Author Topic: [FIXED] [VBS: Malware Gen] False positives Vir. def: 170221-1 22.2.2017 0:08:41  (Read 156631 times)

0 Members and 2 Guests are viewing this topic.

REDACTED

  • Guest
I managed to restore a lot of files that were moved to the chest from the scan and I was lucky enough to stop the boot-time scan before it deleted anything important. However, my scan history has labeled some important files as "delete" and "action postponed until next reboot". Is there any way to stop this action from being carried out? I tried putting the action to "do nothing" but it won't let me apply it.

Edit: I seem to be unable to find the said files that were marked for deletion in their folders. I think Avast already deleted them.

I haven't rebooted my system yet after last night's scan for the same reason as you. Avast said 161 files were "infected". 145 files were moved to the chest while the other 16 files were marked for deletion with the same "action postponed until next reboot" label applied.  I tried to switch it from "delete" to "do nothing" and it won't let me apply it, either. I don't want to reboot because I think it'll delete those files. Most of the files marked for deletion are regtrans-ms, a counters.dat file, and some others that don't have visible extensions. I've sent a support ticket to Avast asking for a solution to this once already and they gave me a standard answer that didn't address my question. I sent a second ticket a few hours ago with hopes that I'll get a more direct answer. Hopefully, someone from Avast will chime in and answer this question soon.

REDACTED

  • Guest
I managed to restore a lot of files that were moved to the chest from the scan and I was lucky enough to stop the boot-time scan before it deleted anything important. However, my scan history has labeled some important files as "delete" and "action postponed until next reboot". Is there any way to stop this action from being carried out? I tried putting the action to "do nothing" but it won't let me apply it.

Edit: I seem to be unable to find the said files that were marked for deletion in their folders. I think Avast already deleted them.

I haven't rebooted my system yet after last night's scan for the same reason as you. Avast said 161 files were "infected". 145 files were moved to the chest while the other 16 files were marked for deletion with the same "action postponed until next reboot" label applied.  I tried to switch it from "delete" to "do nothing" and it won't let me apply it, either. I don't want to reboot because I think it'll delete those files. Most of the files marked for deletion are regtrans-ms, a counters.dat file, and some others that don't have visible extensions. I've sent a support ticket to Avast asking for a solution to this once already and they gave me a standard answer that didn't address my question. I sent a second ticket a few hours ago with hopes that I'll get a more direct answer. Hopefully, someone from Avast will chime in and answer this question soon.

I might have figured out a way around it. Instead of clicking on do nothing, try clicking on repair or fix automatically and then apply. When I did this, the result was that most of them changed to "Error, access is denied". So now at least, nothing is showing that it will be deleted on reboot.

Offline wrlucas

  • Newbie
  • *
  • Posts: 9
FIXED: VPS 170222-0 is already out and fixes this false positive. Moroni
[/size
What is VPS 170222-0?? Where do you get it?  My Avast is up-to-date, yet it is still throughing this alert everytime I navigate to my usual sites in Chrome.

REDACTED

  • Guest
Just tried that by selecting "Move to Chest". I didn't select "Fix Automatically" because that's the option that deletes files if they can't be repaired or moved to the chest. The 16 files changed from "action postponed until next reboot" to "Error, the process cannot access the file because it is being used by another process." I guess that's good news. Means the files haven't been deleted. BUT, will that prevent them from being deleted by Avast at a future point if they're not being used by another process?
« Last Edit: February 22, 2017, 10:02:19 PM by jlwmtx »

REDACTED

  • Guest
FIXED: VPS 170222-0 is already out and fixes this false positive. Moroni
[/size
What is VPS 170222-0?? Where do you get it?  My Avast is up-to-date, yet it is still throughing this alert everytime I navigate to my usual sites in Chrome.

If I am not wrong they have already updated the definitions so if you update the program you must get the fix

REDACTED

  • Guest
Yeah, my program has been updated since early morning, it didn't fix anything.

REDACTED

  • Guest
Lmaooooo

just did a total reformat of my pc thinking I had been compromised with viruses... literally lost like 10 hours of time.

.... then I found this thread.

Avast please check my email account on your records YOU should be providing me with extra days on my licence, what the hell do I pay you for? honestly thinking of switching boats. and I will be if you do not credit my account for this.

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48551
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Lmaooooo

just did a total reformat of my pc thinking I had been compromised with viruses... literally lost like 10 hours of time.

.... then I found this thread.

