{"id":8538,"date":"2014-11-02T11:32:33","date_gmt":"2014-11-02T16:32:33","guid":{"rendered":"http:\/\/thundercloud.net\/infoave\/new\/?p=8538"},"modified":"2014-11-02T11:32:53","modified_gmt":"2014-11-02T16:32:53","slug":"dont-forget-to-check-your-antivirus-false-positives","status":"publish","type":"post","link":"https:\/\/www.thundercloud.net\/infoave\/new\/dont-forget-to-check-your-antivirus-false-positives\/","title":{"rendered":"Don&#8217;t Forget to Check Your Antivirus False-positives"},"content":{"rendered":"<p>We were recently bombarded with email from Avast users because suddenly, without warning, Avast detected Cloudeight CalenderPal as being infected with\u00a0the virus: Win32:Evo-gen. Avast is well-known for its high rate of false-positives. A false-positive is a harmless file detected as a malicious file. If an antivirus cannot differentiate a bad, malicious file from a good, safe file, then one has to wonder if it will detect real viruses when encountered.<\/p>\n<p>First, the suspected virus &#8220;Win32:Evo-gen&#8221;\u00a0seems to be everywhere, at least according to Avast &#8211; but no other antivirus seems to find it. See<span style=\"text-decoration: underline;\"><a href=\"%20https:\/\/forum.avast.com\/index.php?topic=120219.0\" target=\"_blank\">\u00a0https:\/\/forum.avast.com\/index.php?topic=120219.0<\/a>\u00a0<\/span><\/p>\n<p>We have been flooded with emails from folks for the last couple of days asking if we had done something to CalendarPal &#8211; we haven&#8217;t. We haven&#8217;t made any changes to CalendarPal since 2007 &#8211; and it continues to work well in all versions of Windows from Windows XP through Windows 10 (technical preview). We don&#8217;t know why Avast suddenly started detecting viruses in clean files, but we highly suspect it was due to a bad Avast update. As of today, November 2, 2014, Avast no longer finds any virus in CalendarPal. We haven&#8217;t changed CalendarPal &#8211; so Avast must have fixed its botched update.<\/p>\n<p>This leads us to a tip for those of you who continue to use Avast (free or paid) antivirus. The first tip is &#8211; upgrade your antivirus to Emsisoft if for no other reason than, despite what Avast claims, its anti-malware component is virtually impotent &#8212; and it has no PUPs detection at all from what we have seen. We&#8217;ve worked on dozens and dozens of Avast-protected computers &#8211; and almost always we have removed a plethora of malware and PUPs from these systems. \u00a0Emsisoft not only provides superior antivirus protection, it provides antimalware and PUPs detection which Avast is direly lacking. <span style=\"text-decoration: underline;\"><strong><a href=\"http:\/\/www.thundercloud.net\/emsisoft\/\" target=\"_blank\">Find out more about Emsisoft here.<\/a><\/strong><\/span><\/p>\n<p>The second tip we have for you, regardless of the antivirus you use is this: If \u00a0your antivirus detects a virus or Trojan (not a PUP or malware program) in a file or program, double check it before you panic. The fastest, best, safest free way to do this is to <strong><span style=\"text-decoration: underline;\"><a href=\"https:\/\/www.virustotal.com\/\" target=\"_blank\">use a site called VirusTotal<\/a>.\u00a0<\/span><\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone\" src=\"http:\/\/thundercloud.net\/infoave\/images\/2015\/vtotal.png\" alt=\"\" width=\"600\" height=\"438\" \/><\/p>\n<p>VirusTotal will check any file from your computer or from a download link with 54 different antivirus programs. It scans most files in a minute or so, so \u00a0you don&#8217;t have to wait long before you know for sure if your antivirus is detecting a false positive or if you have a real problem.<\/p>\n<p>We know that any antivirus can makes a mistake now and again, but Avast seems to have more trouble with false positives than other security programs. And that should make you wonder about its ability to detect real threats. A rare mistake by an antivirus is understandable but a high rate of false positives should make you wonder.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We were recently bombarded with email from Avast users because suddenly, without warning, Avast detected Cloudeight CalenderPal as being infected with\u00a0the virus: Win32:Evo-gen. Avast is well-known for its high rate of false-positives. A false-positive is a harmless file detected as a malicious file. If an antivirus cannot differentiate a bad, malicious file from a good, safe file, then\u2026 <span class=\"read-more\"><a href=\"https:\/\/www.thundercloud.net\/infoave\/new\/dont-forget-to-check-your-antivirus-false-positives\/\">Read More &raquo;<\/a><\/span><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1462,1433,1669,1656,1654,10],"tags":[],"_links":{"self":[{"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/posts\/8538"}],"collection":[{"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/comments?post=8538"}],"version-history":[{"count":2,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/posts\/8538\/revisions"}],"predecessor-version":[{"id":8540,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/posts\/8538\/revisions\/8540"}],"wp:attachment":[{"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/media?parent=8538"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/categories?post=8538"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/tags?post=8538"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}