Author Topic: Avast ID'ed file as infected, but virscan.org says clean (AVAST leg says clean)  (Read 3461 times)

0 Members and 2 Guests are viewing this topic.

Wonnerber Snerr

  • Guest
Avast 6.0.1000 reported SciTE4AutoIt3.exe (open-source script writing software, straight from its website, so should be clean) was infected with Threat:Win32:Trojan-gen.  Wanting to keep the program, I verified with virscan.org (on-line multiple engine scanner).  34 of 37 engines found it clean, including avast!.  It was using same virus definitions as I, but different engine (4.7.4 vs 6.0.1000).  My local avast hits on this file only on the custom scan (passes the daily quick scan).  Major differences are custom has Heuristics=High, test whole files, scan all packers (yes, it does take a looooooong time).

question 1:  with the settings I have on custom scan, I realize false-positives are more common.  Are there further steps to take to verify, other than on-line multiple-engine scanners?

question 2:  new to virscan.org, so at what % would you start to worry about a file?  3/37 or 8% seems nothing to worry about.


Offline SpeedyPC

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3398
  • Avast shall conquer the whole world
You might wanted to check from VirusTotal http://www.virustotal.com/index.html to make sure is not FP
Gigabyte 670 LGA1200 Full ATX MB | Intel Core i9-13900 CPU/LGA 1700 | GeForce Nvidia RTX-4070/12GB | 32GB DDR4 | 2 x 1TB Samsung SSD | W11 Home 64bit | Avast Premium v24.3.6108 | Avast SecureLine VPN | Avast Secure Browser | Avast Driver Updater | Avast BreachGuard | Firefox 64bit | MalwareBytes Premium | Adguard Premium | CCleaner Portable | Macrium Reflect | 7-Zip

Wonnerber Snerr

  • Guest
Hello Speedy,
OK, I've scanned on VirusTotal, and that makes me feel a bit uneasy (9 out of 42 infected).  Yet again, avast was clean.  But I'd bet they don't have scanners set so high as my custom scan.  That aside, should 9/42 be of concern? 

Offline SpeedyPC

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3398
  • Avast shall conquer the whole world
Hello Speedy,
OK, I've scanned on VirusTotal, and that makes me feel a bit uneasy (9 out of 42 infected).  Yet again, avast was clean.  But I'd bet they don't have scanners set so high as my custom scan.  That aside, should 9/42 be of concern?  

What I would do is wait for essexboy he has a better understanding all kinds of virus and wait further support from someone who has better experience, my guess 9/42 it pretty low just wait for essexboy before you do anything further ;) ;D

Edit: Do you have Malwarebytes' Anti-Malware (MBAM) installed on your PC ???
« Last Edit: March 15, 2011, 05:42:03 AM by SpeedyPC »
Gigabyte 670 LGA1200 Full ATX MB | Intel Core i9-13900 CPU/LGA 1700 | GeForce Nvidia RTX-4070/12GB | 32GB DDR4 | 2 x 1TB Samsung SSD | W11 Home 64bit | Avast Premium v24.3.6108 | Avast SecureLine VPN | Avast Secure Browser | Avast Driver Updater | Avast BreachGuard | Firefox 64bit | MalwareBytes Premium | Adguard Premium | CCleaner Portable | Macrium Reflect | 7-Zip

Wonnerber Snerr

  • Guest
Speedy, yes, I have MBAM installed.  It found no infection with the file, nor did SUPERAntiSpyware.

Offline SpeedyPC

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3398
  • Avast shall conquer the whole world
Speedy, yes, I have MBAM installed.  It found no infection with the file, nor did SUPERAntiSpyware.

Thank you just checking ;)
Gigabyte 670 LGA1200 Full ATX MB | Intel Core i9-13900 CPU/LGA 1700 | GeForce Nvidia RTX-4070/12GB | 32GB DDR4 | 2 x 1TB Samsung SSD | W11 Home 64bit | Avast Premium v24.3.6108 | Avast SecureLine VPN | Avast Secure Browser | Avast Driver Updater | Avast BreachGuard | Firefox 64bit | MalwareBytes Premium | Adguard Premium | CCleaner Portable | Macrium Reflect | 7-Zip