Author Topic: OTL.exe False Positive?  (Read 2779 times)

0 Members and 1 Guest are viewing this topic.

HaterOfViruses

  • Guest
OTL.exe False Positive?
« on: August 14, 2012, 06:22:41 AM »
Hi

New user here and just wanted a wee bit of info if possible.

I was running an anti-malware program for a usual check and then my avast! virus alert popped up about a file - OTL.exe - saying that it was a virus.  I have it stored in the Virus Chest at the moment and when I right-click on it and select Scan it reports it as Win32: Malware Gen.  The location of the file is c:\crcleanup\OTL

This is the first time this file has ever came up and I am wondering if it's a false positive.  I had a search to see if it was but couldn't really see anything (either that or I have just missed it  ;D)

I'm a bit wary of restoring the file just incase it IS a virus, so any information would be helpful.

Thanks.

Offline DJBone

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6366
Re: OTL.exe False Positive?
« Reply #1 on: August 14, 2012, 06:55:48 AM »
Hello and welcome to the forum! :)

You can check the file here: https://www.virustotal.com/

DJBone
Win10 x64, APS (always latest version)
Avast Mobile Security (always latest version)

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: OTL.exe False Positive?
« Reply #2 on: August 14, 2012, 08:48:14 AM »
if this is the OTL analysis tool   http://www.geekstogo.com/forum/files/file/398-otl-oldtimers-list-it/
then this happens sometimes when they release a new version...
there is no danger in deleteing it as you download the new when you need it

HaterOfViruses

  • Guest
Re: OTL.exe False Positive?
« Reply #3 on: August 14, 2012, 08:20:15 PM »
Thanks for the information guys   :D

I'm pretty sure it's the OTL analysis tool that you highlighted, Pondus, so I just decided to delete the file.  I tried restoring the file so I could scan it using the link that DJBone gave me but avast! just bangs it right back into the Virus Chest again.

Thanks again.