avast found a virus were it shouldn't have

Ok I have a game. That is a legit store bought game. And it has been installed before on this computer and my old one and never had a virus. But this time when I went to install it again. avast said there was a virus in one of it .dll’s . I am not sure on what to do with this one.

What is the infected file name, where was it found e.g. (C:\windows\system32\infected-file-name.xxx) ?
Check the avast! Log Viewer (right click the avast ‘a’ icon), Warning section, this contains information on all avast detections.

You could also check the offending/suspect file at: VirusTotal - Multi engine on-line virus scanner and report the findings here. You can’t do this with the file securely in the chest, you need to extract it to a temporary (not original) location first, see below.

Create a folder called Suspect in the C:\ drive, e.g. C:\Suspect. Now exclude that folder in the Standard Shield, Customize, Advanced, Add, type (or copy and paste) C:\Suspect* That will stop the standard shield scanning any file you put in that folder. You should now be able to export any file in the chest to this folder and upload it to VirusTotal without avast alerting.

If it is indeed a false positive, see http://forum.avast.com/index.php?topic=34950.msg293451#msg293451, how to report it to avast! and what to do to exclude them until the problem is corrected.

ok well that web page virustotal wont upload it for some reason. It just say 0 bits recived. But this is what the chest log says. ( Sign of “win32:trojan-gen{other}” has been found in J:\programsfiles\JoDoWood Productions software AG\Gothic II Gold\system\spacer2.exe" file. )

Where are you trying to upload it fron, the original location, the chest or the scspect folder I suggested ?
Did you exclude the suspect folder as I suggested ?

Is avast detecting it when you try to upload it ?

I did make the folder and added it to the exclusion list. Then i extracted it to that folder. Went to that site. browsed for the file in the folder that I made then it went to a white screen stating 0 bits received. And yeah I did get a warning when selected the file. But what I was thinking is. This file “spacer2.exe” comes with the expansion pack for this game. And there are some sites that put virus redden files out there. But that’s weird because this is a store bought, not burnt disc. so I don’t know.

edit: I got it to upload to that site here is what it said:


MD5: a29cf5679c489d306f49d440de4d869f
First received: 08.06.2008 18:28:33 (CET)
Date: 08.16.2008 08:18:51 (CET) [>13D]
Results: 7/34
Permalink: analisis/d4e8dda906ee778bd63c4d39024c976d

Normally the fact that you get an alert by avast means that it will block the upload to virustotal, hence the 0 byte file size. So it would usually meant that you got the exclusion worng, but so long as you managed to get it uploaded in the end.

Whilst there are 7 detections, some of them are heuristic or generic detections (like the avast -gen suffix), which are more prone to false detection.

So it requires further analysis by avast, follow the information in the link about how to report the possible false positive.