Author Topic: False positive ?  (Read 3935 times)

0 Members and 1 Guest are viewing this topic.

Offline patclash

  • Jr. Member
  • **
  • Posts: 35
False positive ?
« on: November 15, 2011, 04:53:39 PM »
Hi all,
I have an alert when I try to download "KernelEx v4.5.2.exe" from this site :
hxxp://kernelex.sourceforge.net/2011/11/kernelex-v4-5-2-released/

If I add the file in the exception , I can download it but if I scan it with Avast, it is be in quarantine  :(

My version of Avast is 6.0.1289
If you can have a look
 ::)
Thanks






« Last Edit: November 16, 2011, 01:08:38 AM by igor »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: False positive ?
« Reply #1 on: November 15, 2011, 04:56:33 PM »
what alert...alert on the site or the file ?

can you attach a screenshot of the avast warning


OK i guess it is on the file   ;)



VirusTotal - KernelEx-4.5.2.exe - 2/41
http://www.virustotal.com/file-scan/report.html?id=b4d4e6475ecf5e3099c0807ba85340a07dabdf9ac0d77b9f03fa5c37312c321b-1321372344
« Last Edit: November 15, 2011, 05:23:00 PM by Pondus »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: False positive ?
« Reply #2 on: November 15, 2011, 05:03:06 PM »
Blacklist status
Domain clean by Google Safe Browsing: kernelex.sourceforge.net - reference
Domain clean by Norton Safe Web: kernelex.sourceforge.net - reference
Domain clean on Phish tank: kernelex.sourceforge.net - reference

Sucuri
web site:    hxxp://kernelex.sourceforge.net/2011/11/kernelex-v4-5-2-released/
status:    Verified Clean
web trust:     Not Blacklisted

Security report (No threats found):
check       Blacklisted:      No
check   Malware:    No
check   Malicious javascript:      No
check   Malicious iFrames:    No
check   Drive-By Downloads:      No
check       Anomaly detection:      No
check       IE-only attacks:        No
check   Suspicious redirections:        No
check   Spam:   No

Looks clean for me, also no avast! alerts...!!
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline patclash

  • Jr. Member
  • **
  • Posts: 35
Re: False positive ?
« Reply #3 on: November 15, 2011, 05:39:47 PM »
Here a screenshot :

 ::)

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: False positive ?
« Reply #4 on: November 16, 2011, 12:57:39 AM »
SOPHOS lab
Quote
thank you for the submission, this files are all not detection worthy, they are too weak

Some weak minor AV vendor detections:

Avast 6.0.1289.0 2011.11.15 Win32:SuspBehav-J [Heur]
GData 22 2011.11.15 Win32:SuspBehav-J

Seems to only run on windows 98/ME

This ticket will now be closed.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: False positive ?
« Reply #5 on: November 16, 2011, 01:04:48 AM »
Hi patclash & Pondus,

Make that link not click through like hxtp or -http
I get an alert from my XSS detector for a chromeplugin XSS attack. The link is the attack vector there,

polonus



« Last Edit: November 16, 2011, 01:10:45 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!