is this a falls positive i was scanning my usb jump drive were this file is located its the install file for Nero-6.6.1.15a as this win32:Adware-gen also says toolbar behind it is this anything to worry about i have had Nero on my PC for years and this is the first time i scanned with avast and got this please help i do have the file to upload if anyone wish to examine it. please not only detects this on my jump drive so far.
Quite possibly.
What is the infected file name, where was it found e.g. (C:\windows\system32\infected-file-name.xxx) ?
Check the avast! Log Viewer (right click the avast ‘a’ icon), Warning section, this contains information on all avast detections.
You could also check the offending/suspect file at: VirusTotal - Multi engine on-line virus scanner and report the findings here. I feel virustotal is the better option as it uses the windows version of avast (more packers supported) and there are currently over 30 different scanners. There is a 10MB upload limit to VirusTotal.
If it is indeed a false positive, add it to the exclusions lists:
Standard Shield, Customize, Advanced, Add and
Program Settings, Exclusions
Restore it to its original location, periodically check it (scan it in the chest), there should still be a copy in the chest even though you restored it to the original location. When it is no longer detected then you can also remove it from the Standard Shield and Program Settings, exclusions.
Send the sample to virus@avast.com zipped and password protected with the password in email body, a link to this topic might help and false positive in the subject.
Or you can send it from the chest (select the file, right click, email to Alwil Software). No need to zip and PW protect when the sample is sent from chest. A copy of the file/s will remain in the original location, so any further action you take can remove that.
the location is here it on my usb jump drive here is file name and location. 1/31/2008 10:05:19 PM Sign of “Win32:Adware-gen [Adw]” has been found in “K:\back up software\nero stuff\Nero-6.6.1.15a.exe\Toolbar.exe[Embedded#620d0][Embedded#04080]”
ok very strange avast updated this morning and now this file is not showing up as a virus at all hmm indeed must have been a fals warning if it happens again will send it to you all.
No problem, it may be that it was an FP and was reported by others (as Nero is quite popular) and the VPS signature corrected.
Welcome to the forums.
I’ve seen this happen with another AV program I had, where it found a Bible program that I had been using and declared it a virus. A few days later I could restore it as it was also a False Positive.