Author Topic: Avast Support is *very* bad  (Read 8225 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Avast Support is *very* bad
« on: August 13, 2015, 07:51:45 PM »
I've detected a false positive in an old medal of honor patch (Breakthrough_patch_2.40b.exe).

This file hasn't been modified since 10 years ago (same md5 I repeat SAME MD5 since 10 years ago), never had any issue with it and it was scanned previously by many other AV without issues ...

Therefore I've raised a ticket to support to flag this as a false positive, and an update of the definition file was eventually released to fix this.
However 2 weeks after the file was marked *again* as a threat by an update.

So I've reopened the ticket and it is going nowhere:

- first the support guy tell me the file is infected, then that it is a false positive that will be fixed in an update (there has been at least a couple of update but it is still not fixed).
- I've asked technical details about why this was flagged as a virus and what actions will be taken to not make this happens but I can get any answers ... The only thing I got is that my ticket was moved to the "private" status. Outrageous!

I'm really disappointed with the unprofessional attitude Avast support has in general, this is not the first time I've to deal with them and they are completely useless and random, I'm wondering why bother to pay a premium for support when you get this poor treatment :(

In addition I'm very worried to see how bad Avast team seems to tackle virus identification, looks like a big bullshit with very poor tests.
Looks this has become a standard in the industry unfortunately have a read here http://pid.gamecopyworld.com/


Offline Rednose

  • Pirate Party Member
  • Avast Überevangelist
  • Massive Poster
  • *****
  • Posts: 3739
  • Bits of Freedom : https://www.bof.nl
    • Nederlandstalig Avast! forum
Re: Avast Support is *very* bad
« Reply #1 on: August 13, 2015, 08:22:49 PM »
Hi zfil :)

Can you post your Ticked ID ?
Than I will try to get some attention to this.

Greetz, Red.

OS: Win 10 / iOS 17 / Debian 12 / Tails 5
Real Time: Avast Premium Security
On Demand: Malwarebytes
VPN: NordVPN ( NordLynx ) with Threat Protection ( Lite )

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89055
  • No support PMs thanks
Re: Avast Support is *very* bad
« Reply #2 on: August 13, 2015, 08:33:50 PM »
I think that the support ticket route isn't as effective as it should be for FPs.
It would/should have been much quicker to submit it from avastUI - presumably it was added to the virus chest - in which case it can be submitted directly from there.

If you didn't allow it to be added to the chest, you can add it manually and then submit (image1).
Open the virus chest - avastUI > Settings > Scan > Scan for Viruses - at the bottom of that page is 'Quarantine (Virus Chest)' clicking that opens the chest.

You can make that less long winded by changing the home page of the AvastUI, image2.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Avast Support is *very* bad
« Reply #3 on: August 13, 2015, 08:39:43 PM »
detected as supicious
https://www.virustotal.com/en/file/8a700bfbba0298590fd515d6e99f9760abc182161bbefec4d890fca97207d52d/analysis/

First submission 2013-12-09 21:44:31 UTC ( 1 year, 8 months ago )



« Last Edit: August 13, 2015, 08:41:14 PM by Pondus »

REDACTED

  • Guest
Re: Avast Support is *very* bad
« Reply #4 on: August 14, 2015, 12:43:49 AM »
detected as supicious
https://www.virustotal.com/en/file/8a700bfbba0298590fd515d6e99f9760abc182161bbefec4d890fca97207d52d/analysis/

First submission 2013-12-09 21:44:31 UTC ( 1 year, 8 months ago )

Yeah only by this crappy Avast. BTW I would really want to know what makes Avast engine think this is suspicious :)
As I've give the other example of ProtectionID that is flagged as virus this completely FUD, just dissassemble the thing and give me the problematic code :/ this is ridiculous.

REDACTED

  • Guest
Re: Avast Support is *very* bad
« Reply #5 on: August 14, 2015, 12:45:39 AM »
I think that the support ticket route isn't as effective as it should be for FPs.
It would/should have been much quicker to submit it from avastUI - presumably it was added to the virus chest - in which case it can be submitted directly from there.

If you didn't allow it to be added to the chest, you can add it manually and then submit (image1).
Open the virus chest - avastUI > Settings > Scan > Scan for Viruses - at the bottom of that page is 'Quarantine (Virus Chest)' clicking that opens the chest.

You can make that less long winded by changing the home page of the AvastUI, image2.

