Author Topic: False positive? win32:malware-gen  (Read 3180 times)

0 Members and 1 Guest are viewing this topic.

Tobias4051

  • Guest
False positive? win32:malware-gen
« on: January 09, 2011, 09:22:50 PM »
Hi,

During a boot scan today the following file was marked as a virus:
c:\MSOcache\Allusers\90000409-6000-11d3-8cfe-0150048383c9\L2561403.cab|>Finder.exe
infected by
win32:Malware-gen

it was moved to chest.

Could this be a false positive?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89065
  • No support PMs thanks
Re: False positive? win32:malware-gen
« Reply #1 on: January 09, 2011, 09:46:00 PM »
There are a few topics relating to finder.exe and it looks like a false positive, so hopefully there will be a virus definitions update soon to correct it.

Ensure you have the latest signature updates and scan the file again within the chest.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2294
Re: False positive? win32:malware-gen
« Reply #2 on: January 10, 2011, 10:00:41 AM »
Hello,
send us (virus@avast.com) the file to analyze, please.

Milos

Tobias4051

  • Guest
Re: False positive? win32:malware-gen
« Reply #3 on: January 10, 2011, 12:15:54 PM »
Hi,

Thank you for the fast reply.

Is it ok to email the file from the chest to the above address?  When the file is in the chest and I wish to send it as an attachment on an email, where do I browse to in order to find the file?

Do I have to restore the file to the original location and then email it from there?

Many thanks

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2294
Re: False positive? win32:malware-gen
« Reply #4 on: January 10, 2011, 03:36:26 PM »
Hello,
first try ro rescan that file -- this FP should be fixed in current VPS (110110-0).

Milos

Tobias4051

  • Guest
Re: False positive? win32:malware-gen
« Reply #5 on: January 10, 2011, 07:41:28 PM »
Hi,

I tried to restore the file to do another boot scan with the file back where it was, however it says that it can't be restored, the option in the drop down list is gray.

I have scanned the file in the chest several times, including once immediately after the boot scan that put it in the chest, before any avast updates.  When the file in the chest is scanned it has always said 'no virus'.

Thanks for your help.