Author Topic: False positives  (Read 15937 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
False positives
« on: April 05, 2018, 10:23:31 PM »
I have recently switched from Avast to Avg due to performance reasons and the behavior shield that Avg uses seems to detect more false positives than Avast ever did. In the last few weeks, a legitimate process in windows (can't remember which one it was) and TeamViewer's sponsor window "7.hta" have both been blocked, an occurrence that had never happened while I was using Avast.  :-\

EDIT: The windows process in question was "mshta.exe".
« Last Edit: April 05, 2018, 10:29:51 PM by chaloja_no »

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2294
Re: False positives
« Reply #1 on: April 06, 2018, 08:57:33 AM »
Hello,
post a screenshot of the window with detection, please.

Milos

REDACTED

  • Guest
Re: False positives
« Reply #2 on: April 06, 2018, 10:39:51 PM »

post a screenshot of the window with detection, please.


This is for the Teamviewer app. I couldn't reproduce the windows process one because it happened on a laptop I was servicing, you'll just have to trust me on that one.
« Last Edit: April 07, 2018, 01:13:33 AM by chaloja_no »

REDACTED

  • Guest
Re: False positives
« Reply #3 on: April 17, 2018, 01:52:54 PM »
Here's another false positive detected by the behavior shield. This is a legitimate AutoCad installation file downloaded from their website. 

VirusTotal analysis: https://www.virustotal.com/#/file/b9c299c25f8d4658ff433062c770400b20fc9bcf6c8c6abc1d587d5d90fc3c07/detection
« Last Edit: April 17, 2018, 02:00:52 PM by chaloja_no »

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: False positives
« Reply #4 on: April 17, 2018, 02:25:43 PM »
In response to your lats post (and picture) - if I'm thinking of the right think, IDP detection's have a guideline to follow for detection that is almost universal. Though I can't find the information on it.

Milos (or someone qualified from Avast!) will swing by again and check things out.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

REDACTED

  • Guest
Re: False positives
« Reply #5 on: April 27, 2018, 04:48:42 PM »


Here is a screenshot of the issue. Its happening to me as well now after I update teamviewer.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: False positives
« Reply #6 on: April 28, 2018, 05:15:07 AM »
You can report a suspected FP (File/Website) here: https://www.avast.com/false-positive-file-form.php
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: False positives
« Reply #7 on: May 19, 2018, 02:10:36 PM »
Even after reporting the file, and getting a response from Avast that it has been whitelisted, the 7.hta file is still getting flagged.
« Last Edit: May 19, 2018, 02:14:44 PM by chaloja_no »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: False positives
« Reply #8 on: May 19, 2018, 04:53:41 PM »
Even after reporting the file, and getting a response from Avast that it has been whitelisted, the 7.hta file is still getting flagged.
Strange, wait for Milos...
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: False positives
« Reply #9 on: August 05, 2018, 07:36:02 PM »
Hello!

Any news regarding this problem?

Offline PDI

  • Avast team
  • Full Member
  • *
  • Posts: 159
Re: False positives
« Reply #10 on: August 06, 2018, 08:41:13 AM »
Hi,

the problem of the 7.hta is that it's generated after each start or the TeamViever Free. You should add the exception for the full path for Behavioral Shield.

Regards,
PDI

REDACTED

  • Guest
Re: False positives
« Reply #11 on: August 06, 2018, 08:56:06 PM »
Hello!

Any news regarding this problem?

Yes, I was contacted by Avast recently. They said they'd have to look into it with TeamViewer's representatives as the software itself is generating "very suspicious files with adverts with no digital signature".