False positive issue with virus defs 110411-1
Virus definition update 110411-1 contained an error that resulted in a good number of innocent sites being flagged as infected. Generally, all sites with a script in a specific format were affected.
Our virus lab staff discovered the problem quickly after releasing the bad update and immediately started working on a fix. The fix was released about 45 minutes after the problematic update and has version number 110411-2. Anyone who still has this problem is kindly asked to manually update the definitions to the latest version, e.g. by right-clicking the avast taskbar icon (the orange (a) ball), and selecting Update -> Engine and Virus Definitions.
We sincerely apologize for the inconvenience. As this typically only affected remote sites (and not local files), simply updating to the latest definitions should completely solve the issue (no local files have been quarantined).

English
Français
Deutsch
Italiano
日本語
Русский
Español
Čeština
polski
Português
Türkçe
Ukrainian 
I am pretty angry. Why wasn’t the definition at least rolled back until the fix was ready or any sort of communication prior to this? I just wasted 2-3 hours of my busy Monday trying to deal with this. AND, this is not the first time. Avast has been uninstalled on all systems and we have switched to AVG. I’m not the only one; you may want to check out the #avastfail twitter tag.
okay, that solved the issue here
but why are the forums down ?
It was not 45 minutes though. It was more than 1.5 hours. We were telling people to fix their internet on Twitter all that while. Still, Avast ROX!
First: Thank you for the quick fix
Second: I suggest using your Twitter account @avast_antivirus for immediate notification about a known failed update next time.
“As this typically only affected remote sites (and not local files”
Not for me, I ran a bootup test and it pickled out several local html files.
I’d also like about the update server being unreachable.
Very bad idea, since it is common that viruses block AV sites.
This really raises the need to work on protocols to handle FP-s.
Thanks VLK..what a dya eh!!
Choked by too many users seeking advice I’m afraid… but it’s better now (accessible albeit very slow).
I admit it took some additional time to push the update to all our updating servers…
Listen you … because of your fault I wiped clean my router’s server site 192.168.1.1 and now my router is kapot.
It gave me goosebumps!
*
Assuming you had avast move these files to the “Chest”, I’d recommend restoring them by going to the avast UI -> Maintenance -> Virus Chest, selecting the files in question, right-clicking them and using the Restore command from the context menu.
Hi,
I have this problem. I had analize my computer and Avast! detected more that 30.000 malware, and I removed. Are there some problem? :S
Thank you!
SUE F* AVAST!
Shortly after the problem was identified, we disconnected the updating servers from the Internet to prevent more people from getting the faulty update. The servers were restarted just after uploading the fix.
Israel Sue Avast!
As soon as I was having this problem, I called Avast support and an India sounding man insisted it was MY computer having a virus attack. I asked more than once if maybe this was a bug with the latest update and this Avast support person said ‘no’. Next thing you know, the man wants me to go to this website whereby it would allow him to have control over my computer, supposedly to see where the problem was coming from. I promptly hung up on him because I didn’t like the sound of that and again, this was someone from Avast support! Turns out is WAS a bug with the latest Avast virus definition update and this jerk wanted to get into my PC! WTF?
OH MY GOD they censored my comment! I really hope your company burns to the ground for producing such junk crap, I am writing a letter to cnn, times and Of course pcworld right now to tell them of this BLUNDER, you literally caused me LOSS, U r going down the urinal now!
I’d started a scann before boot (as I thought I was infected by a malware)… and I deleted more than 4500 html file from my computer… some were important..
Changing my anti-virus now… ( Tip: Mcafee free for 6 months on Facebook )
This has really screwed with my network and created a whole bunch of problems. Not a happy camper.
@Henry
Maybe calm down a little bit, you’re getting a heart attack …
Thanks for the quick fix. We *all* make mistakes.
I second the notion of updating @avast_antivirus on Twitter the instant an issue is discovered (and not just after it’s fixed).
Also, for those of us that are on the free personal edition (like myself), we forfeit the right to complain when a free product messes up.
I did a full and boot scan when the problem occured and I moved a lot of the flagged files into the chest. Shall I just restore them or send them to you to check? I’m worried in case there are a couple in there that may be real flags, as I haven’t run a full scan for a while.
Any chance I can copy & send them on email for you to just run your eye over? There’s so many, it would be a nightmare to send them one by one.
@oleschri Ah well, the thing is i went for FREE stuff but now I will have to buy a new router and pay for the money to get settings on it, I could have spent lesser money buying a proper anti virus from a company like norton, mcafee, etc . So, I am feeling guilty for trying to go cheap and look what it cost me !
Sadly, these guys even don’t care much but yes I will see to that their reputation will pay!
