Author Topic: probable FP alert after the latest virus definition update 102205-2  (Read 4492 times)

0 Members and 1 Guest are viewing this topic.

paraxeno

  • Guest
first scan of the day was just before latest virus def update, and got an alert on adobearmhelper.exe as a high risk virus, send that one to labs - and put in chest Then I run a boot scan that showed no probem or infection whatsoever.

run a second scan with latest definitions 102205-2 and got a high risk alert reported as follows:

process 4084 [seamonkey.exe]memory block 0x0000000005B00000, block size 1048576 severity high status threat JS:ScriptIP-inf [Trj]

I have the free avast program already updated to latest engine and vds, please advise should I worry?

thanks in advance

« Last Edit: February 05, 2012, 04:46:38 PM by paraxeno »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: probable FP alert after the latest virus definition update 102205-2
« Reply #1 on: February 05, 2012, 04:42:12 PM »
...please advise should I worry?

You can safely ignore the memory detection.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

paraxeno

  • Guest
Re: probable FP alert after the latest virus definition update 102205-2
« Reply #2 on: February 05, 2012, 04:45:52 PM »
thank you so very much!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89053
  • No support PMs thanks
Re: probable FP alert after the latest virus definition update 102205-2
« Reply #3 on: February 05, 2012, 04:46:51 PM »
What you do, don't scan memory.

- Detections in Memory -
My guess is that you are doing a Custom scan in which you have elected to scan Memory and that all these detections are in memory or are listings of files that can't be scanned. Since they aren't physical files they can't be moved to the chest, deleted, etc. so there is no action that can be taken, hence the Apply button being greyed out.

The detections in memory are frequently other security applications loading unencrypted virus signatures into memory. Having set off a scan of memory by an antivirus application looking for virus signatures, don't be too surprised if it finds some in memory.

In this case finding a javascript issue in memory when loaded by a browser executable isn't too strange I would say. But the best advice is not to scan memory.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

paraxeno

  • Guest
Re: probable FP alert after the latest virus definition update 102205-2
« Reply #4 on: February 05, 2012, 04:47:26 PM »
should I put the first file adobearmhelper.exe back in its original place or leave it in the virus chest?

paraxeno

  • Guest
Re: probable FP alert after the latest virus definition update 102205-2
« Reply #5 on: February 05, 2012, 04:48:33 PM »
ok David will do that too will change my scan settings thanks

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89053
  • No support PMs thanks
Re: probable FP alert after the latest virus definition update 102205-2
« Reply #6 on: February 05, 2012, 04:52:58 PM »
The first file, has nothing to do with the second detection, moving it back (restore) from the chest would probably result in avast alerting again.

For now leave it in the chest and periodically scan it 'within' the chest, when it is no longer detected then you can 'restore' it. The restore function leaves a copy in the chest (just in case), confirm that the file is back in the original location and then you can manually delete the copy from the chest.

####
Send the sample to avast as a possible False Positive:
Open the chest and right click on the file and select 'Submit to virus lab...' complete the form and submit, the file will be uploaded during the next update. A link to this topic wouldn't hurt.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

paraxeno

  • Guest
Re: probable FP alert after the latest virus definition update 102205-2
« Reply #7 on: February 05, 2012, 04:58:34 PM »
ok done it all

thank you so very much  :)

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: probable FP alert after the latest virus definition update 102205-2
« Reply #8 on: February 05, 2012, 05:18:17 PM »
thank you so very much!

You're welcome.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89053
  • No support PMs thanks
Re: probable FP alert after the latest virus definition update 102205-2
« Reply #9 on: February 05, 2012, 06:03:54 PM »
ok done it all

thank you so very much  :)

You're welcome.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2294
Re: probable FP alert after the latest virus definition update 102205-2
« Reply #10 on: February 06, 2012, 08:55:18 AM »
run a second scan with latest definitions 102205-2 and got a high risk alert reported as follows:

Hello,
I think that 102205-2 was not latest definition. I would expect 120205-x.

Milos

paraxeno

  • Guest
Re: probable FP alert after the latest virus definition update 102205-2
« Reply #11 on: February 06, 2012, 12:17:03 PM »
it updated to 102205-3 late at night for me here in Greece milos... will run scans today as well to check it out. Thanks :D