Author Topic: "Win32:Malware-gen" found in "clt.exe  (Read 9811 times)

0 Members and 1 Guest are viewing this topic.

Nosnibor

  • Guest
"Win32:Malware-gen" found in "clt.exe
« on: February 27, 2010, 05:46:45 PM »
As you can see by the included pix the Screen Saver Scan  has detected "Win32:Malware-gen"  in 8 different places.

The detection of clt.exe  i assume is a false positive.

The items found in "System Volume Information\_restore"  i am unsure about.

PLEASE HELP
« Last Edit: February 28, 2010, 01:25:31 AM by Nosnibor »

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89219
  • No support PMs thanks
Re: 8 "Win32:Malware-gen" found
« Reply #1 on: February 27, 2010, 06:22:00 PM »
I would say the the clt.exe is a good detection as its purpose is to circumvent the firewall, how is avast to know it is a tool, you know that, avast can't determine intent. Put such tools in one folder and exclude it from scans.

- Infected Restore Points - There really is little benefit in chasing a detection in the system volume information folder. It is only there because it had previously been deleted or moved from the system folders and this is a back-up created by system restore.
 
- Worst case scenario it isn't infected and you delete it/move it to the chest, you can't use that restore point in the future, not much of a loss and the older the restore point is the less of an issue it is.
 
- So if there is any suspicion about a restore point then it is best removed from the system volume information folder or it could bite you in the rear at some point in the future when you use system restore if it included that restore point.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Asian

  • Guest
Re: 8 "Win32:Malware-gen" found
« Reply #2 on: February 27, 2010, 06:26:24 PM »
I'm getting the same exact thing. It's a FALSE POSTIVE, as I think. It makes no sense.. iTunes as malware? Or even a CCleaner setup was thought to be malware.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89219
  • No support PMs thanks
Re: 8 "Win32:Malware-gen" found
« Reply #3 on: February 27, 2010, 06:49:15 PM »
You haven't got exactly the same thing unless the detection is on clt.exe.

You have got the same malware name detection, I presume. I have CCleaner on my system and no detection on its setup file, see image, though I use the one without the toolbar (slim) as part of the installation. I don't use itunes so can't say.

You could also check the offending/suspect file at: VirusTotal - Multi engine on-line virus scanner and report the findings here the URL in the Address bar of the VT results page. You can't do this with the file securely in the chest, you need to extract it to a temporary (not original) location first, see below.

- Create a folder called Suspect in the C:\ drive. Now exclude that folder in the File System Shield, Expert Settings, Exclusions, Add, type (or copy and paste) C:\Suspect\* That will stop the File System Shield scanning any file you put in that folder. Now enter the chest again and Extract the file to the Suspect folder and upload it to VT.

« Last Edit: February 27, 2010, 06:56:42 PM by DavidR »
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Nosnibor

  • Guest
Re: 8 "Win32:Malware-gen" found
« Reply #4 on: February 27, 2010, 07:02:36 PM »
Ok so when i add an item to the exclude list do i need to do a exclue in every scan mode such as "Screen Saver Scan" and "Scan from Windows Explorer" and "Full system scan" to make the exclude Fully efective  ???

Ok so "System Volume Information\_ restore"  refres to "System Restore" points and can be safely removed ???

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89219
  • No support PMs thanks
Re: "Win32:Malware-gen" found in System Volume Information\_restore
« Reply #5 on: February 27, 2010, 09:18:23 PM »
From the settings, Exclusions it says it applies to all scans, and a small test would confirm your question. That as it what it seems to do.

I wouldn't have suggested it if it weren't safe.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Nosnibor

  • Guest
Re: "Win32:Malware-gen" found in System Volume Information\_restore
« Reply #6 on: February 28, 2010, 12:14:31 AM »
From the settings, Exclusions it says it applies to all scans, and a small test would confirm your question. That as it what it seems to do.