Henry, I understand your frustration but wouldn’t it be more constructive to try to work on resolving the problem as opposed to flooding the blog with comments? If you told us a bit more about the problem (and what and how exactly did you wipe the data), maybe we would be able to help. In many cases, data can be restored even after deletion.
Thanks.
Yup. Exactly. And most people are *gg*
At least this was not as bad as McAfee’s false positive on April 21, 2010, where McAfee quarantined SVCHOST.EXE which prevented Windows XP from booting, where you had to go into safe mode about 3 times and do a bunch of other thing to get it working.
At least with this Avast bug, all you need to do is wait for the new definitions to come out, then have Avast update itself.
If you have already updated to the fixed definitions (110411-2), just navigate to the Virus Chest (avast -> Maintenance -> Virus Chest), select the files in question, right-click them and select the “Scan” command. If avast says -no virus- for each of them, you can just restore them to their original location by (again) right-clicking and using the “Restore” command.
I WANT TO RESTORED MY DELETED FILES!!!!! How can I do it? :S
I agree this was very frustrating. And my organization is a paying customer of Avast, this brought us down about 2 hours today. We weren’t able to conduct buissness as our central database and customer service application are web apps.
Why isn’t there an option in the distibuted Network manager for us to roll back definitions or even perform an auto-update? Does Avast post their definition files somewhere for manual install? (since that’s the only option in the Management console.)
Also your communication on the issue was really lack luster, most of the net was screaming on Twitter and Facebook. And you didn’t say anything till it was over, no one knew if you were even aware of the issue.
I’m very disapointed, and the irony of us all of this… I was telling my boss how great you were morning. Thanks for making me eat my words.
Very disappointed in Avast that this caused so much headache today. There needs to be a better way to get this information out directly.
This caused a sales person’s laptop to crash because it moved critical system files to the virus chest.
I think it’s always your decision what you’re doing. And – well – you should know what you’re doing, right?
- you’re using a free virus scanner
- you know that virus definition updates can sometimes contain errors
- you choose to not have current backups of your servers
- you blindly follow a free virus scanner’s suggestion to delete files
…
hmmm, what does that give, in your opinion?
DELETED FILES, NOT CHEST (or TRUNK, I don’t know the exact word) @Israel Diéguez
@David H ah well I can’t connect using my dsl connection either now because somehow avast decided that my router was carrying the same set of false viruses!
@vlk Forgive me for saying this but HOW COULD you have missed this humungus error/flaw, I don’t know what to say anymore because I know my router is kapot and I also don’t see any gains from getting angry but I hope that for your own sake, for your reputation’s sake You guys DO BETTER!
Israel, please kindly proceed to the forum http://forum.avast.com/ and ask the question there. I’m sure we will be able to find a solution. (The comments section of the blog isn’t a practical place for this kind of communication though).
Thanks.
Forums were down to limit the number of angry posts that will flood in because of this definition update error…but honestly..will they say that or not…WHY WASN’T it rolled back…
“Typically ONLY affected remote sites my as_…” my html files got borked!
my pc will not update. still shows 110411-1
when ok button is clicked
Damn it! I just spent all day removing an earlier version of windows (dual boot), increasing the remaining (2nd) partition & installing a couple of bits of new hardware, tested everything, then started getting this html:Script-inf…
So I did a thourough scan of all drives, took forever, then did a boottime scan…
The trouble is, I have it set to delete the files (not move to chest) so it looks like I’ll be reinstalling my OS tomorrow. grrr.
At least nmy laptop is ok!
Thank you!
@vlk
Cheers for that vlk. Will do!
@vlk
okay, didn’t realize that so many people would rush to the forums as in my case, the correcting update came very quickly after the first FP and yeah, I had the bad update pretty late, while the forums were down already before that.
A critical system file? Which exactly?
The problem I’m talking about only affected scripts and/or html content (i.e. not binary/executable files).
I don’t have the impression that this is the case here. But it’s totally plausible that the forums went down under the unexpected traffic pressure building up in a few minutes.
@NM
lol, yeah, go ahead and njoy AVG… well you should know that from time to time everyone screws something a little. On December 2010 AVG screwed their update in a way that you would not even turn your PC on and all you could do was to use the recovery CD, sooo, in the end… maybe you will be “angrily” switching to next product in few years…
Yep, fixed here too. Thanks!
You’re wrong about the bug not effecting local files. It flagged my sessionstore.js file for Firefox, and blew away my session.
Btw, when you referred to the bad update as “bogus”, I assume that you mistyped and are not actually saying that the update was a *fake* update.
This whole fiasco is really disappointing and cost me a lot of time today. I’m no longer going to be rcmding Avast to my clients.
I have an environment where we are running 4.8 clients, managed by a 4.x ADNM. I cannot get the server to update the definitions, so that I can push out the new version.
Thanks for fixing it promptly, and for not borking up anything too badly. This could’ve been worse…