Author Topic: Hitman Pro scan calls 2 Avast files malware  (Read 3425 times)

0 Members and 1 Guest are viewing this topic.

Offline tere7

  • Newbie
  • *
  • Posts: 4
Hitman Pro scan calls 2 Avast files malware
« on: February 16, 2019, 05:04:34 PM »
Hitman Pro scan found the file called algo.dll in 2 the folders below and called it malware, saying "One or more antivirus vendors have indicated that the file is malicious."
C:\Program Files\AVAST Software\Avast\defs\19021602 and
C:\Program Files\AVAST Software\Avast\defs\19021510

Offline schmidthouse

  • VIRUS FREE A Long Time
  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 7170
  • When you think you know, Think Again
Re: Hitman Pro scan calls 2 Avast files malware
« Reply #1 on: February 16, 2019, 05:07:23 PM »
Well I'm no expert but I'd say those files are Avast Virus definition files that Avast uses to scan for similar and help protect your OS.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Hitman Pro scan calls 2 Avast files malware
« Reply #2 on: February 16, 2019, 05:08:39 PM »
Well I'm no expert but I'd say those files are Avast Virus definition files that Avast uses to scan for similar and help protect your OS.
Correct.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline schmidthouse

  • VIRUS FREE A Long Time
  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 7170
  • When you think you know, Think Again
Re: Hitman Pro scan calls 2 Avast files malware
« Reply #3 on: February 16, 2019, 05:10:07 PM »
Well I'm no expert but I'd say those files are Avast Virus definition files that Avast uses to scan for similar and help protect your OS.
Correct.
Thanks Asyn  ;)

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5604
  • Spartan Warrior
Re: Hitman Pro scan calls 2 Avast files malware
« Reply #4 on: February 16, 2019, 05:32:24 PM »
Typical false positive report where two active real-time antivirus program scanners are installed and running at the same time. 

One or both reports the virus definitions running in system memory of the other as actual malware/viruses when it is not:  https://forum.avast.com/index.php?topic=211973.0

Why are you running HitMan Pro?
Windows 10 Home 64-bit 22H2 Avast Premier Security version 24.1.6099 (build 24.1.88821.762)  UI version 1.0.797
 UI version 1.0.788.  Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.2.6105 (build 24.1.8918.827) UI version 1.0.801

Offline schmidthouse

  • VIRUS FREE A Long Time
  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 7170
  • When you think you know, Think Again
Re: Hitman Pro scan calls 2 Avast files malware
« Reply #5 on: February 16, 2019, 06:04:19 PM »
Typical false positive report where two active real-time antivirus program scanners are installed and running at the same time. 

One or both reports the virus definitions running in system memory of the other as actual malware/viruses when it is not:  https://forum.avast.com/index.php?topic=211973.0

Why are you running HitMan Pro?

Good question ???

Offline tere7

  • Newbie
  • *
  • Posts: 4
Re: Hitman Pro scan calls 2 Avast files malware
« Reply #6 on: February 16, 2019, 07:39:53 PM »
Thanks everyone.  I just run Hitman Pro on demand sometimes to double check.  it was once recommended.  It's not always actively running so shouldn't conflict with Avast.  Thanks for the link to the topic; I'll read it now.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89033
  • No support PMs thanks
Re: Hitman Pro scan calls 2 Avast files malware
« Reply #7 on: February 16, 2019, 08:33:51 PM »
The main issue is that hitman pro is running it is using multiple different AV scanners, this certainly increases the potential for false positives.

Even if it were just a single scanner, when one scanner scans another's installation area there is a high likelihood that files could be pinged, because of the location of the file and its task. 

When searching out malware you have to be in a position and be on the lookout for what malware actually does. This could make that look suspicious.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline tere7

  • Newbie
  • *
  • Posts: 4
Re: Hitman Pro scan calls 2 Avast files malware
« Reply #8 on: February 17, 2019, 12:35:06 AM »
Well I didn't feel good about it so I downloaded the Sophos Virus Removal Tool which  supposedly can run alongside another anti-virus product.  This time I disabled Avast before starting the scan.  It found that one of the Avast files is infected with Mal/Behav-009, but it was unable to remove it.  Still don't feel good about assuming it's just due to running another antivirus along with Avast.  I don't understand what  DavidR means by "When searching out malware you have to be in a position and be on the lookout for what malware actually does. This could make that look suspicious."

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89033
  • No support PMs thanks
Re: Hitman Pro scan calls 2 Avast files malware
« Reply #9 on: February 17, 2019, 02:20:47 AM »
Well just taking a look at what Sophos supposedly found, 'Mal/Behav-009' (but you don't give the file name and location), taken from that malware name and expanding my supposition of the name 'Malware Behaviour number 009' this would appear to be a generic 

There are signatures and functions in avast that will looking out for and detecting behavioural malware, etc. and it is entirely possible to have another AV to incorrectly identify one of these files/actions as malicious.

I hope you can see what I'm getting at now.  Also if you consider the two (multiple) scans by hitman pro and sophos, only one detection was made by sophos and that wasn't one of those found by hitman pro, nor were any of the others found by hitman pro found by sophos.  So there we have inconsistency between those multiple AVs.

Also not that the algo.dll file is digitally signed by avast.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48553
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Hitman Pro scan calls 2 Avast files malware
« Reply #10 on: February 17, 2019, 05:03:54 PM »
A simple example.
A hacker installs a keylogger on your system - This is dangerous and needs to be blocked.
You install a keylogger to check on someone using your system - Not dangerous because you installed it and you control it.
You are the only one who can determine if the keylogger is dangerous or safe. Not some program you installed. It can only alert you no more, no less.
 
.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline tere7

  • Newbie
  • *
  • Posts: 4
Re: Hitman Pro scan calls 2 Avast files malware
« Reply #11 on: February 17, 2019, 09:07:56 PM »
Ok I'll just have to trust you all.
Just to clarify, the findings from the 2 scans (Sophos & Hitman Pro) are the same.  This is from the Sophos logfile, which I didn't look at until later:

2019-02-16 16:36:53.254   >>> Virus 'Mal/Behav-009' found in file C:\Program Files\AVAST Software\Avast\defs\19021510\algo.dll
2019-02-16 16:38:20.864   >>> Virus 'Mal/Behav-009' found in file C:\Program Files\AVAST Software\Avast\defs\19021602\algo.dll

Thanks again for all the replies.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89033
  • No support PMs thanks
Re: Hitman Pro scan calls 2 Avast files malware
« Reply #12 on: February 17, 2019, 09:20:42 PM »
You're welcome.

Digital signing of files should give an additional degree of confidence on the file being clean.  If a file has/had been altered after signing, then the digital signature would be invalid.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security