Well tried that before and nothing happened :) at least with the ticket this file was white listed for a couple of weeks :) ...
Frankly this is sad and ridiculous :(

Offline Rednose

  • Pirate Party Member
  • Avast Überevangelist
  • Massive Poster
  • *****
  • Posts: 3739
  • Bits of Freedom : https://www.bof.nl
    • Nederlandstalig Avast! forum
Re: Avast Support is *very* bad
« Reply #6 on: August 14, 2015, 12:46:26 AM »
If you would post your Ticked ID like I asked  ::)

Greetz, Red.
OS: Win 10 / iOS 17 / Debian 12 / Tails 5
Real Time: Avast Premium Security
On Demand: Malwarebytes
VPN: NordVPN ( NordLynx ) with Threat Protection ( Lite )

REDACTED

  • Guest
Re: Avast Support is *very* bad
« Reply #7 on: August 14, 2015, 12:48:25 AM »
Can you post your Ticked ID ?
Than I will try to get some attention to this.

Thank you so much!

The ticket id is : #KMF-493-36836

Cheers
Fil

Offline Rednose

  • Pirate Party Member
  • Avast Überevangelist
  • Massive Poster
  • *****
  • Posts: 3739
  • Bits of Freedom : https://www.bof.nl
    • Nederlandstalig Avast! forum
Re: Avast Support is *very* bad
« Reply #8 on: August 14, 2015, 12:55:45 AM »
I have put it forward :)

Greetz, Red.
OS: Win 10 / iOS 17 / Debian 12 / Tails 5
Real Time: Avast Premium Security
On Demand: Malwarebytes
VPN: NordVPN ( NordLynx ) with Threat Protection ( Lite )

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Avast Support is *very* bad
« Reply #9 on: August 14, 2015, 08:36:10 AM »
more info on this detection   
Win32:WrongInf-D [Susp] / Wrongly infected file means it may have been infected by a file infector or not properly cleaned and containe remnants of infection


REDACTED

  • Guest
Re: Avast Support is *very* bad
« Reply #10 on: August 15, 2015, 03:25:05 AM »

So I've received an "answer" from the support: apparently updating my definitions will solve the issue. Unfortunately this is still not true with tonite 150814-6 version (support message was sent in the morning).
Of course I've not received any technical answers about the root cause of this false positive neither info about what they will do to prevent this as I requested (this is beyond me if I was treating my customers the same way I will have lost my job long time ago ...)
No explanation as well why my ticket was put to private status as well ...


more info on this detection   
Win32:WrongInf-D [Susp] / Wrongly infected file means it may have been infected by a file infector or not properly cleaned and containe remnants of infection

Still in this case this is completely ridiculous. I've even compared the file from the original EA servers (witch didn't changed since 2003) and the hash is the same ...

Offline Maxx_original

  • Avast team
  • Super Poster
  • *
  • Posts: 1479
Re: Avast Support is *very* bad
« Reply #11 on: August 19, 2015, 02:11:46 PM »
The file contains a binary (ikernel.exe) with Parite leftover. It's not dangerous, but it is not clean. It's completely ok to detect it at the highest heur level.

REDACTED

  • Guest
Re: Avast Support is *very* bad
« Reply #12 on: August 23, 2015, 11:57:27 PM »
The file contains a binary (ikernel.exe) with Parite leftover. It's not dangerous, but it is not clean. It's completely ok to detect it at the highest heur level.

ikernel.exe is installshield. Not sure what you mean by "Parite leftover" ... But yes actually now is it only detected at the highest heuristic lvl ...

And BTW if is not dangerous why it is marked as a threat ? Shouldn't it be flagged as a warning ?
« Last Edit: August 24, 2015, 12:02:21 AM by zfil »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
« Last Edit: August 24, 2015, 12:28:36 AM by Pondus »

REDACTED

  • Guest
Re: Avast Support is *very* bad
« Reply #14 on: August 24, 2015, 12:27:54 AM »

Ok so thanks @Pontus and @Maxx_original now I understand the root cause of Avast reporting a problem at highest heuristic lvl, but:
- I feel sad that even after many exchanges with support I didn't get any useful answers, this is fortunate to have Avast guys answering here (many thanks !!)
- please consider reporting this class of detection as warnings instead of threats

Now for my education why Virus Total still detect the issue as today, do they run avast in high heuristic sensitivity ?