Author Topic: How can I tell if an infected file is potential malware or a false positive?  (Read 8014 times)

0 Members and 1 Guest are viewing this topic.

NeymarMessi

  • Guest
I'm trying to submit a file and I have to put the type down but I don't know how to tell whether it's potential malware or a false positive... Help please?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
upload suspicious files at www.virustotal.com and test with 40+ malware scanners

alternative.   www.metascan-online.com   /   www.jotti.org

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76016
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

NeymarMessi

  • Guest
upload suspicious files at www.virustotal.com and test with 40+ malware scanners

alternative.   www.metascan-online.com   /   www.jotti.org

Okay thank you very much, and also when it tells me to select a file to scan I don't know which one it is, so how do I know which one it is I need to select?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Quote
Okay thank you very much, and also when it tells me to select a file to scan I don't know which one it is, so how do I know which one it is I need to select?
if you dont know what file you want to send..... how can we know.   ???

what is your problem exactly?



NeymarMessi

  • Guest
Quote
Okay thank you very much, and also when it tells me to select a file to scan I don't know which one it is, so how do I know which one it is I need to select?
if you dont know what file you want to send..... how can we know.   ???

what is your problem exactly?

Well I have an infected file, I put it in the chest yesterday, ran a boot scan as recommended by avast, and I wanted to submit it to the virus lab. So how can I tell which file it is? Is it the Name, Original Location, Virus Description? And also should I repair or delete it? And if so, when should I do one of these? Sorry for all these questions, I'm obviously not good at these kinds of things.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
if avast already detected it and moved it to chest....why do you want to send it to the virus lab?

do you think the detection is wrong?..... if so you can send the file from virus chest

how to use the chest.   http://www.avast.com/faq.php?article=AVKB21


Quote
And also should I repair or delete it? And if so, when should I do one of these?
Clean, Quarantine, or Delete?
http://antivirus.about.com/b/2007/03/11/clean-quarantine-or-delete.htm



NeymarMessi

  • Guest
if avast already detected it and moved it to chest....why do you want to send it to the virus lab?

do you think the detection is wrong?..... if so you can send the file from virus chest

how to use the chest.   http://www.avast.com/faq.php?article=AVKB21


Quote
And also should I repair or delete it? And if so, when should I do one of these?
Clean, Quarantine, or Delete?
http://antivirus.about.com/b/2007/03/11/clean-quarantine-or-delete.htm

Oh so that's what it's for? Okay and is the original location what I should put in the virustotal.com thing? I can't really find it, if I post the original location, can you help me find it?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
when the file is moved to chest it is not at the orginal location anymore....avast has it in virus prison where it can do no harm

Quote
The avast! Virus Chest is a safe and completely isolated place, or a 'quarantine' area in other words, for storing potentially harmful files away from the rest of the operating system. Files inside the Virus Chest are not accessible for any outside process, software application or virus and also cannot be run there. If you double-click a file, by accident or otherwise, you will not run it. Instead, the file properties will be displayed. This is a simple safety feature to prevent infected files being run accidentally and potentially causing damage to your computer. There is no danger in storing files there. Using the Virus Chest is described in the following sections:

if you open the virus chest, then you will see the file there
there you can see the orginal location.... the file name.... and the malware name avast gave it
are you able to post that info, or attach a screenshot?





NeymarMessi

  • Guest
when the file is moved to chest it is not at the orginal location anymore....avast has it in virus prison where it can do no harm

Quote
The avast! Virus Chest is a safe and completely isolated place, or a 'quarantine' area in other words, for storing potentially harmful files away from the rest of the operating system. Files inside the Virus Chest are not accessible for any outside process, software application or virus and also cannot be run there. If you double-click a file, by accident or otherwise, you will not run it. Instead, the file properties will be displayed. This is a simple safety feature to prevent infected files being run accidentally and potentially causing damage to your computer. There is no danger in storing files there. Using the Virus Chest is described in the following sections:



if you open the virus chest, then you will see the file there
there you can see the orginal location.... the file name.... and the malware name avast gave it
are you able to post that info, or attach a screenshot?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
seems to be a banker trojan detected in a restore point.....


NeymarMessi

  • Guest
seems to be a banker trojan detected in a restore point.....

what does that mean??

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Banker Trojan
Quote
In computer and network security terminology, a Banker Trojan-horse (commonly called Banker Trojan) is a malicious program used in an attempt to obtain confidential information about customers and clients using online banking and payment systems.


restore point
http://pcsupport.about.com/od/termsr/g/restore-point.htm




NeymarMessi

  • Guest
Banker Trojan
Quote
In computer and network security terminology, a Banker Trojan-horse (commonly called Banker Trojan) is a malicious program used in an attempt to obtain confidential information about customers and clients using online banking and payment systems.


restore point
http://pcsupport.about.com/od/termsr/g/restore-point.htm

Alright so how do I find it?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
find what?