Author Topic: avast.setup false positive?  (Read 5803 times)

0 Members and 1 Guest are viewing this topic.

eggyolkio

  • Guest
avast.setup false positive?
« on: April 23, 2012, 06:53:45 PM »
hi everyone,

i'm having trouble with avast free continually detecting avast.setup in the c:\program files\avast software\avast\setup as a hidden rootkit process.  when it scans it shows the file as PID0 to PID12 and when looking at the scan results avast.setup is repeatedly shown even though it's the same file.  when i try to remove or move the avast.setup it says "access denied"

no other software (spybot, malware bytes, malware fighter) has been able to detect anything bad in that folder, so i suspect it's a false positive.  even so, i'm quite worried.  can anyone help me?

Offline mikaelrask

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1556
Re: avast.setup false positive?
« Reply #1 on: April 23, 2012, 07:23:22 PM »
hey and welcome to the forum.

where did you download the avast installation file?

avast wouldn't give a threat alert on its own program.
So could you have downloaded a malware infected version?
Windows 8.1 amd a10-5700 64 bit
12 GB ram 1 tb hard drive. Avast 18, MBAM

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: avast.setup false positive?
« Reply #2 on: April 23, 2012, 08:44:04 PM »
eggyolkio, any other antivirus running in this computer at the same time of avast?
The best things in life are free.

eggyolkio

  • Guest
Re: avast.setup false positive?
« Reply #3 on: April 24, 2012, 02:44:05 PM »
Hi guys, thanks for replying so promptly :)

I downloaded the installer file from majorgeeks.com, which I thought was pretty safe.

No, the only anti-virus program running is Avast Free.  I have Spybot, Malwarebytes, SpywareBlaster and Malware Fighter running.  My OS is Win 7 x64

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: avast.setup false positive?
« Reply #4 on: April 24, 2012, 02:52:06 PM »
I have Spybot, Malwarebytes, SpywareBlaster and Malware Fighter running.
Do you mean as resident? Or only on demand?
I don't know much about Malware Fighter... Spybot is outdated for security imho, MBAM is very good, SpywareBlaster is an immunization only... But, maybe, some of all of them is conflicting with avast!.
The best things in life are free.

Offline Gopher John

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2098
Re: avast.setup false positive?
« Reply #5 on: April 24, 2012, 03:16:06 PM »
SpywareBlaster shouldn't be causing a problem, as no part of it is resident.  I have it's full immunizations enabled.

If you are running the current SpyBot Search & Destroy 1.6.2, you may wish to disable it's resident protection.  See http://www.safer-networking.org/en/howto/disable.html.  This doesn't remove it's immunizations but keeps the TeaTimer from loading into memory.  If you are using SpyBot S&D 2.0.7 Beta 5, it currently has no resident protection.

I'm also not familiar with Malware Fighter, but since it's from IOBit I won't touch it.
AMD A6-5350M APU with Radeon HD Graphics, 8.0GB RAM, Win7 Pro SP1 64bit, IE11
i7-3610QM 2.3GHZ, 8.0GB Ram,  Nvidia GeForce GT 630M 2GB, Win7 Pro SP1 64bit, IE 11
Common to both: Avast Premium Security 19.7.2388, WinPatrol Plus, SpywareBlaster 5.5, Opera 12.18, Firefox 68.0.2, MBam Free, CCleaner

Offline AntiVirusASeT

  • Poster
  • *
  • Posts: 462
Re: avast.setup false positive?
« Reply #6 on: April 24, 2012, 03:25:38 PM »
yes, files from majorgeeks are highly safe.

i recommend u to remove malware fighter...its real-time protection is next to nothing. disable spybot's real-time, its heavy on system resources, not really effective either. keep malwarebytes as a free on-demand scanner, its a gd compliment to any antivirus programs.

eggyolkio

  • Guest
Re: avast.setup false positive?
« Reply #7 on: April 25, 2012, 05:44:21 AM »
okay remove malware fighter, and keep malwarebytes.  i might as well keep spybot i don't mind the drain...

but i still don't understand why avast free detected those files...

Offline AntiVirusASeT

  • Poster
  • *
  • Posts: 462
Re: avast.setup false positive?
« Reply #8 on: April 25, 2012, 06:18:37 PM »
@eggyolkio: post ur fp enquires in this section of the forum (http://forum.avast.com/index.php?board=4.0)
avast team ppl in charge of fp solving will help u there.

though i admit its weird that avast detected itself as malware.


Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48559
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: avast.setup false positive?
« Reply #9 on: April 25, 2012, 09:08:43 PM »
@eggyolkio: post ur fp enquires in this section of the forum (http://forum.avast.com/index.php?board=4.0)
avast team ppl in charge of fp solving will help u there.

though i admit its weird that avast detected itself as malware.

At this point, we haven't confirmed that it was actually avast! that gave the alert.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89052
  • No support PMs thanks
Re: avast.setup false positive?
« Reply #10 on: April 25, 2012, 09:23:42 PM »
@eggyolkio: post ur fp enquires in this section of the forum (http://forum.avast.com/index.php?board=4.0)
avast team ppl in charge of fp solving will help u there.

though i admit its weird that avast detected itself as malware.

At this point, we haven't confirmed that it was actually avast! that gave the alert.

I think that was confirmed in the OP first post (my emphasis):
Quote from: eggyolkio
i'm having trouble with avast free continually detecting avast.setup in the c:\program files\avast software\avast\setup as a hidden rootkit process. 
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48559
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: avast.setup false positive?
« Reply #11 on: April 26, 2012, 08:20:45 AM »
I'm running avast!7 free but I don't have avast.setup in the folder the OP mentions. ???

A screen shot would probably helpful.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89052
  • No support PMs thanks
Re: avast.setup false positive?
« Reply #12 on: April 26, 2012, 01:32:12 PM »
Well the avast.setup is created on the fly (from setup.ovr) if there is an update to be done, on completion of the update as far as I'm aware it is then removed (as there is no avast.setup file in that location for me either).

EDIT: - Note, when avast.setup is running its PID isn't 0-12 (which are system PIDs) although for user name it is listed/runs under System. The last time I checked (manual update check) it was 3 thousand and something.
« Last Edit: April 26, 2012, 01:37:46 PM by DavidR »
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security