Author Topic: Strange detection  (Read 2454 times)

0 Members and 1 Guest are viewing this topic.

Dch48

  • Guest
Strange detection
« on: August 01, 2011, 12:46:10 PM »
I was away from my new computer for a while and it went into sleep mode. When I came back and awakened it, I saw an Avast virus detection popup and the computer said it was locked and required my password to get back in. I tried to send the file, a PUP according to Avast, to the chest but it wouldn't do it. I did not want to delete it so I chose to block it. I then did a right click scan of the file with both MBAM and Avast, and they said it was clean. I uploaded it to Virus Total and even though 6 of the scanners detected it as something, the community there rated it completely safe and a part of HP's default installations.

http://www.virustotal.com/file-scan/report.html?id=0dfc621ceda95d297c34951272311e1f7f433d07810da65b233bf7241ada68ad-1312192231

It is also in my log for the File System Shield.

 

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76033
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Strange detection
« Reply #1 on: August 01, 2011, 12:50:46 PM »
Any questions..?
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Dch48

  • Guest
Re: Strange detection
« Reply #2 on: August 01, 2011, 12:58:36 PM »
Any questions..?
I just thought Avast might be interested in what is obviously a false detection.

Maybe I should put it in exclusions?

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76033
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Strange detection
« Reply #3 on: August 01, 2011, 01:01:26 PM »
Any questions..?
I just thought Avast might be interested in what is obviously a false detection.

I see.
Btw, it's not a false detection. It's still a PUP.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76033
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Strange detection
« Reply #4 on: August 01, 2011, 01:03:53 PM »
Maybe I should put it in exclusions?

Ah, a question at last. ;)
Yes, you can do so, or disable PUP scanning in avast.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Re: Strange detection
« Reply #5 on: August 01, 2011, 01:53:40 PM »
Hi Dch48,

My good friend, did you check your version of it against this: http://www.backgroundtask.eu/Systeemtaken/taakinfo/42800/EndProcess.exe/
As it is being considered a PUP, we searched for MD5: fb9f5efc10280f3659dce48069725c3c
The file has no own spreading routine, it is a low risk, low distribution potential and has low damage potential. The only malcious use here you could think of is that it could be used by rogue users or malware to lower security settings. What this potential comes down to can be found here:
http://www.threatexpert.com/report.aspx?md5=fb9f5efc10280f3659dce48069725c3c
Still being detected as PUP. You could upload and report it here as well:
https://www.webimmune.net/default.asp  but they will have a reason to keep it in their database.
I would not worry about it now as you have checked your version and know it will do no further harm and know why it is there and what it does - it is the Factory Reset Application of HP and running as a background task. As far as has been established in this thread this EndProcess.exe is a safe one,

polonus
« Last Edit: August 01, 2011, 01:56:13 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!