Author Topic: Threat Description: IDP.HELU.PSWM6%s_cmd  (Read 7946 times)

0 Members and 1 Guest are viewing this topic.

Offline nynjguy

  • Newbie
  • *
  • Posts: 9
Threat Description: IDP.HELU.PSWM6%s_cmd
« on: March 03, 2020, 04:59:30 PM »
Hi

We are receiving tons of alerts in the same client with this threat but I image is a false positive, Can you help me to figure it out? I scan system and they are clean, I also use malwarebytes as back up.

Description: The device is infected with a security threat.
Details:
Threat Description: IDP.HELU.PSWM6%s_cmd
Threat Severity: Infection
Threat Shield: Behavior Shield
Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Virus Action: Fix automatically - means try to Repair, if it fails, try to Move to Chest, and if even that fails, delete
Group: Default
Date and Time: 3/3/2020 10:56:29 AM
Notes:
Alert Name: Default

Offline nynjguy

  • Newbie
  • *
  • Posts: 9
Re: Threat Description: IDP.HELU.PSWM6%s_cmd
« Reply #1 on: March 05, 2020, 04:47:20 PM »
Here is the screenshot of the error.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37584
  • Not a avast user
Re: Threat Description: IDP.HELU.PSWM6%s_cmd
« Reply #2 on: March 05, 2020, 04:49:19 PM »

Offline Chris1038

  • Newbie
  • *
  • Posts: 2
Re: Threat Description: IDP.HELU.PSWM6%s_cmd
« Reply #3 on: March 09, 2020, 11:43:21 AM »
HI Nynjguy,

By any chance are you running Nessus (Tennable.IO) agents on your machines as well?

Offline PDI

  • Avast team
  • Full Member
  • *
  • Posts: 159
Re: Threat Description: IDP.HELU.PSWM6%s_cmd
« Reply #4 on: March 10, 2020, 09:41:57 AM »
Hi Nynjguy,

could you follow these steps https://support.avast.com/en-us/article/33/ and write the Ticket ID here in the comments?

We cannot really help you when only screen should is provided.

Thanks,
PDI

Offline nynjguy

  • Newbie
  • *
  • Posts: 9
Re: Threat Description: IDP.HELU.PSWM6%s_cmd
« Reply #5 on: March 11, 2020, 06:06:11 PM »
HI Nynjguy,

By any chance are you running Nessus (Tennable.IO) agents on your machines as well?
  Yes we are doing Tenable IO scanning every week, this may be>?

Offline nynjguy

  • Newbie
  • *
  • Posts: 9
Re: Threat Description: IDP.HELU.PSWM6%s_cmd
« Reply #6 on: March 11, 2020, 10:51:55 PM »
Hi Nynjguy,

could you follow these steps https://support.avast.com/en-us/article/33/ and write the Ticket ID here in the comments?

We cannot really help you when only screen should is provided.

Thanks,
PDI


The case number is 10221416

Offline PDI

  • Avast team
  • Full Member
  • *
  • Posts: 159
Re: Threat Description: IDP.HELU.PSWM6%s_cmd
« Reply #7 on: March 12, 2020, 09:12:39 AM »
Hi,

we did change the detection and it'd be fixed in the VPS tomorrow.

Regards,
PDI
« Last Edit: March 12, 2020, 10:40:22 AM by PDI »

Offline Chris1038

  • Newbie
  • *
  • Posts: 2
Re: Threat Description: IDP.HELU.PSWM6%s_cmd
« Reply #8 on: March 12, 2020, 12:22:40 PM »
HI Nynjguy,

By any chance are you running Nessus (Tennable.IO) agents on your machines as well?
  Yes we are doing Tenable IO scanning every week, this may be>?

We run the Nessus SCAN Everyday, I've been in touch with them and asked me to enable advanced logging. It is still on my list of things to do. But from the tests that I have done here it does seem the Nessus is causing the issue.

Offline nynjguy

  • Newbie
  • *
  • Posts: 9
Re: Threat Description: IDP.HELU.PSWM6%s_cmd
« Reply #9 on: March 12, 2020, 05:26:48 PM »
HI Nynjguy,

By any chance are you running Nessus (Tennable.IO) agents on your machines as well?
  Yes we are doing Tenable IO scanning every week, this may be>?

We run the Nessus SCAN Everyday, I've been in touch with them and asked me to enable advanced logging. It is still on my list of things to do. But from the tests that I have done here it does seem the Nessus is causing the issue.


Makes sense, I just check and run an Tenable IO agent scan and avast went crazy again, this is getting annoying. Reports powershell.exe or CMD.exe too.

Offline PDI

  • Avast team
  • Full Member
  • *
  • Posts: 159
Re: Threat Description: IDP.HELU.PSWM6%s_cmd
« Reply #10 on: March 13, 2020, 08:53:12 AM »
Hi,

please be patient. The fix'd be released today as I wrote yesterday.

Regards,
PDI

Offline nynjguy

  • Newbie
  • *
  • Posts: 9
Re: Threat Description: IDP.HELU.PSWM6%s_cmd
« Reply #11 on: April 14, 2020, 05:30:02 PM »
Hi

Today we start seeing the same error again in all of our system, the fixed did work for a while but just came back.


An Avast Business CloudCare High-Priority Alert Occurred.

Description: The device is infected with a security threat.
Details:
Threat Description: IDP.HELU.PSWM7%s_cmd
Threat Severity: Infection
Threat Shield: Behavior Shield
Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Virus Action: Fix automatically - means try to Repair, if it fails, try to Move to Chest, and if even that fails, delete
Customer:
Group: Default
Device:
Date and Time: 4/14/2020 11:05:38 AM
Notes:
Alert Name: Default

Click here to view this alert in the CloudCare portal.

Offline PDI

  • Avast team
  • Full Member
  • *
  • Posts: 159
Re: Threat Description: IDP.HELU.PSWM6%s_cmd
« Reply #12 on: April 16, 2020, 09:00:50 AM »
Hi,

was there any update to the Nessus software?

Thanks,
PDI

Offline nynjguy

  • Newbie
  • *
  • Posts: 9
Re: Threat Description: IDP.HELU.PSWM6%s_cmd
« Reply #13 on: April 16, 2020, 02:26:33 PM »
Not that I'm aware, but is the same thing. Nessus and Tenable IO always uses CMD or Powershell to scan the machines.

I check all the warning is the exact same thing as the one before. Anything you need from us to help out?

Offline PDI

  • Avast team
  • Full Member
  • *
  • Posts: 159
Re: Threat Description: IDP.HELU.PSWM6%s_cmd
« Reply #14 on: April 16, 2020, 05:13:07 PM »
Hi,

it's ok for now. I'll let you know when the fix is ready or if we need more information.

Regards,
PDI