My Avast detected my frostiwire installer to contain a Win32:Agent-XIT[trj]
I tried to delete the installer and download a new one but its the same,Avast detected the new installer of frostwire to contain a trojan…I downloaded my frostwire installer at cnet download.com
Do you think this is a false positive because everytime I download the installer of frostwire Avast detects the installer to contain a trojan.
The problem being how do you determine it is a false positive. The web shield is what I assume is detecting this as it would scan the content before it is fully downloaded. You could pause the web shield (the standard shield may then alert) so you can at least get it on your system (don’t install unless you have confirmed).
Create a folder called Suspect in the C:\ drive, e.g. C:\Suspect. Now exclude that folder in the Standard Shield, Customize, Advanced, Add, type (or copy and paste) C:\Suspect* That will stop the standard shield scanning any file you put in that folder. You should now be able to export any file in the chest to this folder and upload it to VirusTotal without avast alerting.
Try a forum search, frostwire rings a bell and might have been discussed before.
I went to the frostwire forum and they said that it is the ask toolbar that it is being detected and they said that it is safe to install.Ill try what youve said,if the solution does not work maybe ill wait for a patch from Avast that excludes the part of frostwire as a virus.I know that this is a false positive because previous versions of avast did not detected the latest version of frostwire to contain a virus.
Whilst 3 detections might not be considered conclusive, considering the frostwire forum say it is the ask toolbar, can a custom installation be carried out that excludes the ask toolbar (or is that essential) ?
It may simply be that it collates information on your browsing activity to deliver related adverts, but I know nothing about frostwire so I can’t say.
Yeah the ask toolbar is the one that is being detected
Avast detects the trojan when you scan it or execute the installer of frostwire therefore before you can go to the option of the installer to install the ask toolbar,the installer is already deleted or moved to the chest.
Frostwire said that they will try to contact and have coordination to the 3 company that detects their product with a trojan.
Hi,
I scanned frostwire today(6/9/08) and it is the same
avast detects it as a trojan.
Can i humbly request to remove frostwire or the ask toolbar from the virus signatures being loaded in avast?
I think they’re not false positives but indeed adwares…
Anyway, you need to use the Exclusion lists:
For the Standard Shield provider (on-access scanning):
Left click the ‘a’ blue icon, click on the provider icon at left and then Customize.
Go to Advanced tab and click on Add button…
For the other providers (on-demand scanning such as the screen-saver or the Simple User Interface):
Right click the ‘a’ blue icon, click Program Settings.
Go to Exclusions tab and click on Add button…
You can use wildcards like * and ?.
But be careful, you should ‘exclude’ that many files that let your system in danger.
I cant risk my system just to use frostwire,even avast detects it as a false positive.
An ounce of prevention is worth a pound of cure.
Maybe I should wait avast to remove frostwire from their Virus Definition Files or maybe Frostire will remove ask toolbar from their installation package.This is the best solution I can think…for now.
For all I know, it’s an eligible installation, you can uncheck this option while installing Frostwire. Am I wrong? The ask toolbar is eligible in Nero installations also.
post a query at one of the Spyware sites such as Spywarewarrior if you need details
I’ll do a search on the Avast forum later but I would not be surprised if these have not been discussed before
bottom line is that Ask is still an adware privacy problem although they deny it - my opinion