Author Topic: Possible false positive.  (Read 3435 times)

0 Members and 1 Guest are viewing this topic.

mrpbrown

  • Guest
Possible false positive.
« on: November 11, 2008, 08:47:35 PM »
I was attempting to download ZModeler 1.07 from the official site, and got a warning that it was infected with Win32:DelAll-J [trj].

I would think this to be unlikely, so you may want to have a quick look into it. For reference, the download site is: http://www.zmodeler2.com/?mode=dl&ID=3.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89286
  • No support PMs thanks
Re: Possible false positive.
« Reply #1 on: November 11, 2008, 09:44:23 PM »
You could pause the web shield, that would at least allow you to download it (don't execute the file), the standard shield will alert, choose No action so that it remains where you downloaded it to.

You could also check the offending/suspect file at: VirusTotal - Multi engine on-line virus scanner and report the findings here. You can't do this with the file securely in the chest, you need to extract it to a temporary (not original) location first, see below.

Create a folder called Suspect in the C:\ drive, e.g. C:\Suspect. Now exclude that folder in the Standard Shield, Customize, Advanced, Add, type (or copy and paste) C:\Suspect\* That will stop the standard shield scanning any file you put in that folder. You should now be able to export any file in the chest (or move from where you saved it) to this folder and upload it to VirusTotal without avast alerting.

If it is indeed a false positive, see http://forum.avast.com/index.php?topic=34950.msg293451#msg293451, how to report it to avast! and what to do to exclude them until the problem is corrected.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

mrpbrown

  • Guest
Re: Possible false positive.
« Reply #2 on: November 12, 2008, 11:36:30 AM »
According to VirusTotal, several AVs recognise it as malware: http://www.virustotal.com/analisis/b79da218070747f9f944768b7dd17173

I still think this is pretty unlikely, it is one of the biggest free 3D modelling apps out there. I'll email it to avast and see what they say.

Offline misak

  • Moderator
  • Sr. Member
  • *
  • Posts: 234
    • Personal page (CZE)
Re: Possible false positive.
« Reply #3 on: November 12, 2008, 03:26:06 PM »
False positive is fixed in VPS 081112-0

mrpbrown

  • Guest
Re: Possible false positive.
« Reply #4 on: November 12, 2008, 10:35:43 PM »
Thanks, that was incredibly quick.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89286
  • No support PMs thanks
Re: Possible false positive.
« Reply #5 on: November 12, 2008, 11:15:10 PM »
They do act quickly when a false positive is confirmed, but less than 24 hours is quite quick.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security