CNET avast installer bundled with malware?

So I noticed I had the cnet version of the avast installer this morning and that was the one I was using. Decided to scan it on virustotal alongside with the official avast installer from the forum, here’s what I got:

CNET: https://www.virustotal.com/en/file/cf1e4b16335d85acdb9a4c32f5c6917665e7efc935efcae9ad6b4045fed7f3e0/analysis/1445016172/
Avast: https://www.virustotal.com/en/file/001530f750b0fcb2d1648a1c56f8231150d92d11aac2f265654cdedf07cf2368/analysis/1445016228/

Also a few things to note here, i’ve uninstalled the cnet version now for peace of mind. My computer was running sluggish before and I also noticed some websites weren’t functioning properly like thumbnails not loading when they should have been, and software updater wasn’t functioning properly either. The avast installation folder was also over 2 gigabytes with the cnet version and 500 mb when installed through here. So why is avast still redirecting their users to cnet? It just seems like a bad idea to me. Theres better options out there like Filehippo which my adblock won’t discourage me from going to. https://i.imgur.com/pCp9OXc.png

many download sites have PUP in the installers http://www.howtogeek.com/198622/heres-what-happens-when-you-install-the-top-10-download.com-apps/

PUP = Possible Unwanted Software https://www.virusbtn.com/resources/glossary/potentially_unwanted.xml

a very good PUP remover is Malwarebytes

Malwarebytes is what I use, luckily it didn’t find anything. Avast should seriously make it easier to find the clean download on the homepage though. I had to dig around the forums to find it. There’s something weird going on with the “free download” button on the homepage. Sometimes it’ll take you to cnet, sometimes it won’t. Not sure what’s going on here, is this a bug?

You have to exercise care in Cnet (a.k.a. download.com) as it has a bit of deception in it suggests using its downloader/installer and this is where the crap ware (not malware) comes from.

There should be a direct download link to get avast and not use their installer/downloader.

Here is a direct download link for the full avast setup file http://files.avast.com/iavs9x/avast_free_antivirus_setup.exe.

There was no installer/downloader that came with that file from cnet. It’s being advertised as a secure download on their website so theres no way to ‘opt out’ of the crapware. My main concern is why avast still hosts the cnet download on the homepage? https://imgur.com/YBhvi5w

That’s the thing it was very difficult to find the setup file without a good deal of hunting. But it looks like they have dispensed with direct download without CNET’s download setup file.

Since I’m on the 2016 beta build I can’t check against what comes down the pipe from cnet.

Avast is on a number of different download sites, but cnet is still the one pushed by avast. Previous complaints have been made about this behaviour by cnet. And avast had stated there should be a direct download available without any cnet crapware, looks like that has gone by the wayside.

Personally I don’t like this download of what is termed an on-line setup file (just over 5MB) when the full off-line installation file is of the order of 140MB or more. It isn’t the full installation but a stub installer that then downloads the components required.

I have made it a practice to download software from the vendors website.
I don’t remember the last time I used cnet.com/download.com. I don’t
like to have some website using “their” software to track downloads.

Another good addition is adwcleaner which can be safely downloaded from http://www.bleepingcomputer.com/download/adwcleaner/

The full installs (including the latest betas) are still available via the direct download links(I just downloaded them to verify). Avast has chosen to not publish the links to the full downloads in the last two beta announcements.

The download you got from Cnet or Download.com was the stub installer. Which means it downloads the actual installer.

They are both stub installers I know this. What could cnet be doing to the file to make theirs get detected as malware? They should get the same detections if they are in fact the same untouched stub installer. Are avast users really getting the same experience downloading from a third party site like that? It’s kind of ironic how avast redirects you to a site notorious for its pups and viruses just to install their software which is supposed to protect you from that.

Downloading certain software from Cnet may come to you with an installer that adds Pup’s. A Pup is not a virus.
Your Avast download from that site doesn’t include their installer. it’s the same file available directly from Avast.
The links you provided only showed one detection. The company to ask as to what they found according to your link is Rising AV.
That same company showed it as clean on your second link.
I personally see no danger at all but, it’s your computer, not mine. (I’m also running the latest beta.)