Author Topic: Sandbox flags O&O Defrag 2000 Free as potentially unsafe  (Read 4271 times)

0 Members and 1 Guest are viewing this topic.

kd5

  • Guest
Sandbox flags O&O Defrag 2000 Free as potentially unsafe
« on: February 24, 2011, 08:23:37 PM »
C:\WINDOWS\system32\OOD2000.exe, opened by C:\WINDOWS\system32\services.exe


I'm fairly certain you can tell Avast that O&O Defrag is safe.       -kd5-

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89032
  • No support PMs thanks
Re: Sandbox flags O&O Defrag 2000 Free as potentially unsafe
« Reply #1 on: February 24, 2011, 08:37:15 PM »
Well if you select Run normally and remember this answer, etc.

I believe if you subscribe to the avast Community IQ feature then that information should be communicated to avast, to help other avast users with this same application, though it is very old if 2000 relates to the year.

Perhaps newer versions might not be considered suspicious.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

kd5

  • Guest
Re: Sandbox flags O&O Defrag 2000 Free as potentially unsafe
« Reply #2 on: February 24, 2011, 11:14:14 PM »
Well if you select Run normally and remember this answer, etc.

I believe if you subscribe to the avast Community IQ feature then that information should be communicated to avast, to help other avast users with this same application, though it is very old if 2000 relates to the year.

Perhaps newer versions might not be considered suspicious.

1.  I did select 'Run Normally' and 'Remember this answer' but why should I have to do that for a legitimate application?

2.  I'm letting the Community know now, in this thread, that it's happening, so this is a moot point.

3.  It shouldn't matter that O&O Defrag 2000 Free is an older application and I don't understand why that should have any bearing on this issue.  If Avast's Sandboxing is going to protest legitimate applications, regardless of how old they are, from running on my computer, or my customer's computers, then Avast's Sandboxing is not nearly as intelligent as it needs to be for it to be a viable solution to the problems it is attempting to protect us from.       -kd5-
« Last Edit: February 24, 2011, 11:22:51 PM by kd5 »

kd5

  • Guest
Re: Sandbox flags O&O Defrag 2000 Free as potentially unsafe
« Reply #3 on: February 24, 2011, 11:16:14 PM »
I just tried to install Nero 6, Avast's Sandboxing protested to Nero's installers.

You have got to be kidding me.       -kd5-
« Last Edit: February 24, 2011, 11:21:22 PM by kd5 »

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re: Sandbox flags O&O Defrag 2000 Free as potentially unsafe
« Reply #4 on: February 24, 2011, 11:30:50 PM »
3.  It shouldn't matter that O&O Defrag 2000 Free is an older application and I don't understand why that should have any bearing on this issue.  If Avast's Sandboxing is going to protest legitimate applications, regardless of how old they are, from running on my computer, or my customer's computers, then Avast's Sandboxing is not nearly as intelligent as it needs to be for it to be a viable solution to the problems it is attempting to protect us from.       -kd5-

Kd5, I understand your concerns, but on the other hand, from what you have just said, the O&O executable file really looks incredibly suspicious...

I mean, look at this:
- the file is located in the Windows directory - something that legitimate software rarely does, but malware does all the time
- the file is obviously not digitally signed (which is against good habits)
- the file is likely to be internally encrypted

All in all, it really looks like a piece of malware.
Now, of course, we can whitelist files like this, but the fact is that the AutoSandbox was designed to alert on those "gray zone" files, really.

Thanks
Vlk
If at first you don't succeed, then skydiving's not for you.

Offline Gopher John

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2098
Re: Sandbox flags O&O Defrag 2000 Free as potentially unsafe
« Reply #5 on: February 25, 2011, 12:26:56 AM »
I'm satisfied with how the AutoSandbox works.  It alerted on C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe on my machine.  I set it to run normally, as it has been on my machine since 2006.  It's part of the software that came with my HP 7310 AIO printer, and HP software just isn't the best.  As an extra precaution, I sent the file to VirusTotal which gave it a clean bill of health.

As far as I'm concerned, the AutoSandbox is working as advertised.
AMD A6-5350M APU with Radeon HD Graphics, 8.0GB RAM, Win7 Pro SP1 64bit, IE11
i7-3610QM 2.3GHZ, 8.0GB Ram,  Nvidia GeForce GT 630M 2GB, Win7 Pro SP1 64bit, IE 11
Common to both: Avast Premium Security 19.7.2388, WinPatrol Plus, SpywareBlaster 5.5, Opera 12.18, Firefox 68.0.2, MBam Free, CCleaner

sandeep108

  • Guest
Re: Sandbox flags O&O Defrag 2000 Free as potentially unsafe
« Reply #6 on: February 25, 2011, 08:55:06 AM »
Auto sandbox is also warning Primo PDF 5.2 (pdf printer driver) as potentially unsafe.

Dalewyn

  • Guest
Re: Sandbox flags O&O Defrag 2000 Free as potentially unsafe
« Reply #7 on: February 25, 2011, 09:10:28 AM »
Had AutoSandbox ask me about sandboxing HDD Health v2.1 Beta Build 159 as well. I simply told it to run normally and remember my choice as I've used the program for a couple years now and is most certainly legit as far as I'm concerned.

I see no problem, seeing as AutoSandbox is merely suggesting the use of sandboxing rather than forcing sandbox or blocking the program. It's just Avast being nice and saying "Umm, do you really want to run this? I find this software strange, just tell me if it isn't. :)"