Author Topic: aequitas.exe  (Read 3931 times)

0 Members and 1 Guest are viewing this topic.

beegoody

  • Guest
aequitas.exe
« on: July 20, 2008, 11:57:28 AM »
First of all, hello to everyone, I am new to the forums!

I'd like to report a false positive (is it done on the forums? Please correct me if I'm wrong). Aequitas which is an anticheat tool used in a reasonably large league (http://www.esl.eu/) is detected as a Win32:Trojan-gen {Other}

The tool is available for download here : hXXp://www.esl.eu/eu/download/590704/

At first I thought mine was infected but when trying to download it, avast will prevented me from finishing the download and other people are affected by it.

According to virus total, other AVs are affected by this:

AVG
CAT-QuickHeal
eSafe
F-Secure
Fortinet
GData
Ikarus

I hope this helped,

Cheers,

beeG

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89014
  • No support PMs thanks
Re: aequitas.exe
« Reply #1 on: July 20, 2008, 02:43:39 PM »
Well with multiple detections it is more likely to be infected, however you don't say what they found (important).

GData uses two scanning engines and one of those is avast, so would also report win32:Trojan-gen, the -gen indicates a generic signature, which tries to detect multiple variants of the same malware type and is more prone to false positive detection.

If the others have suspicious or gen in their malware name then they could be using heuristic or generic signatures with the same possibility of FP, but that is speculation as you didn't say.

There is nothing to stop you in the interim submitting it as a possible FP, see http://forum.avast.com/index.php?topic=34950.msg293451#msg293451, how to report it to avast! and what to do to exclude them until the problem is corrected.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security