Author Topic: Calmain.exe False positive boot-time virus?  (Read 6582 times)

0 Members and 1 Guest are viewing this topic.

kayjay1

  • Guest
Calmain.exe False positive boot-time virus?
« on: October 22, 2013, 12:19:55 PM »
Hi all, another newbie here.  :)

I've just booted the pc and Avast has highlighted Calmain.exe as a boot-time virus/trojan.  I believe this is part of Canon camera software and therefore wonder if this is actually a false positive?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Calmain.exe False positive boot-time virus?
« Reply #1 on: October 22, 2013, 12:21:47 PM »
what does avast say....malware name given?

upload file to www.virustotal.com and test with 40+ malware scanners
post link to scan result here

alternatives: www.metascan-online.com / www.jotti.org





kayjay1

  • Guest
Re: Calmain.exe False positive boot-time virus?
« Reply #2 on: October 22, 2013, 12:25:20 PM »
Going to sound really stupid here but could you please tell me how do I do that?  I chose to ignore the threat rather than remove it as was suggested and now can't seem to find the original warning message.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
« Last Edit: October 22, 2013, 12:38:44 PM by Pondus »

kayjay1

  • Guest
Re: Calmain.exe False positive boot-time virus?
« Reply #4 on: October 22, 2013, 01:25:13 PM »
Okay, I hope I've done this correctly.

Here are the results, the scan showed no problems.   MD5   8ef654045e518ac00e52e7a1e2d3ad70

The last pop-up message for some reason is an Avast Tip on FB privacy although I haven't seen the 'FB privacy' pop-up show itself today.  The last pop up that was seen was the 'Calmain' virus warning.

Thank you for your help with this.  :)
« Last Edit: October 22, 2013, 01:38:09 PM by kayjay1 »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Calmain.exe False positive boot-time virus?
« Reply #5 on: October 22, 2013, 02:21:14 PM »
https://www.virustotal.com/en/file/c267aab7ca9c6d1dd49043de13211e25157aadecc8d302712bbbd6eb6f530ed9/analysis/
First submission 2009-02-17 04:42:47 UTC ( 4 years, 8 months ago )


Quote
The last pop up that was seen was the 'Calmain' virus warning.
yes...but i wanted to know what malware name avast gave the file?...guessing it was W32:Evo-gen [susp] = suspicious

anyway this seems to be a clean file   ;)


Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Calmain.exe False positive boot-time virus?
« Reply #6 on: October 22, 2013, 02:22:59 PM »
You can upload files and report issues to avast  here : http://www.avast.com/contact-form.php  (select subject according to Your case)

You can use mail
send to virus@avast.com in a password protected zip file
mail subject:  False Positive / undetected sample (select subject according to your case)
zip password:  infected

or you can send files from avast chest
how to use the chest.    http://www.avast.com/faq.php?article=AVKB21




kayjay1

  • Guest
Re: Calmain.exe False positive boot-time virus?
« Reply #7 on: October 22, 2013, 02:56:15 PM »
Hi Pondus,

Yes I do understand that you needed the name that avast gave but I cannot find it anywhere.  I did shut down the system (although it took much longer than normal) to try and re-create the problem but thus far, Avast has shown nothing.

I cannot confirm if it was W32:Evo-gen [susp] = suspicious or not.  All I know is that Avast wanted to delete the file, it didn't say anything about sending it to the virus chest which is why I told Avast to ignore it when it was highlighted.  Do you think perhaps that by taking the 'ignore' action Avast will no longer show it up as an issue?

I'm really am very sorry for my dumbness, people like me must seriously get on your nerves.  I am a true newbie at this so please forgive me. :-[  I've also just realised that I've probably put this in the wrong forum too? Ooops!!

Thanks for all your help and advice.  ;D

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Calmain.exe False positive boot-time virus?
« Reply #8 on: October 22, 2013, 03:13:12 PM »
send file to avast lab using one of the options i gave above and detection will be fixed.   ;)



kayjay1

  • Guest
Re: Calmain.exe False positive boot-time virus?
« Reply #9 on: October 22, 2013, 03:19:54 PM »
Okey dokey wll do.  :)

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Calmain.exe False positive boot-time virus?
« Reply #10 on: October 22, 2013, 03:22:51 PM »

kayjay1

  • Guest
Re: Calmain.exe False positive boot-time virus?
« Reply #11 on: October 22, 2013, 03:38:57 PM »
Yes, yes, that looks more familiar, it definitely said Rootkit I remember that now.
Rootkit. SVC:CCALib8>C:\CALMAIN.exe Name Win32:Evo-gen(susp)

Should I search for the file?

Oh dear, I've already submitted the file under the possibility of it being W32:Evo-gen [susp] = suspicious.