Author Topic: False Postive VBS Malware Gen - Deleted Valuable Files  (Read 6723 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
False Postive VBS Malware Gen - Deleted Valuable Files
« on: February 23, 2017, 02:00:42 AM »
Avast detected about 500 false positives today. Listing them all as VBS-Malware-Gen  These files included minecraft save games, jpeg images (That I took), documents from Word, Text, and Open Office, as well as hundreds of other valuable and much-needed files, docs, images, and save files.  I called "Premium Support" and they want to bill me to resolve the issue.  BILL ME! 

Avast Pro -  Licensed
Program Version - 17.1.1.2286  (Build 17.1.3394.42)  CURRENT as of February 22nd, cannot be updated.
Virus Definitions Version - 170222-3  CURRENT as of February 22nd, cannot be updated.

I would submit the entire list, of which 99% are false positives, but do not know how to submit the entire report, in mass, to the correct department.  Additionally, I can no longer trust AVAST with my security needs because of this incredible breach of trust. Calling tech support is a horrific waste of time.  The connection is poor, the tech support people don't understand the issue and just want billing information.  That makes the entire tech support of AVAST useless beyond a brick at resolving this issue.

I must go through the list and individually report each false positive, and restore the file.  Who has the time for this?  500 plus false positives!  I am extremely concerned that this issue has happened, and am unsure of how to keep it from happening again. Ergo, I cannot trust Avast and will have no choice but to remove it and discontinue my subscription if not resolved.

How can I report the entire list at one time to correct department?
How can I prevent this from happening again?  (Added individually to the exclusion list is insane, these files number in the hundreds!)
« Last Edit: February 23, 2017, 02:36:43 AM by Raymond84 »

Offline TheOwner

  • Poster
  • *
  • Posts: 406
Re: False Postive VBS Malware Gen - Deleted Valuable Files
« Reply #1 on: February 23, 2017, 02:19:22 AM »
That happen due broken definitons update https://forum.avast.com/index.php?topic=197572.0
It is fixed now. Look in your chest for files, if is not there, i think no one help you. If yes, all items called VBS Malware Gen you can safely restore. And for sure run full scan again.
« Last Edit: February 23, 2017, 02:27:03 AM by TheOwner »

REDACTED

  • Guest
Re: False Postive VBS Malware Gen - Deleted Valuable Files
« Reply #2 on: February 23, 2017, 02:32:58 AM »
Thank you. It should be noted that my virus definitions and program are CURRENT and cannot be updated. I just tried, again, and it says I am current.  I am, however, working on restoring the wrongfully removed files now.
« Last Edit: February 23, 2017, 02:34:52 AM by Raymond84 »

Offline TheOwner

  • Poster
  • *
  • Posts: 406
Re: False Postive VBS Malware Gen - Deleted Valuable Files
« Reply #3 on: February 23, 2017, 02:37:35 AM »
You have latest version which are fixed. That broken update was 170221-1

REDACTED

  • Guest
Re: False Postive VBS Malware Gen - Deleted Valuable Files
« Reply #4 on: February 23, 2017, 03:19:06 AM »
Thank you again, but I updated to this version, then ran my scan, and it was that scan that detected all those VBS files.  Of which, none are actual VBS malware.  :(

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48550
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: False Postive VBS Malware Gen - Deleted Valuable Files
« Reply #5 on: February 23, 2017, 10:40:56 AM »
Thank you again, but I updated to this version, then ran my scan, and it was that scan that detected all those VBS files.  Of which, none are actual VBS malware.  :(
I've just reported this to Avast which should get their attention and hopeful;y a reply.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: False Postive VBS Malware Gen - Deleted Valuable Files
« Reply #6 on: February 23, 2017, 10:55:56 AM »
Could you post a printscreen of a detection?
Could you attach some of the detected files?

Offline Jiří Šembera

  • Avast team
  • Jr. Member
  • *
  • Posts: 46
  • Developer/Malware Analyst, former VPS maintainer
Re: False Postive VBS Malware Gen - Deleted Valuable Files
« Reply #7 on: February 23, 2017, 11:19:37 AM »
You can also check your definitions folder at %programfiles%\AVAST Software\Avast\defs\. If folder 17022101 is present (that's the faulty VPS), try restarting Avast Service by running
Code: [Select]
net stop "avast! Antivirus" && net start "avast! Antivirus" in cmd.exe (as Administrator, also self-defense has to be turned off). Or you can just reboot your computer. This will ensure Avast loads only the latest VPS.

Edit: In case of a reboot, please make sure you have the latest VPS to prevent any damage caused by the faulty VPS during boot-time scan (if scheduled).
« Last Edit: February 23, 2017, 11:24:50 AM by Jiří Å embera »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89021
  • No support PMs thanks
Re: False Postive VBS Malware Gen - Deleted Valuable Files
« Reply #8 on: February 23, 2017, 11:21:22 AM »
<snip>
Could you attach some of the detected files?

