{"id":23216,"date":"2013-10-31T18:06:24","date_gmt":"2013-10-31T14:06:24","guid":{"rendered":"http:\/\/greatis.com\/blog\/?page_id=23216"},"modified":"2014-06-03T22:07:40","modified_gmt":"2014-06-03T18:07:40","slug":"do-not-trust-avast-antivirus","status":"publish","type":"page","link":"https:\/\/greatis.com\/blog\/do-not-trust-avast-antivirus","title":{"rendered":"The real truth about AVAST Antivirus!"},"content":{"rendered":"<div class=\"wpInsert wpInsertInPostMy wpInsertAbove\" style=\"padding: 0px;\"><\/div><p>Do you remember that on December 06, 2012 AVAST deleted TCPIP.SYS from thousands computers?<br \/>\nAs a result: \u201cNo network connection of my computer. \u201c<br \/>\nforum.avast.com\/index.php?topic=110804.0<\/p>\n<p>I have never used AVAST earlier and I supposed that it was only a bug.<br \/>\nWe released the small free tool to rescue users before AVAST updated their databases:<br \/>\n<a href=\"http:\/\/greatis.com\/unhackme\/tcpip-sys-restore.htm\">http:\/\/greatis.com\/unhackme\/tcpip-sys-restore.htm<\/a><\/p>\n<p>But, I have recently got a message from my client:<\/p><div class=\"wpInsert wpInsertInPostMy wpInsertMiddle\"><\/div>\n<p><em>Ticket ID: FVI-SCQQP-805:\u00a0Avast\u00a0Anti-virus recognized one of your program processes as a Trojan and blocked the connection:<br \/>\nInfection Blocked<br \/>\nURL: <\/em>www.greatis.com\/appdata.exe%7Cgreatis.rdb<br \/>\n<em> Infection: AutoIt:Agent-KP [Trj]<br \/>\nRelax, your\u00a0avast! just saved you from a virus.<br \/>\nPlease explain&#8230;!<\/em><\/p>\n<p>Greatis.rdb is a virus encyclopedia. It includes only virus file names. There is no executable code in that file.<br \/>\nI spent some time to post a <strong>false positive ticket<\/strong> on the Avast web site.<\/p>\n<p><strong>Two days of silence\u2026<\/strong><\/p>\n<p>The answer:<br \/>\n<em>Hello,<br \/>\nThank you for contacting AVAST Software company with your concerns.<br \/>\nIt&#8217;s not false positive, detection is correct.<br \/>\nIf you need further assistance, don&#8217;t hesitate to contact me again.<\/em><br \/>\n<em>Miroslav Jen\u0161\u00edk<br \/>\nTechnical Support Engineer<br \/>\nAVAST Software a.s.<\/em><\/p>\n<p>Link here:<br \/>\n<a href=\"http:\/\/greatis.com\/appdata\/false-avast\/ticket1.png\">http:\/\/greatis.com\/appdata\/false-avast\/ticket1.png<\/a><\/p>\n<p><strong>I asked for information:<br \/>\nI would like to get the detailed report of your test.<\/strong><\/p>\n<p>Answer after 2 days of silence:<br \/>\n<a href=\"http:\/\/greatis.com\/appdata\/false-avast\/ticket2.png\">http:\/\/greatis.com\/appdata\/false-avast\/ticket2.png<\/a><\/p>\n<p><em>Hello,<\/em><br \/>\n<strong><em> Contains unencrypted virus signatures, thus it will trigger avast! as it sees the signatures.<\/em><\/strong><br \/>\n<em>Miroslav Jen\u0161\u00edk<br \/>\nTechnical Support Engineer<br \/>\nAVAST Software a.s.<\/em><\/p>\n<p>I wasted some time before I found the signature.<br \/>\n<strong>It was really simple and stupid.<br \/>\nI have never even thought\u00a0 how much stupid it is.<\/strong><\/p>\n<p>I shared the files to confirm my discover.<\/p>\n<p>This file is detected as a virus:<br \/>\n<a href=\"http:\/\/greatis.com\/appdata\/false-avast\/false-detect\/appdata.exe\">http:\/\/greatis.com\/appdata\/false-avast\/false-detect\/appdata.exe<\/a><br \/>\n<strong>Of course, it is absolutely clean.