Here's the picture as requested.
When the silent install from Crashplan runs (about once a month) to update their software, AVG appears to block it - which causes the file to fail to run, and thus Crashplan has to be reinstalled. Adding in the exceptions as listed above have not stopped Behavior Shield from allowing the Crashplan silent update to proceed. I've been working with Crashplan and we have been able to re-create the issue, but it's a lengthy process for those steps to get a silent update to occur.
I've included the excludes in the original update - Can you confirm if these are written correctly based on the attached screenshot?
Hello U J,
This isn't the experience we want you to have.
We're really sorry to know that you feel this way.
You can contact our AVG representative through this phone number and they will assist you further.
United States: +1 844 259 8811
If you still need assistance, please feel free to connect with our AVG additional remote support team with the link provided in the previous mail.
Thank you.
Additional information -
The config.msi file is created when the Crashplan silent update downloads and starts the install process of their update. The *.rbf file name it ocntains changes each time. And once the Config.msi file completes, it is removed/cleaned off the system. Running on Windows 10.
Running AVG Internet Security - ver 21.8.3202- build 21.8.6586.695
(10 device licensed version good for another 7 months)
When Crashplan (a backup service) runs a silent upgrade, AVG Behavior Shield falsely detects this as a threat and blocks the silent upgrade from happening.
The threat is identified as IDP.HEUR.24
File Path c:\Config.Msi\xxxxx.rbf
Process c:\Windows\System32\wscript.exe
Detected by Behavior Shield
Selecting More Options and creating an exception does not appear to work unless I'm entering the exception incorrectly.
The following three exceptions are now listed without working…
C:\Config.Msi
C:\Config.Msi*
C:\Config.Msi*.*
Any help available to try and prevent the false positive from causing hours of cleanup this causes about every month when an update from Crashplan is released?
Here's the picture as requested.
When the silent install from Crashplan runs (about once a month) to update their software, AVG appears to block it - which causes the file to fail to run, and thus Crashplan has to be reinstalled. Adding in the exceptions as listed above have not stopped Behavior Shield from allowing the Crashplan silent update to proceed. I've been working with Crashplan and we have been able to re-create the issue, but it's a lengthy process for those steps to get a silent update to occur.
I've included the excludes in the original update - Can you confirm if these are written correctly based on the attached screenshot?
Hello U J,
We apologize for the inconvenience caused to you.
In order to analyze the website, we request you to submit the URL for analysis through this https://www.avg.com/false-positive-file-form website.
If it is confirmed as safe, it will be whitelisted and the virus definitions database will be released through update.
You will also get the status updated via email.
Thank you and please keep us informed.
While I appreciate the offer of the remote assistance service to remote into my computer and poke around, I cannot allow that for security purposes. However, I am available to speak with a representative to provide any information they need on the configuration of AVG. I would assume they would be able to verbally provide support without having to connect to my computer.
I'll respond on the email you sent. And thank you.
We sincerely apologize for the difficulties you are currently experiencing.
We've sent you an email that offered free additional support to investigate and resolve this issue.
Please check for the email and revert to us.
Thanks for your understanding in advance.
Sreenu Yadavalli : Please actually read this thread and you will see the canned response you just gave was pointless. Please pass this issue onto someone else who will show a little more care in a response. This was not a website\url, it was AVG Behavior Shield preventing the Application Crashplan from providing a silent update. AVG Behavior Shield keeps identifying it as a false positive threat.
Please accept our apologies, if you feel this way.
I request you to contact our AVG technical team by call, they will certainly help you to resolve this matter without any further delay.
ps - the link you provided is down
| AVG
Sreenu Yadavalli : Thank you for providing the bare minimum of support.
I currently (and have never had any) blocked or allowed apps explicitly listed in AVG. And when I go to 'allowed apps' to key in an app, the options are to allow is either Ransomware Protection and/or Webcam Protection. Neither of these should be allowed.
Also – these False Positive is coming from Behavior Shield not the Ransomware or Webcam modules.
If there’s another area to allow an app in Behavior Shield, please let me know.
Picture included to show…
Note: Code42 Tray is Crashplan…
PS: All the links you have provided DO NOT work –they go to blank pages… May want to check them too…
We appreciate your effort taken to share the screenshot with the necessary information. Could you please check and confirm whether the concerned application has added in the allowed apps in AVG Internet Security? If it has been listed in the 'block app', please remove it and add the file path to the 'allow app'.
For more details, please refer this article.
Also, please let us know, if any other antivirus program are installed on your PC.
If so, please uninstall it, add the concerned app in 'allow apps' and check the status.