How to deal (..) [CHECK DAVID LAST QUESTION]

G-Data detection is the same as avast (as it uses avast engine).
Seems a false positive… but it will be good if avast team take a look and correct the detection. Until there, it will be safe to keep it into Chest.

Well I too would say there is a strong possibility of it being an FP. With 4 results (3 counting gdata and avast as 1) either generic or suspicious (heuristic) which are more prone to FP.

The only exception being (see below) and that to appears not to be a specific signature detection, so I would say submit the file to avast for further analysis.

ClamAV - - PUA.Packed.Armadillo

Send the sample to virus@avast.com zipped and password protected with the password in email body, a link to this topic might help and possible false positive in the subject.

Or you can also add the file to the User Files (File, Add) section of the avast chest (if it isn’t already there) where it can do no harm and send it from there (select the file, right click, email to Alwil Software). No need to zip and PW protect when the sample is sent from chest. A copy of the file/s will remain in the original location, so any further action you take can remove that.

It says I cannot send it since it’s too big. :frowning:

Increase the size , avast Program Settings, Chest, Max size file to send, etc. so that it is large enough to cope the actual file size.

OMFG! I’M ******* GETTING MAD HERE AT THIS DAMN OUTLOOK! -.-’
Please, I can’t get it to work. Give me another way to get this file sent. And what about the text, is this good enough;

Hello.

DavidR on Avast! Support Forums told me to send you this file since it could be a false positive. I’d be glad if you could check it. [Forum Thread Name; How to deal with a virus? [CHECK DAVID]].
Thanks.

Well you could try zipping and password protecting the sample and sending it from outlook conventionally e.g. attach the zip to the email, as in my post, Reply #21 above.

As for the text, the more important things are the password in email body, a link (from the address window of the topic, the same way you captured the URL for the VT results) to this topic and the link to the VirusTotal results might help. Place possible false positive in the email subject.

You don’t need to go into much detail as the link to this topic would provide the detail.

But it’s outlook who isn’t working. I don’t know why, I’ve tried and tried but isn’t it possible sending it by Hotmail or something else?
And how do I ZIP & Pass protect the file? :slight_smile:

I don’t know why outlook isn’t working but the chest may add an extra complication, which is why I suggested trying outside.

You don’t say ‘why’ it isn’t working ?

Since you mention Hotmail, I can only assume that you send and download email to your Hotmail account using Outlook ?

Hotmail isn’t a normal SMTP or POP3 account but web mail, which is normally accessed by your browser, although MS allows Outlook (and OE) to be able to send and receive Hotmail, but it doesn’t use SMTP or POP3 protocols, but uses WEBDEV or something like that to convert hotmail. Because it doesn’t use the SMTP/POP3 protocols avast can’t access this account.

You need to have a zip program, 7zip, winzip or RAR, I would say 7zip is the easiest to work with when it comes to setting a password as it is clear on the screen.

Outlooks says I need to choose some kind of server (?) and choose name, register here and there, connect here, oh, couldn’t connect outlook need to be running. I don’t know, I’m just getting mad with it. Anyway, maybe you got some experience from starting outlook for the first time?

Maybe you want a screenshot?

I don’t use Outlook so can’t really be any practical help.

How do you normally receive and send email ?

Hotmail, and I don’t use mail that often.

That is the problem, because Hotmail is web based email that doesn’t use the standard SMTP protocol but a propriatary MS protocol so Outlook can send to it, but avast can’t handle that protocol.

So you would have to start by creating an email using Outlook to virus@avast.com, zip and password protect the sample, then send it to avast.

Another problem that I foresee is that although zipped and password protected Hotmail may block the sending of the email because the Ravenhearst.exe is an executable file and whilst it can scan the file it blocks by type a really crude and pathetic strategy. So before zipping the sample you may need to rename it Ravenhearst_exe.txt as that file type shouldn’t be blocked.

Whilst this is a lot of hassle it might be the only way of getting past Outlook and Hotmail to submit a sample. There is no such problem if you had a conventional POP3/SMTP email account (like one provided by your ISP, etc.) then it could have been sent from the avast chest, no zip/password hassles.

“Connection to Microsoft Exchange Server is not available. Outlook needs to be online
or connected for this to be finished.”

Any idea whats wrong? :frowning:

By the way, I’m going to try calling Microsoft tomorrow when I’m free. And let’s
see what they say. I’ll let you know. :slight_smile:

Sorry I just ran off like that. Just been alot. Anyway, I believe this office program is only working with the comp we bought it with (?). So, do you want me to send it some other way or just delete it? I just really dont got the time to fight with Microsoft atm. :stuck_out_tongue:

[I have WinRaR, haven’t paid for it tho, but it’s still working unzipping files]

Hey, great news!

I was scanning my computer while I was watching a movie, and when I got back - no viruses found! What?!
But I have the file in my Suspect map! So I rescanned the file in the chest, and avast! did not find any virus.
So, I guess this is the end! :slight_smile:

Anyway, I really would like yo thank you for the time you’ve spent on helping me! :]
If I delete the file by pressing the button up in the corner, will avast! delete the whole file from my comp, and not just from the chest, yes?

You’re welcome.

In the interim someone else may have had this problem and ben able to send the sample to avast and the detection was corrected.

Right click on the file in the chest and select restore, that will place it back in the original location (after all it is no longer considered infected), confirm that a copy has been placed in the original location and then delete the file in the chest (this only deletes the file in the chest nothing else).

But I don’t want the file, I mean, it’s a game I got with my computer. But if I delete it, by just clicking the delete button in the corner, will there be any kind of copy somewhere?

But I’ve uninstalled the game months ago, but I still have the file, so it wouldn’t make any difference if I restored it.

I wasn’t aware that you had uninstalled the game (or didn’t remember if you mentioned it, it has been a long topic) when I said you could restore the file to its original location. If the game isn’t there nor would the original location so it would fail on the restore you can obviously delete it from the chest.

Okay, they’re deleted. But the file is totally gone from the comp now also?