Author Topic: Confirmation about gamaredon false positive  (Read 1297 times)

0 Members and 1 Guest are viewing this topic.

Offline HelpPlease

  • Newbie
  • *
  • Posts: 3
Confirmation about gamaredon false positive
« on: March 23, 2022, 12:59:51 PM »
Hi,

I am using Avast free.

So I had the alert yesterday about VBS:Gamaredon-CM [Apt] like a lot of others have, and I've seen the confirmation on the Avast twitter account that it was a false positive, however my alert was different than the others I have read about.

Other people have mentioned that Avast quarantined their firefox profiles, or aborted connection to various websites when the alert popped up, but for me it was a file located in C:\ProgramData\Microsoft\Windows\WER\Temp and the infected file was called WER579D . tmp . txt

Is it normal for windows files to have both tmp and txt at the end? I don't recall seeing that before.

And is this just the same as the other false positives? Is all as it should be and I am not infected?

Thanks.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Confirmation about gamaredon false positive
« Reply #1 on: March 23, 2022, 01:35:25 PM »
Hi, best you post/ask in the dedicated forum section/thread.
-> https://forum.avast.com/index.php?topic=318639.0
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline HelpPlease

  • Newbie
  • *
  • Posts: 3
Re: Confirmation about gamaredon false positive
« Reply #2 on: March 23, 2022, 01:53:35 PM »
Hi, best you post/ask in the dedicated forum section/thread.
-> https://forum.avast.com/index.php?topic=318639.0

Oh sorry, should I make another post, or can a moderator move my post?

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48566
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Confirmation about gamaredon false positive
« Reply #3 on: March 23, 2022, 01:55:57 PM »
Hi, best you post/ask in the dedicated forum section/thread.
-> https://forum.avast.com/index.php?topic=318639.0

Oh sorry, should I make another post, or can a moderator move my post?
Another post really isn't needed. It's a false positive. Just follow the other threat for
the latest information.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet