So almost a week ago, I downloaded NetBeans and send it to VirusTotal to find out, if everything looks as it should. When I imported the NetBeans installer, the Avast malware detection poped-up, and I did not know why. So I used Avast “Full virus scan” and after that Eset online scanner. They found nothing. (NOTE: I now know, that it was probably a false positive due to a VirusTotal scan.).
However, when I turned on PC a day later, and connected to it headphones to charged them, and leave the PC in “the login to desktop” screen, the Avast auto-detected malware. The alert had typicall visual style of Avast alerts, and it appeared in the middle of the screen. But the the alert itself was more of rectangular shape, than the regular squarish shape of Avast virus detection alerts. And on top of that, the alert did not showed what the file/executable was, or it’s respective directory. The name of that supossed virus file, was not even the name. The name was made by question marks. Besides the name, the another important info it showed was 1 malware was detected, which was in red color.
So after that, I used 8 virus scaners, and non of them found anything. The scanners and anti-virus programs were:
Avast
Eset virus online scanner
Malwarebyte
Kaspersky Virus Removal Tool
Norton Virus Removal Tool
HitmanPro
Rouge Killer
Windows Defender
So the questions are:
Could that be a false positive, or it could be some legit virus?
Could that be a fake virus pop up, or scareware?
Could that be some Avast bug, or something similar?
Is there a way to look up for the report of virus detections, or something like that?
A screenshot of the avast warning would be good to see.
If you have submitted to Virus Total etc and is reported as clean, then I suggest you submit a false positive form to avast. See here: Choose Your Sample Submission Type | Avast
Note I am not an Avast Team Member, just another user.
Sadly, I do not have picture of it. And when it comes to VirusTotal I’m pretty sure it was false positive.
However, the 2. time the Avast scanned, was when I turned on PC and it didn’t show anything about what type of file was detected, where the file is located, or what script was detected.
Virustotal or full scan shows static detection only, but behavior shield detection (starting with “IDP:”) is dynamic (during-execution) as the name suggests.
This means, Virustotal does not show Behavior shield detection at all.
Also, these detections may be difficult to reproduce also because of behavioral basis.
Some logs may be placed below, depending on settings.
Sorry for my late response, I’ve had it too much and forgot to reply.
So, when it comes to the reports, I didn’t had them turned on, so whatever it detected, it was not saved in repots. But the Virustotal is not bothering me right now, cuz I know it was false positive.
But the thing I want to ask is; when it comes to that 2., weird Avast detection in my description above, could it be a detection of some malware exe. file which was not yet executed, or not? And on top of that, could that be the reason why it did not showed any name or location of the infected file, or is it more likely that the missing name and directory can be caused by something else?