Avast please check my email account on your records YOU should be providing me with extra days on my licence, what the hell do I pay you for? honestly thinking of switching boats. and I will be if you do not credit my account for this.
A simple google search for " Avast false positives 2017" brings up the following:
https://forum.avast.com/index.php?topic=197572.0 among other threads.
It's never a good idea to start a fix with the most drastic option.
But, we are all different and maybe it's what you thought was a reasonable action.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

REDACTED

  • Guest
So i take it Avast is completely ignore people on this topic.. anyways with it update and everything still an issue.. cant delete cant do nothing with those 2 infected files.. let alone if there is anything else wrong.. it was scaning fine i left it at around 25%-50% come back to find it back at 19%.. so clearly there is more of an issue with this update then lead to believe .. Some help would be nice.. AVAST.. pay good money for your product to get bad CS...

REDACTED

  • Guest
Definitions 17022-3 no improvement and not updated versions available. Still getting all kinds of erros

Offline TheOwner

  • Poster
  • *
  • Posts: 406
So i take it Avast is completely ignore people on this topic.. anyways with it update and everything still an issue.. cant delete cant do nothing with those 2 infected files.. let alone if there is anything else wrong.. it was scaning fine i left it at around 25%-50% come back to find it back at 19%.. so clearly there is more of an issue with this update then lead to believe .. Some help would be nice.. AVAST.. pay good money for your product to get bad CS...
This is not false positive related to this topic. Name of malware is different. Try upload on virustotal. It seems like avast own files, but i don't have those files in this folder. (Free version)
Anyway in safe mode delete should work perfectly.
« Last Edit: February 23, 2017, 01:03:25 AM by TheOwner »

REDACTED

  • Guest
Avast please inbox me on how to get a refund on all the products I currently have Active, should be about $100 worth... I'll need that money to sign up to another A/V

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
So i take it Avast is completely ignore people on this topic.. anyways with it update and everything still an issue.. cant delete cant do nothing with those 2 infected files.. let alone if there is anything else wrong.. it was scaning fine i left it at around 25%-50% come back to find it back at 19%.. so clearly there is more of an issue with this update then lead to believe .. Some help would be nice.. AVAST.. pay good money for your product to get bad CS...

1.  Your image shows two unpxxxxxxxx.tmp files in the _avast_ temp folder, this is where avast unpacks or sends files to be scanned. Ordinarily after completion of the scan these unpxxxxxxxxx.tmp files are removed. It is safe to remove those two files.

2.  When avast makes a detection, it changes the sensitivity of the scan to a higher level this is why you see a change in the percentage scanned and why it subsequently takes longer.

I was running full system scan as a test and essentially got the same change in scan percentage from around 25% down to about 13%. The main problem is you don't know why that happened until you see that it has made a detection. Nor are you aware that these detections are why the percentage dropped as it reassess how much now needs to be scanned.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48551
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Avast please inbox me on how to get a refund on all the products I currently have Active, should be about $100 worth... I'll need that money to sign up to another A/V
If you're still eligible to a refund, you can apply for it here:
https://support.avast.com/support/tickets/new?form=2
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

REDACTED

  • Guest
Quote
Posted by: bob3160 on: Yesterday at 11:26:07 PM
A simple google search for " Avast false positives 2017" brings up the following: https://forum.avast.com/index.php?topic=197572.0 among other threads.
It's never a good idea to start a fix with the most drastic option. But, we are all different and maybe it's what you thought was a reasonable action.

It's almost never a good idea to reinforce the lesson that a poster appears to have already learned the hard way. It's also quite unreasonable to expect that someone who may have never experienced anything like this before would somehow intuitively know that, actually, antivirus programs can accidentally become temporary viruses themselves because programmers are human like everyone else, even antivirus programmers. S/he may have had zero reason to know that false-positives are a thing.

Speaking as a huge, longtime fan of Avast, I can only guess that Bob was unreasonably reproaching a poster who has apparently suffered plenty already in a misguided effort to try to come to Avast's defense. The thing is, as amazing as Avast is, I'm sure they'd be the first to admit that actually they're the ones who failed this time, not the people who trusted them implicitly. Crediting their paying customers for a few days is actually an incredibly reasoned and fair request, especially from a poster who has just rebuilt his software/machine for nothing because their software gave him reason to do so. I'm surprised you don't see that Bob, but hey, we are all different and maybe it's just not what you thought is a reasonable action for Avast to take.

I have every faith that Avast will do the right thing. In my experience from having seen them do so much good for so long, they deserve to be forgiven if they make it up to their customers.