Hello,
This morning I open my computer and about 30 minutes later Avast Home reported a virus with the name of: Trojan-gen(UPX) Uninstall.exe, in C:\ProgramFiles\ServicesController XP.
I clik on “No Action” as I suspected it is a false positive
In the mean time I scanned my PC Online with Kasperski, Dr.Web CureIt and SuperAntispyware and they did not find anything. ??? That would confirm what I was thinking first, it must be a false positive. :-\
Anyway just to make sure,I quarantine the file until this is sort out.
Deletion isn’t really a good first option (you have none left), ‘first do no harm’ don’t delete, send virus to the chest and investigate.
Send the sample to virus@avast.com zipped and password protected with the password in email body, a link to this topic might help and false positive in the subject.
Or you can send it from the chest (select the file, right click, email to Alwil Software). No need to zip and PW protect when the sample is sent from chest. A copy of the file/s will remain in the original location, so any further action you take can remove that.
You could also check the offending/suspect file at: VirusTotal - Multi engine on-line virus scanner and report the findings here. I feel virustotal is the better option as it uses the windows version of avast (more packers supported) and there are currently over 30 different scanners.
If it is indeed a false positive, add it to the exclusions lists and send sample to avast as mentioned: Standard Shield, Customize, Advanced, Add and Program Settings, Exclusions
Restore it to its original location, periodically check it (scan it in the chest), there should still be a copy in the chest even though you restored it to the original location. When it is no longer detected then you can also remove it from the Standard Shield and Program Settings, exclusions.