many false positives. For the first time in years I'm thinking about getting rid of AVAST.

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Re: False positive or Behaviour Shiled incompatibility?
« Reply #2 on: October 30, 2013, 06:09:52 PM »
The behavior shield is now part of the file shield. See the FAQ for more information.
What are you using for the settings? Are you using default settings?
If you are sure it's a false positive you may make the proper exclusions.
GUI>Settings>Antivirus>Exclusions  :)
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: False positive or Behaviour Shiled incompatibility?
« Reply #3 on: October 30, 2013, 06:10:15 PM »
The behavior shield as was is integrated into the file system shield. avastUI > Settings > Antivirus - scroll down to the Exclusions. The File Paths would apply to the file sustem shield and the DeepScreen and Hardened mode tabs speak for themselves.

Can you attach a screen shot of the alert window as I suspect that this may be the new functionality in the file system shield (not necessarily behavior element), possibly the hardened mode or deep screen.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Bellzemos

  • Avast Evangelist
  • Poster
  • ***
  • Posts: 621
Re: False positive or Behaviour Shiled incompatibility?
« Reply #4 on: October 30, 2013, 07:34:55 PM »


There's sadly no "Ignore" option so I had put the whole folder where the game is to Avast File Shield exclusions to be able to play the game and upload the file to Virus Total and send it to Avast team.

I don't want to have stuff in exclusions, I never needed that in older Avast versions. I'd rather turn off or change settings in the Behaviour Shiled because I suspect this being an incompatibility issue between Avast and Sandboxie.

Please help :)

PS: This si what it found during the installation of the game. I didn't want to include the game folder back because last time Avast deleted the file in question (sw.exe) and I had to reinstall the whole game.
Intel Core i7 Q 740 @ 1.73 GHz, 6 GB RAM, Windows 7 Ultimate x64 SP1, Avast! Free Antivirus, Malwarebytes Anti-Malware (free version) and Sandboxie (paid version).

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Re: False positive or Behaviour Shiled incompatibility?
« Reply #5 on: October 30, 2013, 07:53:44 PM »
If you want our malware experts to double check follow the guide here.

I say that because of your screenshot showing "Win32:Evo-Gen[Susp(icious)].
At least you will know one way or another whether is an infection or a false positive.  :)
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline Bellzemos

  • Avast Evangelist
  • Poster
  • ***
  • Posts: 621
Re: False positive or Behaviour Shiled incompatibility?
« Reply #6 on: October 30, 2013, 08:30:32 PM »
No, thank you, I'm pretty sure it's a FP:
https://www.virustotal.com/sl/file/f772bac4bf11b14b56f7132107ed3f8ce32a1d73b01b47d1084c936984c694aa/analysis/1383161309/

What I would like to know is how can I disable the Behaviour Shiled in Avast, is it possible in the new version?
Intel Core i7 Q 740 @ 1.73 GHz, 6 GB RAM, Windows 7 Ultimate x64 SP1, Avast! Free Antivirus, Malwarebytes Anti-Malware (free version) and Sandboxie (paid version).

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Re: False positive or Behaviour Shiled incompatibility?
« Reply #7 on: October 30, 2013, 08:59:50 PM »
As previously stated the behavior shield is now part of the file shield. There are "no" behavior shield settings.
As per my screenshot above you can make the proper exclusions.
GUI>Settings>Active Protection>click on the "gear" symbol.  :)
Did you read the FAQ link as I provided?  ???

Virustotal is a good start but it does not cover every possibility of malware.
For this a certified malware expert would be better equipt to assist you.
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline Bellzemos

  • Avast Evangelist
  • Poster
  • ***
  • Posts: 621
Re: False positive or Behaviour Shiled incompatibility?
« Reply #8 on: October 30, 2013, 10:46:31 PM »
I've read the part of FAQ dealing with Behaviour Shield being integrated in the File System Shield now. So the exclusion is the only way then... Well, I guess I'll have to live with that. I hope there won't be too many problems like that in the future. I still suspect the Behaviour (now File Shield) conflicting with Sandboxie.

Does it matter if I type the exclusion folder path into the Settings\Antivirus\Exclusions or into the Settings\Active Protection\File System Shield\Exclusions ?

Thank you for help! :)
Intel Core i7 Q 740 @ 1.73 GHz, 6 GB RAM, Windows 7 Ultimate x64 SP1, Avast! Free Antivirus, Malwarebytes Anti-Malware (free version) and Sandboxie (paid version).

Offline Bellzemos

  • Avast Evangelist
  • Poster
  • ***
  • Posts: 621
Re: False positive or Behaviour Shiled incompatibility?
« Reply #9 on: October 31, 2013, 01:45:09 PM »
Anyone, please? :)
Intel Core i7 Q 740 @ 1.73 GHz, 6 GB RAM, Windows 7 Ultimate x64 SP1, Avast! Free Antivirus, Malwarebytes Anti-Malware (free version) and Sandboxie (paid version).

Offline Bellzemos

  • Avast Evangelist
  • Poster
  • ***
  • Posts: 621
Re: False positive or Behaviour Shiled incompatibility?
« Reply #10 on: November 02, 2013, 07:15:02 PM »
Guess not. Well, I can only wish then that Avast and Sandboxie solve the compatibility issues sometime in the future...
Intel Core i7 Q 740 @ 1.73 GHz, 6 GB RAM, Windows 7 Ultimate x64 SP1, Avast! Free Antivirus, Malwarebytes Anti-Malware (free version) and Sandboxie (paid version).

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: False positive or Behaviour Shiled incompatibility?
« Reply #11 on: November 02, 2013, 07:26:48 PM »
Did you update to 9.0.2007 yet..??
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Bellzemos

  • Avast Evangelist
  • Poster
  • ***
  • Posts: 621
Re: False positive or Behaviour Shiled incompatibility?
« Reply #12 on: November 02, 2013, 10:24:13 PM »
I updated just now after I read your comment and THE PROBLEM IS GONE! :D

Thank you! I wonder what was that they changed that got rid of the problem, but what really matters is it's gone! I'm happy, thank you! :)
Intel Core i7 Q 740 @ 1.73 GHz, 6 GB RAM, Windows 7 Ultimate x64 SP1, Avast! Free Antivirus, Malwarebytes Anti-Malware (free version) and Sandboxie (paid version).

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: False positive or Behaviour Shiled incompatibility?
« Reply #13 on: November 02, 2013, 10:26:14 PM »
You're welcome.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0