The forum software only allows certain file types: Allowed file types: jpg, png, txt, log, gif.

Changing a file type to attach could well corrupt the file anyway.

Not to mention if they were allowed the last thing we would want is an alert within the forums by Avast.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

REDACTED

  • Guest
Re: False Postive VBS Malware Gen - Deleted Valuable Files
« Reply #9 on: February 23, 2017, 11:30:58 AM »
I had EXACTLY the same experience as Raymond84.  For starters, I see that the New Avast (I am using 17.1.2286 build 17.1.3394.46) automatically updates the virus definitions.  It occurs to me that I wouldn't have had this happen to me if my computer had not downloaded the new corrupt virus definition database, so I would like to know how to disable it so that I can wait 2 weeks before downloading any new definitions so that Avast has time to work out the kinks :/

Additionally, I am trying to figure out how to restore all these files without going 1 at a time.  Among the several choices when I right click on a line in the chest, I get "delete" "restore" "extract" "refresh all files"... now going 1 at a time, I figured out that "restore" puts the file back, but is "refresh all files" the same as "restore"?  Or does that refresh the list?  I wish that Avast would post more help on how to fix this problem that THEY created, since SOOOOOO many people were instantly affected due to their auto-update of corrupt virus definitions.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89021
  • No support PMs thanks
Re: False Postive VBS Malware Gen - Deleted Valuable Files
« Reply #10 on: February 23, 2017, 12:11:29 PM »
@    phredri
The default action for the VPS updates has for some considerable time always been set to Automatic. There are also the Streaming signature updates coming out every few minutes, these rely on VPS updates being set to automatic. It may also disable some of the protection modules, CyberCapture and Hardened Mode (aggressive) I believe.

You can set the Virus Definitions to manual, in the avastUI > Settings > Update. That however also disables the streaming updates also.  Lastly the volume of new malware samples in a two week period is absolutely massive and would reduce your protection greatly. One area of greater risk would web browsing as the Web Shield would be benefiting from the new signature information.

So this isn't a decision to be taken in haste.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: False Postive VBS Malware Gen - Deleted Valuable Files
« Reply #11 on: February 23, 2017, 12:44:18 PM »
<snip>
Could you attach some of the detected files?
The forum software only allows certain file types: Allowed file types: jpg, png, txt, log, gif.
Sorry, what I actually meant was linking the VT analysis, or linking a file sharing service with the files... I should be more precise next time :)

REDACTED

  • Guest
Re: False Postive VBS Malware Gen - Deleted Valuable Files
« Reply #12 on: February 23, 2017, 02:30:58 PM »
@    phredri
The default action for the VPS updates has for some considerable time always been set to Automatic. There are also the Streaming signature updates coming out every few minutes, these rely on VPS updates being set to automatic. It may also disable some of the protection modules, CyberCapture and Hardened Mode (aggressive) I believe.

You can set the Virus Definitions to manual, in the avastUI > Settings > Update. That however also disables the streaming updates also.  Lastly the volume of new malware samples in a two week period is absolutely massive and would reduce your protection greatly. One area of greater risk would web browsing as the Web Shield would be benefiting from the new signature information.

So this isn't a decision to be taken in haste.

I appreciate that info, but you didn't shed any light on the functions that I asked about, ie "restore" vs "refresh"


Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89021
  • No support PMs thanks
Re: False Postive VBS Malware Gen - Deleted Valuable Files
« Reply #13 on: February 23, 2017, 03:44:06 PM »
@    phredri
The default action for the VPS updates has for some considerable time always been set to Automatic. There are also the Streaming signature updates coming out every few minutes, these rely on VPS updates being set to automatic. It may also disable some of the protection modules, CyberCapture and Hardened Mode (aggressive) I believe.

You can set the Virus Definitions to manual, in the avastUI > Settings > Update. That however also disables the streaming updates also.  Lastly the volume of new malware samples in a two week period is absolutely massive and would reduce your protection greatly. One area of greater risk would web browsing as the Web Shield would be benefiting from the new signature information.

So this isn't a decision to be taken in haste.

I appreciate that info, but you didn't shed any light on the functions that I asked about, ie "restore" vs "refresh"

I didn't address it because I'm not clear what the hell Refresh is/means/does.

I can't recall having seen it in earlier avast versions. To me refresh in other contexts could mean reload, but clicking on Refresh doesn't seem to do anything. It doesn't rescan them as if I specifically select the scan option I get a confirmation of the scan and its result.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48550
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: False Postive VBS Malware Gen - Deleted Valuable Files
« Reply #14 on: February 23, 2017, 03:47:44 PM »
Reported to Avast. Let's wait for them to answer this. It's a new option.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet