Author Topic: Not Really Sure  (Read 2943 times)

0 Members and 1 Guest are viewing this topic.

dokgu

  • Guest
Not Really Sure
« on: November 23, 2013, 06:37:30 PM »
Hi,

I've recently opened a file (.exe) which I suspect to have viruses or malwares or spywares. Before opening it though, I scanned it with Avast and it turn out to be a safe file. After opening it I noticed that when I open a third-party application to view my Windows startup, I see 2 records for Avast. One is the normal one that I usually see:

"C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui

Then the second one which I have just seen today is:

C:\Program Files\AVAST Software\Avast\setup\emupdate\ecb548a0-1048-4af1-adcf-ecd65c483280.exe /check

To me this is weird, but it is registered as one of Avast files. So I was wondering if this file is really a legitimate Avast file or has the file been injected maliciously? Thanks!

For now, I will disable this startup entry until I get an answer.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37585
  • Not a avast user
Re: Not Really Sure
« Reply #1 on: November 23, 2013, 06:47:20 PM »
Quote
I've recently opened a file (.exe) which I suspect to have viruses or malwares or spywares.  
Then why did you not check it first?    www.virustotal.com  /  www.jotti.org  /  www.metascan-online.com


Belongs to avast update...

dokgu

  • Guest
Re: Not Really Sure
« Reply #2 on: November 23, 2013, 06:54:22 PM »
Quote
I've recently opened a file (.exe) which I suspect to have viruses or malwares or spywares.   
Then why did you not check it first?    www.virustotal.com  /  www.jotti.org  /  www.metascan-online.com


Belongs to avast update...

Like I said on my question:

Quote
Before opening it though, I scanned it with Avast and it turn out to be a safe file.

I didn't know I had to do more steps.
Funny because I have never seen it before. I always check my Windows startup regularly.

Ok, so this is a safe file that I can re-enable for my Windows startup?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Not Really Sure
« Reply #3 on: November 23, 2013, 06:56:38 PM »
It appears to have been added via the latest VPS update

dokgu

  • Guest
Re: Not Really Sure
« Reply #4 on: November 23, 2013, 06:58:25 PM »
Ok thanks! I can finally breathe now.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37585
  • Not a avast user
Re: Not Really Sure
« Reply #5 on: November 23, 2013, 07:02:39 PM »
No security programhave100% detection ....
So test downloaded files on VT before you run them.... then you test with 40+ malware scanners