Author Topic: False/positive Office 10 (XP) ...help?  (Read 5079 times)

0 Members and 1 Guest are viewing this topic.

tinto101

  • Guest
False/positive Office 10 (XP) ...help?
« on: November 28, 2009, 11:03:50 PM »
from 2-3 days AVAST 4.8

say to me that a file in a old  OFFICE-10  (office for XP)

is infect !?

later NEVER say this !

false posivite or ?


in how mode i post here the log and the name of this file or files ...here?



help me ::)

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89104
  • No support PMs thanks
Re: False/positive Office 10 (XP) ...help?
« Reply #1 on: November 28, 2009, 11:14:30 PM »
That is possible as if it was a false positive and someone reported and submitted a sample of the file, then it would be analysed and the signatures adjusted if confirmed as a false positive.

What is the malware name, the infected file name, where was it found e.g. (malware name, C:\windows\system32\infected-file-name.xxx) ? 
Check the avast! Log Viewer (right click the avast 'a' icon), Warning section, this contains information on all avast detections. C:\Program Files\Alwil Software\Avast4\ashLogV.exe
 
- Or check the source file using notepad C:\Program Files\Alwil Software\Avast4\DATA\log\Warning.log and copy and paste the entry.

That is why it is important never to delete, but to send detections to the avast chest.

Then if you think something may be a false positive then you need to confirm that detection:
You could also check the offending/suspect file at: VirusTotal - Multi engine on-line virus scanner and report the findings here the URL in the Address bar of the VT results page. You can't do this with the file securely in the chest, you need to extract it to a temporary (not original) location first, see below.

Create a folder called Suspect in the C:\ drive, e.g. C:\Suspect. Now exclude that folder in the Standard Shield, Customize, Advanced, Add, type (or copy and paste) C:\Suspect\* That will stop the standard shield scanning any file you put in that folder. You should now be able to export any file in the chest to this folder and upload it to VirusTotal without avast alerting.

Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

tinto101

  • Guest
Re: False/positive Office 10 (XP) ...help?
« Reply #2 on: November 29, 2009, 10:23:48 AM »
hi,,,it come on with the new version of AVAST .... last 2-3 days ago!

the strange is that with VIRUS TOTAL is not possible to upload to scan....why ????

Hi, avast team

with the new update of avast .... in this 2-3 days

avast say this file infect :


* Operazione 'Protezione residente' usata
* Avviato venerdì 27 novembre 2009 18.37.56
* VPS: 091126-1, 26/11/2009
*

C:\Programmi\Microsoft Office\OFFICE10-Silvano\OFFICE 10 -Silvano\SHAREPT\SQL\X86\BINN\DTSWIZ.EXE [L] Win32:Malware-gen (0)

*
* Operazione fermata: sabato 28 novembre 2009 4.34.00
* Utilizzato da 9 ora(e), 56 minuto(i), 4 secondo(i)
*

*
* Rapporto avast!
* Questo file è generato automaticamente
*
* Operazione 'Protezione residente' usata
* Avviato sabato 28 novembre 2009 12.13.30
* VPS: 091127-1, 27/11/2009


is real this file infect or?

OFFICE 10\SHAREPT\SQL\X86\BINN\DTSWIZ.EXE [L] Win32:Malware-gen


i try with VIRUS TOTAL online scanner but it say no
upload !!!!

help me ?

tinto101

  • Guest
Re: False/positive Office 10 (XP) ...help?
« Reply #3 on: November 29, 2009, 11:27:19 AM »

the correct sintax of the folder in avast shield is:

C: \suspect \

or

C: \suspect \ (and the little star)

????

tinto101

  • Guest
Re: False/positive Office 10 (XP) ...help?
« Reply #4 on: November 29, 2009, 01:26:49 PM »
i not found in avast the MENU to insert this  "suspect" folder !

where is in avast 4.8 programm ?

spg SCOTT

  • Guest
Re: False/positive Office 10 (XP) ...help?
« Reply #5 on: November 29, 2009, 01:30:51 PM »
Left click the avast! tray icon --> click 'more detail' if necessary -->scroll to and click on standard shield --> click customise --> click advanced tab --> click add --> type C:\Suspect\*

The * means that all files inside that folder will not be scanned by the standard shield and you can upload the file to virsutotal.

