illustrate
Products            Buy            Support Forum            Registrations            About           
 

Avira antivirus has just flagged two files as malware - why?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Hadron

    • May 2026
    • 1

    #1

    Avira antivirus has just flagged two files as malware - why?

    My Avira antivirus program has flagged the following files from within dBpoweramp as containing a malware called DR with the following description "The term 'DR' denotes a program that is able to place a virus or malware discretely on a system." They have been put into quarantine within Avira.
    The files are dMCShell.dll and Ogg Vorbis.dll
  • Spoon-
    Administrator
    • Apr 2002
    • 46002

    #2
    See last message:

    The following lists security software which is not performing as it should, that is blocking legitimate programs (such as dBpoweramp) from running. There is nothing we can do on our side, we produce legitimate software, virus free for the last 20 years, never once have we supplied a virus, Trojan, spyware with any of our
    Spoon-
    www.dbpoweramp.com

    Comment

    • Dat Ei
      dBpoweramp Supporter
      • Feb 2014
      • 1904

      #3
      Hey Spoon,

      Norton, Avast, AVG again (they are all the same product)...
      this time Sophos Home joined the party. This is the first time that Sophos detects dBpa as a problem (same findings: dMCShell.dll and Ogg Vorbis.dll).

      Dat Ei

      Comment

      • Spoon-
        Administrator
        • Apr 2002
        • 46002

        #4
        There must be an option in the program to submit the files to examination.
        Spoon-
        www.dbpoweramp.com

        Comment

        • Dat Ei
          dBpoweramp Supporter
          • Feb 2014
          • 1904

          #5
          There is an option in Sophos Home to handle this false positive and allow the access on those two DLLs. But I thought it is worth to mention that this release is detected as problematic by Sophos Home too, which has never been the case in the at least 10 years.

          I have Sophos Endpoint Control (professional version of Sophos) on my business PC, so I can test that too.


          Dat Ei

          Comment

          • Spoon-
            Administrator
            • Apr 2002
            • 46002

            #6
            What is it detected as? (the false positive)
            Spoon-
            www.dbpoweramp.com

            Comment

            • Spoon-
              Administrator
              • Apr 2002
              • 46002

              #7
              Ok here is the current detections, dmcshell.dll:



              Nothing flags.

              Ogg Vorbis.dll (encoder) just two detect as 'generic':



              As the files are analyzed they will be removed from the flagging.

              The sad thing is, each time we re-compile the program, the same can happen. The generic detections should be removed from antivirus, they serve no purpose.
              Spoon-
              www.dbpoweramp.com

              Comment

              • Dat Ei
                dBpoweramp Supporter
                • Feb 2014
                • 1904

                #8
                Hey Spoon,

                here are the details:

                Mal/Generic-S: C:\Program Files\dBpoweramp\DSPs\ID Tag Processing.dll
                Mal/Generic-S: C:\Program Files\dBpoweramp\encoder\Ogg Vorbis.dll

                ​Those details were generated when I tried to rip a CD. After I have marked both dlls as "false positive", I could rip without any problems.

                When I now scan those dll files, Sophos shows no detections at. So I think Sophos has alarmed based on an analysis of the programs bevahior, rather than a typical virus pattern.


                Dat Ei

                Comment

                Working...