Author Topic: New to Avast - False Positives?  (Read 5724 times)

0 Members and 1 Guest are viewing this topic.

callmeandy

  • Guest
New to Avast - False Positives?
« on: July 11, 2011, 01:21:20 PM »
1003609_realtek_5_10_0_5850.exe and hpWLPGInstaller1032.cab.....these driver files I believe to have been on my system as copies of drivers from another laptop since way back (cant be sure on the first though as I think Avast moving it to the virus chest, and my restoring it has changed the timestamps the later timestamps created/modified dates are appropriate age). The laptop is still in use. So i don't want to lose the driver copies unless absolutely the only choice. So my guess is that these are both FP's, but previous scans by avast since installing it a few days ago never never found these problems.

However is it possible that a virus could have been injected into a random file in this mannor? - seems unlikely surely that would mean it had been activated, if it could inject into one why not not 10000 files?

Is there anyway to check the validity of Avasts identified Threats on large files?. This file is to big for Jotti or Virustotal.

This is more a question in the context of ongoing practicality of using Avast than about dealing with this specific problem (i.e I am pretty sure I have the original files somewhere in this case).
My concern is that I don't have the time to spend all day, every other day, on verifying possible FP's especially when this has not been the only problem with avast - many file scans returned errors "Archive password protected (2056)" and "Reached the end of the file (38)" but those for a separate thread maybe.

I come from Avira antivir after their disastrous decision to bully users of free version into using the ask toolbar. Otherwise to be honest I would not have migrated this was a great tool without FP issues or files that could not be scanned.

ON XP SP3

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: New to Avast - False Positives?
« Reply #1 on: July 11, 2011, 01:41:06 PM »
Quote
Otherwise to be honest I would not have migrated this was a great tool without FP issues or files that could not be scanned.
Avira will also have files that can not be scanned, but it is not everyone that show it in the log
and trust me Avira also have False Positives....all AV does


what is the malware name avast give on these file(s)
« Last Edit: July 11, 2011, 01:42:48 PM by Pondus »

callmeandy

  • Guest
Re: New to Avast - False Positives?
« Reply #2 on: July 11, 2011, 06:58:29 PM »
Quote
Otherwise to be honest I would not have migrated this was a great tool without FP issues or files that could not be scanned.
Avira will also have files that can not be scanned, but it is not everyone that show it in the log
and trust me Avira also have False Positives....all AV does


what is the malware name avast give on these file(s)
Yes sorry new there was something else I meant to put in the thread:
Win32:Malware-gen and Win32:Agent-AKRR[Drp] respectivly

callmeandy

  • Guest
Re: New to Avast - False Positives?
« Reply #3 on: July 12, 2011, 10:38:34 AM »
So the focal question is still standing: Is there anyway to check the validity of Avasts identified Threats on large files?. Both files are to large for Jotti or Virustotal.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: New to Avast - False Positives?
« Reply #4 on: July 12, 2011, 02:52:02 PM »
So the focal question is still standing: Is there anyway to check the validity of Avasts identified Threats on large files?. Both files are to large for Jotti or Virustotal.

I don't think so.
Well, you could upload to their ftp-site, but I doubt that they want it full of such requests. :-\
I suggest you ask here: http://www.avast.com/contact-form.php?loadStyles
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

JoeB

  • Guest
Re: New to Avast - False Positives?
« Reply #5 on: July 12, 2011, 05:12:16 PM »
Seems that your files are infected.
Here the Realtek driver for Amilo laptop tested with Avast IS 6.0.1203 and definition 110712-0
http://www23.zippyshare.com/v/45292612/file.html

Can you give me some info regarding the HP (F2400?) driver?
« Last Edit: July 12, 2011, 05:13:58 PM by JoeB »

psw

  • Guest
Re: New to Avast - False Positives?
« Reply #6 on: July 12, 2011, 07:15:10 PM »
Results of Virustotal check of hpWLPGInstaller1032.cab can be found by Google
http://www.virustotal.com/file-scan/report.html?id=254210fb502319915af83a1d68e76893c5a45c2563455fe5447d869596b45bb2-1303834719
Avast is the only AV which was detecting something. So is it very like to FP.

JoeB

  • Guest
Re: New to Avast - False Positives?
« Reply #7 on: July 13, 2011, 05:31:40 PM »
Results of Virustotal check of hpWLPGInstaller1032.cab can be found by Google
http://www.virustotal.com/file-scan/report.html?id=254210fb502319915af83a1d68e76893c5a45c2563455fe5447d869596b45bb2-1303834719
Avast is the only AV which was detecting something. So is it very like to FP.
Still would like to know which device that driver is for.
In the above uploaded Realtek driver, Avast didn't find anything.
It could be that the OP needs to update Avast and the definition file thou.

callmeandy

  • Guest
Re: New to Avast - False Positives?
« Reply #8 on: July 14, 2011, 12:06:33 PM »
Results of Virustotal check of hpWLPGInstaller1032.cab can be found by Google
http://www.virustotal.com/file-scan/report.html?id=254210fb502319915af83a1d68e76893c5a45c2563455fe5447d869596b45bb2-1303834719
Avast is the only AV which was detecting something. So is it very like to FP.
Still would like to know which device that driver is for.
In the above uploaded Realtek driver, Avast didn't find anything.
It could be that the OP needs to update Avast and the definition file thou.

Sorry for late reply - yes its an HP D1660 printer driver!
« Last Edit: July 14, 2011, 12:08:13 PM by callmeandy »

callmeandy

  • Guest
Re: New to Avast - False Positives?
« Reply #9 on: July 14, 2011, 12:09:36 PM »
Results of Virustotal check of hpWLPGInstaller1032.cab can be found by Google
http://www.virustotal.com/file-scan/report.html?id=254210fb502319915af83a1d68e76893c5a45c2563455fe5447d869596b45bb2-1303834719
Avast is the only AV which was detecting something. So is it very like to FP.
Didnt follow you on this. VirusTotal has a 20MB file size limit. You can do something at google to get around this?