[SOLVED] Virus after update ? in gpg.exe ???

Hi after updating a few minutes ago, to version 0604-0 Avast is saying that my gpg.exe is infected with Win32: Golember-M (Wrm) .
I send the E-Mail than without Enigmail.
I think that this is an false Alarm but Iam not shure.

Greetz
Black Sheik

If you are getting a virus warning that you believe is a false positive, then if you can zip and password protect (‘virus’, will do) the suspect file and send it to virus @ avast.com (no spaces), or send from the chest.

Give a brief outline of the problem (possibly a link to this thread), the fact that you believe it to be a either a new, undetected virus or false positive and include the password in the body of the email. Some info on the avast version and VPS number (see about avast {right click avast icon}) will also help.

You could also check the offending/suspect file at: Jotti - Multi engine on-line virus scanner if any other scanners here detect them it is less likely to be a false positive. You can’t do this with the file in the chest, you will need to move it out.
Or VirusTotal - Multi engine on-line virus scanner

If it is indeed a false positive, add it to the exclusions lists and check scan it periodically using the ashQuick scan (right click scan), when it is no longer detected then remove it from the exclusions.
Also see (Mini Sticky) False Positives

Hi DavidR :slight_smile:

Its tested by Jotti and all say “Found nothing” except AVAST he say " Avast
Found Win32:Golember-M "

Thats was what i think ;D it was a false Alarm.
Can you send a Mail to “virus @ avast.com” ? because my english is terribly.

AntiVir Found nothing
ArcaVir Found nothing
Avast Found Win32:Golember-M
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
Fortinet Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
UNA Found nothing
VBA32 Found nothing

Greetz
Black Sheik

Your English is fine, just copy what you put in your first post and the Jotti Results in the body of the email plus a link to this thread - http://forum.avast.com/index.php?topic=18888.0

I can’t send it to avast as I don’t have the file.

The important thing is you have used the Jotti site and the information should also be passed to avast, so if you feel sending it to avast is too dificult, don’t worry.

Ok Done :wink:

Thx for help

Greetz
Black Sheik

Not really.
First, I’m not sure how often the Jotti’s samples are distributed; second, it’s the undetected samples that are sent, not the detected ones. So… we’d need that file.

Hi Igor :slight_smile:

I have send the E-Mail with the file.

Greetz
Black Sheik

Thanks for the clarification Igor.

My thinking was if only one AV detected a virus it might/would be sent to that AV as a possible FP, so no logic like that employed at Jotti then. Rather than send the undetected sample to all the other AVs that didn’t detect it.

After the update “0604-1” all is working good. ;D ;D ;D

It was an false Alarm !

Greetz
Black Sheik