I wouldn't have suggested it if it weren't safe.

Ok thanks. The System Volume Information Restore issue has been resolved.
In regardes to the exclusion issue with "clt.exe" i put it in exclusion under Main Settings and it does not detect it in "Quick Scan" & "Full systen scan" & "Select folder to scan" & "Scan from Windows Explorer" & "Screen saver scan"  but  it does still show up as a detection when i use "Boot Scan"

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89219
  • No support PMs thanks
Re: "Win32:Malware-gen" found in System Volume Information\_restore
« Reply #7 on: February 28, 2010, 01:07:18 AM »
Well I would say that since the boot-time scan is outside of windows it may not be covered, though I would have thought it would.

Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Nosnibor

  • Guest
Re: "Win32:Malware-gen" found in System Volume Information\_restore
« Reply #8 on: February 28, 2010, 01:24:51 AM »
Well I would say that since the boot-time scan is outside of windows it may not be covered, though I would have thought it would.



WOO HOO i found a bug :) What do i win lol
I agree that it should  be included!
how do i now forward this bug info  to the powers to be?
« Last Edit: February 28, 2010, 01:26:51 AM by Nosnibor »

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89219
  • No support PMs thanks
Re: "Win32:Malware-gen" found in "clt.exe
« Reply #9 on: February 28, 2010, 02:09:48 AM »
I don't know whether you would call it a bug, which is why I said "I would say that since the boot-time scan is outside of windows it may not be covered," so I don't know if it is by design or not.

I can't recall if there was an option in the 4.8 boot-time scan advanced settings to exclude files/folders or not. That option I can't see in the 5.0 boot-time settings only being able to select what to scan (selective area) not what not to scan.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Nosnibor

  • Guest
Re: "Win32:Malware-gen" found in "clt.exe
« Reply #10 on: February 28, 2010, 02:19:17 AM »
I do think it is a bug with v5 as when i used v4.8 it did not detect "clt.exe" as malware.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89219
  • No support PMs thanks
Re: "Win32:Malware-gen" found in "clt.exe
« Reply #11 on: February 28, 2010, 02:27:27 AM »
Because 4.8 didn't detect clt.exe and avast 5.0 does means nothing as, a) both virus definitions databases differ and b) new signatures or updating existing signatures happen all the time. So it is entirely possible that files that weren't previously detected are now.

In any case a false detection if it were so isn't a bug, that is a failing in the program code and not its detections.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Nosnibor

  • Guest
Re: "Win32:Malware-gen" found in "clt.exe
« Reply #12 on: February 28, 2010, 09:04:25 PM »
From the settings, Exclusions it says it applies to all scans, and a small test would confirm your question. That as it what it seems to do.

I wouldn't have suggested it if it weren't safe.

Ok thanks. The System Volume Information Restore issue has been resolved.
In regardes to the exclusion issue with "clt.exe" i put it in exclusion under Main Settings and it does not detect it in "Quick Scan" & "Full systen scan" & "Select folder to scan" & "Scan from Windows Explorer" & "Screen saver scan"  but  it does still show up as a detection when i use "Boot Scan"

CORRECTION -- the exclusion option under main settings  Does NOT work  I put clt.exe  in main settings under exculions using the correct path  but avast v5 still  detects it as bad and moves it to the virus chest.  Because this item is still being detected as bad even though i put it in main settings under exclusions it IS A PROGRAM BUG

Nosnibor

  • Guest
Re: "Win32:Malware-gen" found in "clt.exe
« Reply #13 on: February 28, 2010, 09:06:05 PM »
Please close this thread as i'm going to post it in  bug report
« Last Edit: February 28, 2010, 09:07:49 PM by Nosnibor »

Jahn

  • Guest
Re: "Win32:Malware-gen" found in "clt.exe
« Reply #14 on: March 01, 2010, 03:25:30 AM »
clt.exe is no longer detected in vps 100228-1