Avast WEBforum

Consumer Products => Avast Free Antivirus / Premium Security (legacy Pro Antivirus, Internet Security, Premier) => Topic started by: avast.nospam4sba on March 30, 2019, 07:05:35 AM

Title: Avast keeps moving PowerShell.exe to the chest even with exclusion
Post by: avast.nospam4sba on March 30, 2019, 07:05:35 AM
Hi,

Since yesterday Avast has made Visual Studio Code unusable because its "Behavior Shield" triggers a "IDP.HELU.PSE16 - Fileless malware" -- see screenshot.

Adding an exclusion for C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe doesn't help.

I'll have to live with disabling the "Behavior Shield" for now, but given that PowerShell.exe is a critical part of Windows and of my developer work, I'd like a fix ASAP.
 
Title: Re: Avast keeps moving PowerShell.exe to the chest even with exclusion
Post by: Asyn on March 30, 2019, 08:12:08 AM
You can report a suspected FP (File/Website) here: https://www.avast.com/false-positive-file-form.php
Title: Re: Avast keeps moving PowerShell.exe to the chest even with exclusion
Post by: avast.nospam4sba on March 30, 2019, 08:15:43 AM
Already done before I posted here. Note that this is "fileless" FP IOW Avast doesn't think the file contains malware, but that it behaves strangely.
Title: Re: Avast keeps moving PowerShell.exe to the chest even with exclusion
Post by: PDI on March 30, 2019, 09:07:58 AM
Hi avast.nospam4sba,

please send us the support package https://support.avast.com/en-eu/article/Submit-support-file and post the Ticket ID into this post.

Thanks,
PDI
Title: Re: Avast keeps moving PowerShell.exe to the chest even with exclusion
Post by: avast.nospam4sba on March 30, 2019, 09:50:47 AM
The tool fails with "Cannot generate support file, error code: 12002".

Tried a second time, same error.

[Update: could be linked to my Orange Livebox's firewall that IIRC blocks FTP; I've contacted Avast support directly and provided them with the files]
Title: Re: Avast keeps moving PowerShell.exe to the chest even with exclusion
Post by: tpnorton on March 30, 2019, 01:36:04 PM
I am seeing the exact same behaviour with Visual Studio Code and Powershell.exe

Avast says its put powershell.exe in the virus vault - but it has not - exclusions dont work either

VSC - becomes unusable

Disabling Behaviour Shield - does "fix" the problem
Title: Re: Avast keeps moving PowerShell.exe to the chest even with exclusion
Post by: jnewby72 on April 02, 2019, 04:29:51 AM
I can vouch for this behavior as well.

The "offending cmdlet" or script is part of the powershell extension for Visual Studio Code.

Thanks,
Jody
Title: Re: Avast keeps moving PowerShell.exe to the chest even with exclusion
Post by: LesF on April 03, 2019, 10:02:43 AM
It also blocks installation of Visual Studio 2019 Community.
Just what I didn't need, a hung up halfway installation.

Title: Re: Avast keeps moving PowerShell.exe to the chest even with exclusion
Post by: Pondus on April 03, 2019, 10:29:01 AM
It also blocks installation of Visual Studio 2019 Community.
Just what I didn't need, a hung up halfway installation.
Does avast give a message, if so what does it say? ... screenshot


Title: Re: Avast keeps moving PowerShell.exe to the chest even with exclusion
Post by: avast.nospam4sba on April 03, 2019, 10:22:57 PM
Avast support reports that the fix was included in VPS version 190402-02.

I'm currently running 190304-4 and can't repro the issue anymore.
Title: Re: Avast keeps moving PowerShell.exe to the chest even with exclusion
Post by: Chrispy5 on May 11, 2019, 07:08:18 PM
I can confirm that I received the same message (only once) when installing Visual Studio 2019 Community today.
Program version: 19.4.2374
Virus definitions: 190511-2

The difference for me is that the installation didn't stop, but completed successfully!
Title: Re: Avast keeps moving PowerShell.exe to the chest even with exclusion
Post by: Asyn on May 11, 2019, 07:10:30 PM
See Reply #3.
Title: Re: Avast keeps moving PowerShell.exe to the chest even with exclusion
Post by: Chrispy5 on May 11, 2019, 07:50:07 PM
I'm afraid I can't as my Avast is a free version.
Title: Re: Avast keeps moving PowerShell.exe to the chest even with exclusion
Post by: Asyn on May 11, 2019, 07:51:24 PM
I'm afraid I can't as my Avast is a free version.
Sure you can, follow instructions: https://support.avast.com/article/33/ and post your File-ID here afterwards.
Title: Re: Avast keeps moving PowerShell.exe to the chest even with exclusion
Post by: Chrispy5 on May 11, 2019, 09:25:02 PM
OK, here goes...

File ID: LVE04

Got confused because it asked me to go to the support portal to get a "Ticket ID".

Hope this helps.
Title: Re: Avast keeps moving PowerShell.exe to the chest even with exclusion
Post by: WhiteHat on January 06, 2020, 03:42:20 PM
Hi

Has anyone solved this problem yet?

I've a powershell script in which I have to store a password (I know this is unsafe, but there is no way around). For this reason I am obfuscating it, for at least a minimum of security. Additionally, I have to make a workaround by calling it from a batch script, otherwise it doesn't works correctly.

And sometimes if the script gets run, avast says that powershell.exe has been moved to virus container. I've already set exclusions for the scripts and the powershell file, but avast seems to constantly ignore this. And also if I'm looking into the virus chest, there is no new file, but powershell doesn't work any more until I reboot my system.

So is there any way to tell avast to leave my files alone exept disabling behaviour shield? I'd really like to avoid that.

Thanks for your help :)

Greetings
WhiteHat