Author Topic: since 2 days we have Avast armageddon  (Read 2243 times)

0 Members and 1 Guest are viewing this topic.

Offline Tom610

  • Full Member
  • ***
  • Posts: 126
since 2 days we have Avast armageddon
« on: March 02, 2023, 09:52:12 AM »
1. Since feburary 28th Avast is detecting many .doc files (MW97:CVE-2006-2492) --> Case has been opened
2. As of this morning Avast behavior shield is going crazy! We have detections in an amount that we never had before. Something must have been change from Avast! Short Workaround: disableing behavior shield within the global policies...

Offline Tom610

  • Full Member
  • ***
  • Posts: 126
Re: since 2 days we have Avast armageddon
« Reply #1 on: March 06, 2023, 03:52:10 PM »
Update:

After disableing the behavior shield last week (which worked so far) we see it still running on customer clients right away with detections of it.

This is really a mess Avast!

Action: Create a case --> revering to case 15814728 and informing contacts at Avast... hope we can speed up some things here...
« Last Edit: March 06, 2023, 04:15:59 PM by Tom610 »

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48564
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: since 2 days we have Avast armageddon
« Reply #2 on: March 06, 2023, 03:56:05 PM »
Reported to Avast.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline vojtech.vobr

  • Avast team
  • Newbie
  • *
  • Posts: 3
Re: since 2 days we have Avast armageddon
« Reply #3 on: March 06, 2023, 04:52:04 PM »
Hello,

fix for this issue has been released in virus definitions update 230302-00, can you still reproduce it with current virus definitions?

Offline Tom610

  • Full Member
  • ***
  • Posts: 126
Re: since 2 days we have Avast armageddon
« Reply #4 on: March 06, 2023, 05:09:48 PM »
Hello,

fix for this issue has been released in virus definitions update 230302-00, can you still reproduce it with current virus definitions?

To which problem of the two shall this apply? DOC or behavior shield?

Regardless of any definition updates: Those would not explain why behavoir shield is active again although disabled within global policies...

Offline vojtech.vobr

  • Avast team
  • Newbie
  • *
  • Posts: 3
Re: since 2 days we have Avast armageddon
« Reply #5 on: March 06, 2023, 05:30:27 PM »
I'm sorry, I missed the behavior shield question, only detections on DOC files were solved by virus definitions update.

We're currently working on resolving the behavior shield issue.

Offline Tom610

  • Full Member
  • ***
  • Posts: 126
Re: since 2 days we have Avast armageddon
« Reply #6 on: March 07, 2023, 12:56:10 PM »
As per case 17592044 this problem (behavior shield) was also fixed...

At least as of today we do not have suche a great amount of detection/blocking mails from the hub. This indicates that it could be fixed indeed.

I'll keep an eye on this!

Offline Tom610

  • Full Member
  • ***
  • Posts: 126
Re: since 2 days we have Avast armageddon
« Reply #7 on: March 07, 2023, 01:43:32 PM »
Negative: I enabled BS within our global client policy, right after that a bunch of Hub detection mails where sent...

This has definitely not been solved!!!!

Again I disabled BS since customers can't work with this and we still have 15814728 unsolved.

God this is so bad work guys!  >:(

Offline PDI

  • Avast team
  • Full Member
  • *
  • Posts: 159
Re: since 2 days we have Avast armageddon
« Reply #8 on: March 08, 2023, 12:40:13 PM »
Hi Tom610,

the issue was fixed but there may be some pending detections for some reason. There are 2 other shields running in the process which may have some impact on the results after the BS restart.

Could you please restart the devices before enabling the BS?

Thanks,
PDI

Offline Tom610

  • Full Member
  • ***
  • Posts: 126
Re: since 2 days we have Avast armageddon
« Reply #9 on: March 10, 2023, 04:20:27 PM »
I have activated BS as of today 10.57 a.m german time.

We'll see next week how it goes with this.

Offline Tom610

  • Full Member
  • ***
  • Posts: 126
Re: since 2 days we have Avast armageddon
« Reply #10 on: March 14, 2023, 02:16:01 PM »
Update: Seems that Avast has solved both problems. Hub has calm down... armageddon is over...  ::)