<br \/>\nVirustotal \u00a0test (1\/47):<\/strong><br \/>\n<a href=\"https:\/\/www.virustotal.com\/en\/file\/45ec92cc3e09f4f87c7932d75983153cb6d95ea4026ee473e20e00c14d613b7e\/analysis\/1383216861\/\">https:\/\/www.virustotal.com\/en\/file\/45ec92cc3e09f4f87c7932d75983153cb6d95ea4026ee473e20e00c14d613b7e\/analysis\/1383216861\/<\/a><br \/>\nOnly one of 47! Who is this one? Of course, Avast.<\/p>\n<p>Small magic, fixing the database.rdb:<br \/>\n<a href=\"http:\/\/greatis.com\/appdata\/false-avast\/clean\/appdata.exe\">http:\/\/greatis.com\/appdata\/false-avast\/clean\/appdata.exe<\/a><\/p>\n<p>VirusTotal Test of appdata.exe (0\/47):<\/p>\n<p><a href=\"https:\/\/www.virustotal.com\/en\/file\/d5d513adee4ffc138ac2f0fbc83bfa4362dcc5b16df2d251fb39632ea303646f\/analysis\/1383217269\/\">https:\/\/www.virustotal.com\/en\/file\/d5d513adee4ffc138ac2f0fbc83bfa4362dcc5b16df2d251fb39632ea303646f\/analysis\/1383217269\/<\/a><\/p>\n<p>Where is the change?<\/p>\n<p><img loading=\"lazy\" class=\"alignnone\" title=\"Changes\" src=\"http:\/\/greatis.com\/appdata\/false-avast\/image01.gif\" alt=\"\" width=\"671\" height=\"530\" \/><\/p>\n<p>Here is a signature:<\/p>\n<p><strong>%WINDIR%\\FACEBOOK LIKE HACK V1.5.1.EXE<\/strong><\/p>\n<p><strong>That\u2019s all! Avast detects a virus by a simple text string. It is a super stupid.<br \/>\nBe careful! Next time Avast deletes your important files as viruses!<\/strong><br \/>\nI don\u2019t know what other signatures they have.<\/p>\n<p>After that, I made a short test of Avast with <strong>Sprotector Adware<\/strong> and, of course,\u00a0<strong>Avast failed this simple test<\/strong>.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone\" title=\"Failed Avast\" src=\"http:\/\/greatis.com\/appdata\/false-avast\/image00.jpg\" alt=\"\" width=\"762\" height=\"249\" \/><\/p>\n<p>&nbsp;<\/p>\n<p><strong>Addons installed, Google search is redirected.<\/strong><\/p>\n<p><strong>Keep away from Avast for your safety.<\/strong><\/p>\n<p>&nbsp;<\/p>\n<div class=\"wpInsert wpInsertInPostMy wpInsertBelow\" style=\"padding: 0px;\"><\/div>","protected":false},"excerpt":{"rendered":"<p>Do you remember that on December 06, 2012 AVAST deleted TCPIP.SYS from thousands computers? As a result: \u201cNo network connection of my computer. \u201c forum.avast.com\/index.php?topic=110804.0 I have never used AVAST earlier and I supposed that it was only a bug. We released the small free tool to rescue users before AVAST updated their databases: http:\/\/greatis.com\/unhackme\/tcpip-sys-restore.htm [&hellip;]<br \/><a style=\"color: #42A2CE\" href=\"https:\/\/greatis.com\/blog\/do-not-trust-avast-antivirus\"><u>More&#8230;<\/u><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":[],"_links":{"self":[{"href":"https:\/\/greatis.com\/blog\/wp-json\/wp\/v2\/pages\/23216"}],"collection":[{"href":"https:\/\/greatis.com\/blog\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/greatis.com\/blog\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/greatis.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/greatis.com\/blog\/wp-json\/wp\/v2\/comments?post=23216"}],"version-history":[{"count":0,"href":"https:\/\/greatis.com\/blog\/wp-json\/wp\/v2\/pages\/23216\/revisions"}],"wp:attachment":[{"href":"https:\/\/greatis.com\/blog\/wp-json\/wp\/v2\/media?parent=23216"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}