Can anyone shed any light on this:
[b] 0001000B.c1 C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles VME Family
Avast detected this (and another 46 identical files) advising that this is a virus.
Posts back in April seem to think this is a false positive, not a virus and a fix would be out soon.
Can anyone say definitely that this is a false positive or a virus.
I’m running Avast Home Edition on vista Home Premium
We can’t say that because it isn’t something we can check on ‘your’ system.
In that same thread I assume that it also mentioned checking it out at: VirusTotal - Multi engine on-line virus scanner I feel virustotal is the better option as it uses the windows version of avast (more packers supported) and there are currently 30 different scanners.
Or Jotti - Multi engine on-line virus scanner if any other scanners here detect them it is less likely to be a false positive. Whichever scanner you use, you can’t do this with the file in the chest, you will need to move it out.
I have tried both the attached links (VirusTotal & Jotti), neither gave any indication that this is malicious (cept for Avast). I do feel reasonably confident that this is a false positive.
Any clue as to why Avast generates a Virus Indication for this?
Detection by signature, especially one which looks like it is trying to catch more than one virus (VME Family) may find a character string that closely matches the signature.
If it is indeed a false positive, add it to the exclusions lists (Standard Shield, Customize, Advanced, Add and Program Settings, Exclusions) and Restore it to its original location, periodically check it (scan it in the chest), there should still be a copy in the chest even though you restored it to the original location. When it is no longer detected then you can also remove it from the Standard Shield and Program Settings, exclusions.
Also see False Positives, how to report it to avast! and what to do to exclude them until the problem is corrected.