Win32:PrefPoly [Cryp] in Eraser.exe -- false positive?

Dear all,

I’d very much welcome any thoughts on the following issue:

When I scan my Eraser program folder, or Eraser.exe itself, the latest versions of both Avast and Malwarebytes find no threat.

However, when I run a memory scan, Avast warns me that Eraser.exe is infected by Win32:PrefPoly [Cryp]. (Please see attached screenshot below.)

If I exit Eraser, and run a memory scan the threat is gone. If I then launch Eraser again, Avast’s real-time shields allow the action, still not detecting any threat as the program is loaded into memory and run to erase files. Now, if I run a memory scan with Eraser still loaded in memory the threat is back.

If this threat is real, I’m puzzled as to why Avast’s real-time shield is not aware of the threat when the program is loading into memory. A quick scan of the PC using Avast’s standard settings (which does not include a memory scan) found no threat, even while Eraser was still loaded in the memory. Malwarebytes (which does include a memory scan) also found no threat when I ran a quick scan with standard settings.

My Eraser program was installed on 15 Feb 2008, from the official site. Numerous scans of memory and hard disk have revealed no problems until yesterday. I have experienced no other unusual problems (unexpected HD activity, slowdowns, pop-ups, etc) with my Vista (no service pack) PC whatsoever.

Any thoughts would be welcome as to whether this is likely to be a real threat or a false positive?

With thanks,

David

For sure it’s a false positive. But I have Eraser and avast isn’t detecting it…

Thank you very much for your fast reply, Tech.

I wonder if we have different versions of Eraser. I am using version 5.86.1, which is fairly old.

I held off from updating to the newest version of Eraser because so many people on the Eraser forum were having problems with version 6.

Thank you again for having helped me so quickly,

David

I’m with 6.0.8.2273.
Be used with avast forum speed :slight_smile:

to be totally sure. u can check it on virus total.

I have the same problem as Teardrop. I have the same version 5.86.1. I recently upgraded to the latest Avast free version and the warning started soon after. This is on my relatively clean machine so I expect this is a false positive. I look forward to see if others determine otherwise.