Author Topic: false positive?  (Read 8220 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: false positive?
« Reply #15 on: June 12, 2011, 07:35:41 PM »
The hjt logfile seems OK, but there is new rogue av malware that sometimes installs on:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = 
-http://apod.nasa.gov/apod/astropix.html

Do you get popups with fake av or do you get redirected to fake sites?

Maybe essexboy may have a cleansing routine for you, a run with TDSSKiller.exe and OTL log analysis, wait untill he appears,

polonus
« Last Edit: June 12, 2011, 07:37:55 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

riobio

  • Guest
Re: false positive?
« Reply #16 on: June 12, 2011, 07:43:57 PM »
I have NOT had any popups with fake av, and there has not been any redirects.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: false positive?
« Reply #17 on: June 12, 2011, 07:51:14 PM »
No further problems would suggest that MBAM killed whatever it was  ;D

riobio

  • Guest
Re: false positive?
« Reply #18 on: June 12, 2011, 08:00:39 PM »
No further problems would suggest that MBAM killed whatever it was  ;D

Thanks to all; I truly appreciate your assistance.
riobio

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89033
  • No support PMs thanks
Re: false positive?
« Reply #19 on: June 12, 2011, 08:15:32 PM »
Hi,
Run hijack this from trend micro and post the log to read? Sure a malware process is running!

Sorry bobo1, but HijackThis is a busted flush now, it hasn't had any development for probably over 18 months and it just isn't up to the task any longer. It doesn't even look in the areas that modern malware hides, this is why specialist analysis tools have come to the fore like OTS as you will see mentioned in the forums.
David R, you're saying the hijack this is useless?  If so, do you have a suggestion?  Just finished deleting all system restore points, making a new one, doing a full mbam scan which shows zero "0" infections.  Am I done, or is there something else?

Pretty much so, any security application that hasn't had development in over a year, really isn't keeping up with developments.

Any suggestions would be dependant on the circumstances, e.g. if you were still getting symptoms and other general removal tools haven't resolved it, which doesn't appear to be the case. But as I mentioned in the quoted text OTS, but that is a specialist tool that requires specialist analysis (essexboy, etc.), so it isn't a tool that you jump straight in and run without it being requested.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: false positive?
« Reply #20 on: June 13, 2011, 08:57:31 AM »
Thanks for the input; finally got a link to submit the FP.

You're welcome..!
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0