Once you are done with this issue, you can delete the folder and remove the exclusion if you wish.

tinto101

  • Guest
Re: False/positive Office 10 (XP) ...help?
« Reply #6 on: November 29, 2009, 08:20:33 PM »
shield   and customized

i have avast in italian language....

help ? ???

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89104
  • No support PMs thanks
Re: False/positive Office 10 (XP) ...help?
« Reply #7 on: November 29, 2009, 09:03:55 PM »
Whilst these images show English the position of the various Shields (avast Providers) and tabs/buttons should be the same.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

majoMo

  • Guest
Re: False/positive Office 10 (XP) ...help?
« Reply #8 on: November 29, 2009, 09:54:49 PM »
It seems to be a False Positive.

File is from MS, Office 2000 CD install.

VirusTotal report.

Please see this topic.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89104
  • No support PMs thanks
Re: False/positive Office 10 (XP) ...help?
« Reply #9 on: November 29, 2009, 10:46:36 PM »
Yes it looks like it in your case, but that is no guarantee for another user who may have a different version, is MS Office-10 the same as MS Office 2000 ?

You should send the sample to virus@avast.com zipped and password protected with the password in email body, a link to this topic might help and false positive in the subject.
 
Or you can also add the file to the User Files (File, Add) section of the avast chest (if it isn't already in the chest) where it can do no harm and send it from there. A copy of the file/s will remain in the original location, so you will need to take further action and can remove/rename that.
 
Send it from the User Files section of the chest (select the file, right click, email to Alwil Software). It will be uploaded (not actually emailed) to avast when the next avast auto (or manual) update is done.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

majoMo

  • Guest
Re: False/positive Office 10 (XP) ...help?
« Reply #10 on: November 29, 2009, 11:14:14 PM »
Yes it looks like it in your case, but that is no guarantee for another user who may have a different version, is MS Office-10 the same as MS Office 2000 ?

Please see VirusTotal report quoted above; at the bottom in "( Microsoft )". You can see there a lot of MS'app. about that file (included MS Office-10/Office XP).

You should send the sample to ( ... )

It was done yet through Avast warning to send False Positive.

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: False/positive Office 10 (XP) ...help?
« Reply #11 on: November 30, 2009, 06:27:54 AM »
Yes it looks like it in your case, but that is no guarantee for another user who may have a different version, is MS Office-10 the same as MS Office 2000 ?

I think the -10 denotes XP Office as in post above. So 2002. And maybe also for some later versions. Unfortunately I dont have an earlier one running any more. But I don't think -10 for the 2000 versions.
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.

Offline RZPogi

  • Sr. Member
  • ****
  • Posts: 237
Re: False/positive Office 10 (XP) ...help?
« Reply #12 on: November 30, 2009, 06:52:08 AM »
this is no isolated case. I tried to installed office XP on my friend's netbook, and avast detected dtswiz.exe as malware on the cd.

I had to exempt this file from scanning.

BTW: Office XP is Office 10
DESKTOP: Win 10, Avast 20 Free, Windows firewall, Malwarebytes free

LAPTOP: Win 10, Windows Defender, Malwarebytes free, Windows Firewall, Mcshield

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: False/positive Office 10 (XP) ...help?
« Reply #13 on: November 30, 2009, 07:15:55 AM »
on the cd  :o :o :o

I could only test the Office XP 10 that I have (see below)

Could not find dtswiz.exe on the disk


Edit - I scanned disk with current 4.8 definitions and no detection. Only means my disk is okay really. Sorry can't help any more, may run a test by installing on computer running avast if I get the chance.
« Last Edit: November 30, 2009, 07:41:46 AM by mkis »
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2294
Re: False/positive Office 10 (XP) ...help?
« Reply #14 on: November 30, 2009, 08:57:41 AM »
Hi,
thank you for notice False positive will be fixed in next  (091130-0) VPS update.


Milos