Author Topic: upgrade.ps1 quarantined  (Read 1230 times)

0 Members and 1 Guest are viewing this topic.

Offline J.Sage

  • Newbie
  • *
  • Posts: 3
upgrade.ps1 quarantined
« on: November 12, 2021, 03:49:40 PM »
Hi, I have this error 7214d8f8765e/211112.1431+0100

I'm a complete noob in pc security, do I need to be worried about this?
It's about a "upgrade.ps1" file in my windows temp folder.
I keep getting this alert when I close it, and it keeps getting "quarantined".

What can I do to solve this?

Appreciate your help :)

John

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: upgrade.ps1 quarantined
« Reply #1 on: November 13, 2021, 09:21:10 AM »
Test the file at VT (https://www.virustotal.com) and post the link to the result here.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline J.Sage

  • Newbie
  • *
  • Posts: 3
Re: upgrade.ps1 quarantined
« Reply #2 on: November 13, 2021, 01:05:59 PM »
Hi! thanks for your answer. Basically it all shows "undetected" and some "unable to process file type"

Here are the details:

Basic Properties
MD5   984932d863a5a564215417a157903e02
SHA-1   50696f0ed8dd02acaa55b3fe946b3b1344e4f762
SHA-256   5832b099084db4aeb5f64f0b755a093fdf6672dfd278e7eaa7f517def7f3f477
Vhash   8d3d009cc256738588a79c98bfe7e82c
SSDEEP   96:rqDwulBnQSwpwUw4Ow9SwZqmAnAVAVA30HyzbLuiYz:rqHOF03Aqq3PLKz
TLSH   T16D71011E7596813806B657699D0B906DFF27312B123920147BEEC1812FF7C2DE353AAD
File type   Powershell
Magic   ASCII English text, with CRLF line terminators
TrID   file seems to be plain text/ASCII (0%)
File size   3.40 KB (3485 bytes)
History
First Submission   2021-11-13 12:03:30
Last Submission   2021-11-13 12:03:30
Last Analysis   2021-11-13 12:03:30
Names
upgrade.ps1
Powershell Info
Cmdlets
convertfrom-json
get-service
get-wmiobject
invoke-webrequest
new-object
resolve-path
set-location
start-process
start-sleep
stop-process
stop-service
where-object
Cmdlets Aliases
sc
.NET Calls
System.IO.Path
Functions
Get-MsiDatabaseVersion
stop-service
Variables
$erroractionpreference
$lastexitcode
$null
$psscriptroot


Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: upgrade.ps1 quarantined
« Reply #4 on: November 13, 2021, 02:21:27 PM »
You can report a suspected FP (File/Website) here: https://www.avast.com/false-positive-file-form.php
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0