Author Topic: Two items of Malware found following re-subscription to Avast  (Read 2221 times)

0 Members and 1 Guest are viewing this topic.

Offline kyloglen

  • Newbie
  • *
  • Posts: 4
Two items of Malware found following re-subscription to Avast
« on: August 22, 2020, 04:26:15 PM »
Could be a total coincidence but the same night I re-subscribed to Avast, I set a virus scan to complete and went to sleep, when I woke up, Avast had found two possible Malware items

Win32:Malware-gen - libGLESv2.dll - D:Battlenet\Heroes of the Storm\Support\BlizzardBrowser
Win32:Dropper-gen [Drp] libGLESv2.dll - D\Steam\steamappls\common\Trove

Both found during the same scan, they've both been quarantined now but I read online one virus is able to open a backdoor for others & one is able to replicate itself. Also read that they're both undefined and haven't been seen before/enough to be categorised or named, so does this mean they could just be false positives? It's the same file in both games, I haven't used any Blizzard programs in ages and I haven't even played Trove since I installed it. Not sure if they've had any updates to introduce files which would be detected as false positives either.

Also worth noting, I have Avast Premium and have always had it - was simply renewing my subscription, so there wasn't a period I was without it. I also run Malwarebytes and that detected nothing on it's scan.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Two items of Malware found following re-subscription to Avast
« Reply #1 on: August 22, 2020, 04:39:56 PM »
Test the file at VT (https://www.virustotal.com) and post the link to the result here.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline kyloglen

  • Newbie
  • *
  • Posts: 4
Re: Two items of Malware found following re-subscription to Avast
« Reply #2 on: August 22, 2020, 04:45:13 PM »
Do I bring it out of Quarantine then? or is there a way to do so without taking it out

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Two items of Malware found following re-subscription to Avast
« Reply #3 on: August 22, 2020, 04:50:56 PM »
Yes. If you don't want to take the risk, you can send it from chest to threat lab for analysis.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline kyloglen

  • Newbie
  • *
  • Posts: 4
Re: Two items of Malware found following re-subscription to Avast
« Reply #4 on: August 22, 2020, 04:56:36 PM »
This is what it's showing.

https://prnt.sc/u41gy4

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Two items of Malware found following re-subscription to Avast
« Reply #5 on: August 22, 2020, 04:57:53 PM »
You can report a suspected FP (File/Website) here: https://www.avast.com/false-positive-file-form.php
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline kyloglen

  • Newbie
  • *
  • Posts: 4
Re: Two items of Malware found following re-subscription to Avast
« Reply #6 on: August 22, 2020, 04:59:54 PM »
So would you suggest it's a false positive? Where do you think they've come from, because they didn't show up on the virus scan a few days prior? I haven't opened battle.net in a while so don't think it would have updated & as I say, I haven't played Trove ever, and it's been installed for a long time.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Two items of Malware found following re-subscription to Avast
« Reply #7 on: August 22, 2020, 05:01:16 PM »
So would you suggest it's a false positive?
Yes, most certainly.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48559
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Two items of Malware found following re-subscription to Avast
« Reply #8 on: August 22, 2020, 05:03:18 PM »

Report a false positive (select file or website)
https://www.avast.com/false-positive-file-form.php
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Two items of Malware found following re-subscription to Avast
« Reply #9 on: August 22, 2020, 05:05:20 PM »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0