I’m not an expert mate but if all the other anti-virus are saying its clean it could be either:
a) A false positive (ie its been detected as bad but its not)
b) Avast has detected this and others havent
you could try either sending the file to Avast team or using www.virustotal.com which checks it with all available anti-virus software
another last possibility would be to put as much info on here as possible and someone will help you work it out, a program such as Hijackthis can provide the details of your system
It’s being detected by a gen(eric) signature for trojans of Win 32 systems.
To know if a file is a false positive, please submit it to JOTTI or VirusTotal and let us know the result. If it is indeed a false positive, send it in a password protected zip to virus@avast.com
Please, mention in the body of the message why you think it is a false positive and the password used. Thanks.
VirusTotal and Jotti both have file size limits 10 and 15MB each.
As a workaround, you can add these files to the Standard Shield provider (on-access scanning) exclusion list.
Left click the ‘a’ blue icon, click on the provider icon at left and then Customize. Go to Advanced tab and click on Add button…
You can use wildcards like * and ?. But be carefull, you should ‘exclude’ that many files that let your system in danger.
After that, please, periodically check it - scan it into Chest, right clicking the file - there should still be a copy in the chest even though you restored it to the original location. When it is no longer detected as being infected then you can also remove it from the Exclusion list.
I put the infected file on VirusTotal!
The result is only Ikarus T3.1.1.12 detects it and the others includes Avast at VirusToal do not detect it.
However, My Avast detects it!! I have no idea here why?
VirusTotal usually lags behind avast users in the VPS version they use, by all accounts VT can’t easily update the VPS. So you will often see something like this, remember what you are looking for is confirmation from other AVs that the detection is good.
In this case it would appear to be an FP.
If it is indeed a false positive, add it to the exclusions lists (Standard Shield, Customize, Advanced, Add and Program Settings, Exclusions) and Restore it to its original location, periodically check it (scan it in the chest), there should still be a copy in the chest even though you restored it to the original location.
When it is no longer detected then you can also remove it from the Standard Shield and Program Settings, exclusions.
Thank you!!
This is a quickly information.
The VPS has updated from 000767-1 to 000767-2 around 12:00 noon at US PDT today.
After that I scanned the infected files again by the Avast. In this time, it found no virus!
I hope something was wrong on 000767-1. But still Ikarus says “Infected”. So I keep eyes on it!
Well, shall I add to this thread or start a new one? I got the same alert during a scan last night. Two instances of Spybot’s TeaTimer update being infected:
“ORIGINAL FILE NAME: teatimer 1506-setup.exe”
I clicked the button to send report - is that enough?
I haven’t been here in a long time, so my profile needs updating, but everything on the computer is up to date.
It may be better to start a new topic because the file that is being detected is different, though the Win32:Trojan-gen {Other} is likely to cover many different files if it is an FP, it relates to the file.
In the other topic you can post any confirmation of an FP like the VirusTotal results.
I don’t believe the report button provides any meaningful information, follow the false positive reporting link above.
You can click the Profile and edit your Forum Profile Information.