false alarm ?

To day, after automatic update of virus data base I received notification that a file is infected.

I have very strong suspicion to believe it is a false alarm. (the file existed before the Avast update and an online scan from Mac Afee does not show that this file is infected)

What can I do to ensure this file is not blocked by Avast (at the moment I cannot start the application where the file belongs to, unless I desactivate Avast)
Thanks for your help

First of all, you should tell us what application it is and what is the exact virus name reported.

Thanks,
The application is Ulead Videostudio 11.
The “infected” file is in:
C:\program files\ulead systems\ulead videostudio 11\TgeDll.dll
Avast names the malware as " Win 32: Vapsup-CU [Adw]"

Can you please pack the mentioned file (TgeDll.dll) into a password-protected ZIP or RAR and send it to virus@avast.com (together with the password)?
Thanks.

You could also check the offending/suspect file at: VirusTotal - Multi engine on-line virus scanner and report the findings here. I feel virustotal is the better option as it uses the windows version of avast (more packers supported) and there are currently over 30 different scanners.

If it is indeed a false positive, add it to the exclusions lists:
Standard Shield, Customize, Advanced, Add and
Program Settings, Exclusions

Restore it to its original location, periodically check it (scan it in the chest), there should still be a copy in the chest even though you restored it to the original location. When it is no longer detected then you can also remove it from the Standard Shield and Program Settings, exclusions.

If you have sent the sample to avast as Igor requested you have nothing further to do.

Thanks to both of you.

  1. I have sent to “virus@avast.com” the file but not in a ZIP file (…I believe I do not have a ZIP software in my PC, unless it is part of Vista but I have not checked) after having disabled the antivirus. (of course !)
  2. I have sent he file to “VirusTotal - Multi engine on-line virus scanner” . The outcome is that only Avast has mentioned the Vapsup malware, as shown in the copy/paste herebelow.
    Avast 4.7.1098.0 2008.03.26 Win32:Vapsup-CU
    Next step ? as suggested by DavidR: Standard Shield, Customize, Advanced, Add and Program Settings, Exclusions ? or shall I wait to have confirmation that is is indeed a false alarm ?
    best regards
  1. There is a possibility it might get intercepted by an email server (your ISP’s, etc) on route. Though in this case it is unlikely to get intercepted if it is a false positive. There are many free zip applications, I use 7zip which I feel is quite good.

  2. The VT result basically confirms it is a false positive detection.

  3. Next step to add the exclusions and restore the file as my previous post. There is no need to wait for confirmation, in fact you normally don’t receive confirmation and your check that it has been rectified is by scanning the file copy in the chest.

Problem solved by Avast. it was indeed a false alarm.
Anyway MERCI for your help.

No problem, glad we could help.

Welcome to the forums.