Author Topic: Anyone know what this threat is possible false positive  (Read 11925 times)

0 Members and 1 Guest are viewing this topic.

Offline jon67236723

  • Newbie
  • *
  • Posts: 4
Anyone know what this threat is possible false positive
« on: December 26, 2022, 06:55:32 PM »
I wasn't downloading anything i stepped away from my laptop and when i returned this message was popped up. I'm not 100% what AWCC is but when i googled it  it shows AlienWare Command Center which makes since i have that installed on my laptop. whether its Alienware related i don't know, i moved it to quarantine for now.

IDP.HEUR.26 is the threat name not sure what it is.

https://i.imgur.com/M6NIHI7.png

Can anyone tell me if this is a threat or if its a false positve thanks.

EDIT: I downloaded the latest Alienware command center which was 5.5.35.0 from Dell's website. Scanned it it was clean so i installed it and the install ran without issue.
« Last Edit: December 26, 2022, 07:18:48 PM by jon67236723 »

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89026
  • No support PMs thanks
Re: Anyone know what this threat is possible false positive
« Reply #1 on: December 26, 2022, 07:19:05 PM »
Please attach your screenshot to your next post, many won't visit unknown 3rd party sites.

IDP.HEUR.26 - IDP (Intrusion Detection Protection), HEUR = Heuristic, the method of detection and the number, defining which heuristic detection (I guess, the first two elements of the detection being more important).
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline jon67236723

  • Newbie
  • *
  • Posts: 4
Re: Anyone know what this threat is possible false positive
« Reply #2 on: December 26, 2022, 07:24:19 PM »
Sorry i couldn't see the attach option at first

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89026
  • No support PMs thanks
Re: Anyone know what this threat is possible false positive
« Reply #3 on: December 26, 2022, 08:02:07 PM »
No problem.

As you aware of this setup_5.5.35.0.exe is, e.g. is this something you downloaded (Alienware command center). 

As this was something intentional, a program you had downloaded or an update, etc. then there is a little less concern.  As this is (or appears to be) the case the Detection is by the Behavior Shield, it is more of what the installation wants to do might be considered suspect.

I'm not familiar with the Avast One program version, but it should be similar to the Avast Antivirus Free that I'm using.

If you choose the Move to Quarantine option and it is in there.  You could open the Quarantine and select Send for analysis and give a brief description of the problem.  A link to this topic would help give more information than you could input on the submission.

If you didn't send it to Quarantine:
Then you can use the - Reporting a Possible False Positive File or Website - https://www.avast.com/false-positive-file-form.php.
You should get a response in a day or two. 
Same drill here give a link back to this topic as it contains a lot of information that should help.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline jon67236723

  • Newbie
  • *
  • Posts: 4
Re: Anyone know what this threat is possible false positive
« Reply #4 on: December 26, 2022, 08:29:10 PM »
This is something it downloaded or updated itself. I only downloaded the .exe after the detection just to see if it would flag the install which it didn't. Maybe because the app downloaded the update itself Avast flagged it.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89026
  • No support PMs thanks
Re: Anyone know what this threat is possible false positive
« Reply #5 on: December 26, 2022, 08:54:29 PM »
That is a possibility.

The thing that I find strange is that this is a detection by the Behaviour Shield (as in your image), if it was a detection on the downloaded file (rather than its actions) I would have expected the detection to have been made by the Web Shield.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security