Author Topic: "C:\\Windows\Setup\SCRIPTS\VLD.exe|>[UPX] Threat: Win32:Dropper" false positive?  (Read 2237 times)

0 Members and 2 Guests are viewing this topic.

otarks

  • Guest
I was looking through my scan logs and four days ago during one of my daily full system scans, avast flagged the following:

C:\\Windows\Setup\SCRIPTS\VLD.exe|>[UPX]
C:\\Windows\Setup\SCRIPTS\Activation Report.exe|>VLD.exe|>[UPX]

as:

Threat: Win32:Dropper-gen [Drp]

I took no action and did not notice until now (silent mode is on, need to make it where it pops up with the results after a scan though...)

Anyway, four subsequent full system scans picked up nothing, and a boot-time scan I ran a few minutes ago shows nothing. MBAM is running a full system scan as I type.


Virustotal for C:\\Windows\Setup\SCRIPTS\VLD.exe|>[UPX]: https://www.virustotal.com/en/file/dc7c712bdaac9b3f9d480c15d6cf801f8084be8d1535d0f926e72bfc4bf6367f/analysis/1395511289/

(I may have deleted the other file in a momentary laps of basic mental capacity....)


Likely a False positive that has already been fixed or should I start pulling logs?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
False Positive   
First submission 2007-12-21 09:11:03 UTC ( 6 years, 3 months ago )

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
You can report it using one of these options......you may add a link to this topic in case they reply here


You can upload files and report issues to avast  here : http://www.avast.com/contact-form.php  (select subject according to Your case)

You can use mail
send to virus@avast.com in a password protected zip file
mail subject:  False Positive / undetected sample (select subject according to your case)
zip password:  infected

or you can send files from avast chest
how to use the chest.    http://www.avast.com/faq.php?article=AVKB21


otarks

  • Guest
thanks for the heads up and will do.

Offline jefferson sant

  • Starting Graphoman
  • *
  • Posts: 6669
  • volunteer
thanks for the heads up and will do.

was been fixed in update VPS 140322-1.