False positive Avira

Discussion in 'other anti-virus software' started by Boost, Mar 21, 2009.

Thread Status:
Not open for further replies.
  1. Boost

    Boost Registered Member

    Joined:
    Feb 2, 2007
    Posts:
    1,294
    Contains HEUR/Modified Systemfile suspicious code C:\Windows\explorer.exe

    Uploaded it to Avira,wait and see what they say ;)
     
  2. Baz_kasp

    Baz_kasp Registered Member

    Joined:
    May 1, 2008
    Posts:
    593
    Location:
    London
    Are you using a skinning pack?

    If so, with 99.9% certainty, it is not a FP.

    System files have to be patched in order for the skins etc to work, this wouldn't happen on most normal home user pc's so in cases where a skinning pack is used you know to exclude such detect or turn off the detection altogether.
     
  3. Boost

    Boost Registered Member

    Joined:
    Feb 2, 2007
    Posts:
    1,294
    Yup, I'm using a BricoPack Vista skin package for XP :D

    I figured they would want to know about this? Maybe, or not?
     
  4. Baz_kasp

    Baz_kasp Registered Member

    Joined:
    May 1, 2008
    Posts:
    593
    Location:
    London
    I don't think they will fix it, BricoPack modified a system file. Malware will modify system files to avoid detection in certain cirumstances so this detection is technically correct.
     
  5. Boost

    Boost Registered Member

    Joined:
    Feb 2, 2007
    Posts:
    1,294
    If they dont want to fix it,I'll just add it to the ignore list ;)
     
  6. firzen771

    firzen771 Registered Member

    Joined:
    Oct 29, 2007
    Posts:
    4,815
    Location:
    Canada
    that wuld probly be the best choice since its not REALLY a FP... since it says modified system file (which it is) and only says suspicious so doesnt say that it is a virus or something exactly.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.