Author Topic: Avast and Firefox False Positive-Answered  (Read 8580 times)

0 Members and 1 Guest are viewing this topic.

Offline Spiritual2016

  • Sr. Member
  • ****
  • Posts: 348
Avast and Firefox False Positive-Answered
« on: March 22, 2022, 07:14:57 PM »
Avast Free Antvirus Version 22.2.6003
Firefox 98.0.1

What Happened:

At 10:45am Pacific (and using the latest version of Firefox), I opened an email survey link from a legit company that I am a member of..

A pop-up was displayed 'Avast Blocking Prefs.js File.' I attempted to open the link two more times and the tab opened but the survey page would not open-Three copies of this file were placed in the 'Quarantine' section, showing the same time.

I was about to sign into the Avast forum when another pop-up was displayed 'Avast Has Safely Aborted 'VBS.Gamaredon-CM(Apt).'

I ran a smart scan and a full scan (but no issues were detected) so the computer was restarted and there have not been any further issues.

Next Steps:

-What are the next steps, does a setting need to be changed, and can the three copies of the Quarantine file be deleted)?
« Last Edit: March 24, 2022, 05:20:29 PM by Spiritual2016 »

Offline Bc102

  • Newbie
  • *
  • Posts: 1
Re: Avast and Firefox False Positive
« Reply #1 on: March 22, 2022, 07:29:37 PM »
Just got this myself today, 05:42PM, 05:43PM, 05:45PM and 05:49 GMT VBS:Gamaredon-CM [Apt] Prefs.js

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89057
  • No support PMs thanks
Re: Avast and Firefox False Positive
« Reply #2 on: March 22, 2022, 07:33:52 PM »
@ Spiritual2016

I use Firefox (latest version) as my default browser and so far I haven't bumped into this.

Also reported in another topic - https://forum.avast.com/index.php?topic=318639.0
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Spiritual2016

  • Sr. Member
  • ****
  • Posts: 348
Re: Avast and Firefox False Positive
« Reply #3 on: March 22, 2022, 07:36:00 PM »
-
« Last Edit: March 23, 2022, 12:28:58 AM by Spiritual2016 »

Offline CBinRIC

  • Newbie
  • *
  • Posts: 5
Re: Avast and Firefox False Positive
« Reply #4 on: March 22, 2022, 07:39:14 PM »
I got the same msg for BOTH Firefox and Thunderbird profile files 3/22/22 at 1:30 PM EDT using free AVAST.  Have newest versions of both Mozilla products that automatically update.

Have been into both Mozilla programs earlier today without complaint from AVAST.

Offline lenslark

  • Newbie
  • *
  • Posts: 1
Re: Avast and Firefox False Positive
« Reply #5 on: March 22, 2022, 08:02:28 PM »
I also got the message that pref.js was infected by VBS Gamaredon-CM en placed into quarantine
i ve send the file to avast for analysis

Offline MRTMN

  • Jr. Member
  • **
  • Posts: 22
Re: Avast and Firefox False Positive
« Reply #6 on: March 22, 2022, 08:11:15 PM »
I'm seeing the same thing, but with the pref.js in Thunderbird. Hoping it's a false positive - submitted the file to Avast.

How do we track the false positive analysis?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Avast and Firefox False Positive
« Reply #7 on: March 22, 2022, 08:23:35 PM »
Updated Feb. 16 to include new information on Gamaredon infrastructure and Indicators of Compromise

https://unit42.paloaltonetworks.com/gamaredon-primitive-bear-ukraine-update-2021/


Microsoft discloses new details on Russian hacker group Gamaredon

https://maislsenders.com/2022/02/04/microsoft-discloses-new-details-on-russian-hacker-group-gamaredon/





« Last Edit: March 22, 2022, 08:48:23 PM by Pondus »

Offline Spiritual2016

  • Sr. Member
  • ****
  • Posts: 348
Re: Avast and Firefox False Positive
« Reply #8 on: March 22, 2022, 08:27:24 PM »
-
« Last Edit: March 23, 2022, 12:29:11 AM by Spiritual2016 »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Avast and Firefox False Positive
« Reply #9 on: March 22, 2022, 08:36:35 PM »
The link(s) i posted only explaine what the gamaredon detection is, it does not say if the file in Your or others case is a FP

But there is a new post/reply from avast team here.  https://forum.avast.com/index.php?topic=318640.0


« Last Edit: March 22, 2022, 08:58:50 PM by Pondus »

Offline papinianos

  • Newbie
  • *
  • Posts: 11
Re: Avast and Firefox False Positive
« Reply #10 on: March 22, 2022, 08:46:07 PM »
Avast Premium Security destroyed Firefox and Mozilla Thundbird with the pref.js files of the browsers as infected files with VBS Gamaredon-CM.

I don't have my email accounts and my emails accessible anymore.

PLEASE HELP !

Offline emwillsea

  • Newbie
  • *
  • Posts: 4
Re: Avast and Firefox False Positive
« Reply #11 on: March 22, 2022, 08:47:47 PM »
Is that official from Avast and not just from a forum post?
This problem appears to have quarantined my Firefox profile and my Thunderbird profiles are now missing although all the quarantined files look like they come from Firefox.

Offline Hopper15

  • Full Member
  • ***
  • Posts: 105
Re: Avast and Firefox False Positive
« Reply #12 on: March 22, 2022, 09:16:02 PM »
I got the same thing today as well. The files are in my quarantine. I had to refresh Firefox.
Win 8.1 64 bit 16GB Avast Free/Malwarebytes Pro/CCleaner

Offline CBinRIC

  • Newbie
  • *
  • Posts: 5
Re: Avast and Firefox False Positive
« Reply #13 on: March 22, 2022, 09:18:20 PM »
Reddit user running AVG also reported infection by VBS:Gamaredon-CM about 2 hr ago.   This may not be an AVAST issue. 

https://www.reddit.com/r/ukraine/comments/tk8q8z/is_anyone_else_getting_notifications_for_malware/

Offline emwillsea

  • Newbie
  • *
  • Posts: 4
Re: Avast and Firefox False Positive
« Reply #14 on: March 22, 2022, 10:58:44 PM »
When attempting to restore the quarantined .js file and overwrite the existing file, it cannot do this.  Where do we go from here?