After quite some while started a smart scan again with my updated a-squared free scanner. It came up with a brilliant FP according to my knowledge of malware definitions. 34 instances of the Netcraft Toolbar anti-phishing toolbar, very safe according to me, a medium security risk according to a-squared. Here is my scan log:
//////////////////////////
a-squared Free - Version 2.1
Scan settings:
Objects: Memory, Traces, Cookies, C:\WINDOWS, C:\Program Files
Scan archives: On
Heuristics: On
ADS Scan: On
What are they doing there at a-squared, plucking their noses? In such a fashion their scanner is being turned into a risk tool in the hands of the uninformed. What do the forum members think of all this? Shall we advise against using this spyware scanner or is there still hope, that a-squared will turn back on it’s sloppy ways?
You were so right there, and the update I installed, thanks for the heads-up, and have a good night’s rest, my friend. It is 10.20 AM here on the European Continent, just had my coffee.
it’s 3:25 here damian and no coffee-that animation above is where i am going NOW!!!
sorry for your false positve from the product inserted below
in case you want to update again damian ;D
Shame on a-squared, again…
Maybe they’re fighting for high number of detectable things and just trying to persuade users to get the anti-malware (payed) version.
It’s just a fact of life, a false positive, if your going to ditch each and every security application that has an FP, you might not be on these forums ;D It has to be user education and unfortunately, many get in trouble before that education ‘never delete’ quarantine or ignore (if low risk assessment) and investigate.
I’m currently ignoring two registry key detections in adaware that I believe are not an issue, I choose to ignore them (not exclude) so I can monitor if suddenly they are no longer detected. I quite like adaware but it is a real hassle to try and report a possible false positive.
David, why are you been so radical?
Do you use a-squared? Did you know about a-squared failures to restore infections from Quarantine and even avoiding the user to boot? It’s not a silly false positive but a program that cannot manage its own Quarantine functions. The encryption of Quarantined items fails from time to time… it’s silly… pathetic…
I’ll keep blaming against a-squared false positives, yes I will. Lack of support of its forum is another problem…
I think David was suggesting that if you were going to abandon every product that ever produced a false positive, then you would have no anti-malware scanners left to use, including avast!.
The quarantine error with a-Squared was a serious issue, but it’s wrong to imply that support on the a-Squared forum is a problem.
The issue was fixed the same day it was reported with an apology and an explanation posted by the a-Squared team. What more could be expected? ???
It is a false alert, or better said a bug in our signatures.
The signature file has been fixed now. Please run an online update to verify.
I apologize for the troubles it made!
The problem was, that it did not try to quarantine the missing reg key only, it quarantined nearly the whole registry. That can't work and would take hours to complete. I guess that's the reason why it was not able to restore it.
Your complaint about lack of support in the same thread was mad a week after these postings!
A couple of FP issues I’ve had were dealt with promptly after I reported them on the forum.
With the detection by a-Squared of malware quarantined by other anti-malware products, the a-Squared team posted an entirely reasonable response:
Btw. if you require immediate answers, please post a support ticket at the customer center. We're not hourly watching the progress of every single forum thread.
even spybot had a false positive incident the other day and corrected it-so not all software is perfect
i posted this in updates yesterday
Spybot Search & Destroy - http://spybot.info/en/updatehistory/index.html
An update is available to correct a false positive which occurred with yesterday’s update
At the time of posting the website had not been updated but the update is available.
i have just had my share of troubles with a-squared free and decided not to use it anymore-my computer-my choice of software that works for my computer
I’ve posted in two threads and does not receive any official answer about the bug. I’m not implying anything, just reporting a personal experience, sad one.
The issue? No, for sure not. They’ve corrected the false positive detection.
Quarantine was still unable to restore the deleted keys of the Registry and the Quarantine has still unencrypted items.
Still there was a position from them about the Registry restoration.
Neither in Safe Mode…
Reasonable? I’ve sent the email to the support team… receive nothing…
They don’t fix the problem… they fix the false positive.
Frank, I won’t think different. I’m not a fan-boy. If I don’t like the product or the support I will complain.
Frank exactly understood my comment in his reply (quote below), that false positives are a fact of life that have to be worked around rather than jump from application to application as it effects them all including avast to one degree or another. Some won’t even admit to false positives.
Your issue with the functionality is an entirely different matter (serious), but in this topic we are talking about false positives, that and only that was what my post was about.
The problem was, that it did not try to quarantine the missing reg key only, it quarantined nearly the whole registry. That can't work and would take hours to complete. I guess that's the reason why it was not able to restore it.
The a-Squared statement has explained the issue to my satisfaction at least: the FP resulted in the quarantine feature being required to back up the whole registry, something it was not designed to do and could not reasonably be expected to do.
So there is no ‘bug’ in the quarantine feature.
Of course a-Squared can be criticised for not spotting a FP with such disastrous consequences in the first place.
I think you have a bug ;D in your quoting again Tech as you are putting words into my mouth again ;D when it was Frank who made the statement you quoted.
So there is no 'bug' in the quarantine feature.
Yes, there are:
1. Non-encrypting quarantine itens.
2. If restore feature won't work, at least I expect a message: "you won't be able to roll-back this operation. Do you want to proceed?"
Quarantine items were encrypted, but some other AV products were able to decrypt a-Squared quarantine files because both used the same ‘generic decryption module’. You pointed this out in a thread started on 29th April, on 1st May you wrote:
I'll give up on waiting for an official answer...
It's a pity. Lack of support
Having given up on a-Squared support, perhaps you didn’t notice the two relies from the a-Squared team posted the same day:
Other virus scanners come with a generic decryption module that are able to unpack our crypted quarantine files. We'll use a stronger encryption in the next version.
Today's beta update should fix that problem.
I think three days to investigate, identify and fix a problem is actually pretty good support, and I’m having trouble understanding your impatience on the a-Squared forum. :
If a-Squared had seen the problem coming, they would presumably have just not introduced the FP identification. They are saying that quarantine is not designed to back up the entire registry. It’s a bit like saying ‘My seat belt didn’t protect me when the wheel fell off my car, it careered of the road and exploded: why doesn’t the manufacturer provide better seat belts?’ What you should be asking is ‘Please can you ensure the wheel doesn’t fall off my next car please?’ ;D