Author Topic: Detected Win32:Adware-gen Fairuse wizard 2 False Positive??  (Read 4864 times)

0 Members and 1 Guest are viewing this topic.

puppetj

  • Guest
Detected Win32:Adware-gen Fairuse wizard 2 False Positive??
« on: October 01, 2008, 10:52:15 PM »
Is Fairuse wizard 2 a False Positive??

As i see in there forums, being told thats true:

http://www.dvd-guides.com/component/option,com_smf/Itemid,91/action,search2





Here my Virus total Scan

File FU-Setup_LE.exe received on 10.01.2008 02:34:29 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
Result: 2/36 (5.56%)
Loading server information...
Your file is queued in position: ___.
Estimated start time is between ___ and ___ .
Do not close the window until scan is complete.
The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
If you are waiting for more than five minutes you have to resend your file.
Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.
Compact Compact
Print results Print results
Your file has expired or does not exists.
Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.

You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
Email:   
   
Antivirus    Version    Last Update    Result
AhnLab-V3   2008.10.1.0   2008.09.30   -
AntiVir   7.8.1.34   2008.09.30   -
Authentium   5.1.0.4   2008.09.30   -
Avast   4.8.1195.0   2008.09.30   Win32:Adware-gen
AVG   8.0.0.161   2008.09.30   -
BitDefender   7.2   2008.10.01   -
CAT-QuickHeal   9.50   2008.09.30   -
ClamAV   0.93.1   2008.10.01   -
DrWeb   4.44.0.09170   2008.09.30   -
eSafe   7.0.17.0   2008.09.30   -
eTrust-Vet   31.6.6118   2008.09.30   -
Ewido   4.0   2008.09.30   -
F-Prot   4.4.4.56   2008.09.30   -
F-Secure   8.0.14332.0   2008.10.01   -
Fortinet   3.113.0.0   2008.09.30   -
GData   19   2008.10.01   Win32:Adware-gen
Ikarus   T3.1.1.34.0   2008.10.01   -
K7AntiVirus   7.10.478   2008.09.30   -
Kaspersky   7.0.0.125   2008.10.01   -
McAfee   5395   2008.10.01   -
Microsoft   1.4005   2008.10.01   -
NOD32   3484   2008.09.30   -
Norman   5.80.02   2008.09.30   -
Panda   9.0.0.4   2008.09.30   -
PCTools   4.4.2.0   2008.09.30   -
Prevx1   V2   2008.10.01   -
Rising   20.63.62.00   2008.09.28   -
SecureWeb-Gateway   6.7.6   2008.10.01   -
Sophos   4.34.0   2008.10.01   -
Sunbelt   3.1.1675.1   2008.09.27   -
Symantec   10   2008.10.01   -
TheHacker   6.3.0.9.097   2008.09.29   -
TrendMicro   8.700.0.1004   2008.09.30   -
VBA32   3.12.8.6   2008.09.30   -
ViRobot   2008.9.30.1397   2008.09.30   -
VirusBuster   4.5.11.0   2008.09.30   -
Additional information
File size: 8214801 bytes
MD5...: c12ff23dde2257a91e59da88c9dcdda1
SHA1..: 9312a535e9dd9034f50c2e62ec6199a9cd035b8b
SHA256: 5cc46ecb7d51f4aeffa597a9864777f75ada6f8a4be430870fde0251742aa0b1
SHA512: 7898a55a24050d42c211d2da9a46875954e5e879cdc4fe2ad69494c9e1a8e5d1
3ad1463926ef95f9a199621ff44ef7488062cd6e43f8c6182add347aa12a14da
PEiD..: -
TrID..: File type identification
Win32 Executable Generic (58.3%)
Win16/32 Executable Delphi generic (14.1%)
Generic Win/DOS Executable (13.7%)
DOS Executable Generic (13.6%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x40998c
timedatestamp.....: 0x2a425e19 (Fri Jun 19 22:22:17 1992)
machinetype.......: 0x14c (I386)

( 8 sections )
name viradd virsiz rawdsiz ntrpy md5
CODE 0x1000 0x909c 0x9200 6.55 5c85f6eca8dd457c844f53af07a11be7
DATA 0xb000 0x24c 0x400 2.73 e79cf3fe610f881d632107e630eb8d98
BSS 0xc000 0xe3c 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
.idata 0xd000 0x950 0xa00 4.43 bb5485bf968b970e5ea81292af2acdba
.tls 0xe000 0x8 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
.rdata 0xf000 0x18 0x200 0.20 9ba824905bf9c7922b6fc87a38b74366
.reloc 0x10000 0x8b0 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
.rsrc 0x11000 0x17b84 0x17c00 4.85 2a67077ee2bbad38baa408c861979558

( 8 imports )
> kernel32.dll: DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, VirtualFree, VirtualAlloc, LocalFree, LocalAlloc, WideCharToMultiByte, TlsSetValue, TlsGetValue, MultiByteToWideChar, GetModuleHandleA, GetLastError, GetCommandLineA, WriteFile, SetFilePointer, SetEndOfFile, RtlUnwind, ReadFile, RaiseException, GetStdHandle, GetFileSize, GetSystemTime, GetFileType, ExitProcess, CreateFileA, CloseHandle
> user32.dll: MessageBoxA
> oleaut32.dll: VariantChangeTypeEx, VariantCopyInd, VariantClear, SysStringLen, SysAllocStringLen
> advapi32.dll: RegQueryValueExA, RegOpenKeyExA, RegCloseKey, OpenProcessToken, LookupPrivilegeValueA
> kernel32.dll: WriteFile, VirtualQuery, VirtualProtect, VirtualFree, VirtualAlloc, Sleep, SizeofResource, SetLastError, SetFilePointer, SetErrorMode, SetEndOfFile, RemoveDirectoryA, ReadFile, LockResource, LoadResource, LoadLibraryA, IsDBCSLeadByte, GetWindowsDirectoryA, GetVersionExA, GetUserDefaultLangID, GetSystemInfo, GetSystemDefaultLCID, GetProcAddress, GetModuleHandleA, GetModuleFileNameA, GetLocaleInfoA, GetLastError, GetFullPathNameA, GetFileSize, GetFileAttributesA, GetExitCodeProcess, GetEnvironmentVariableA, GetCurrentProcess, GetCommandLineA, GetACP, InterlockedExchange, FormatMessageA, FindResourceA, DeleteFileA, CreateProcessA, CreateFileA, CreateDirectoryA, CloseHandle
> user32.dll: TranslateMessage, SetWindowLongA, PeekMessageA, MsgWaitForMultipleObjects, MessageBoxA, LoadStringA, ExitWindowsEx, DispatchMessageA, DestroyWindow, CreateWindowExA, CallWindowProcA, CharPrevA
> comctl32.dll: InitCommonControls
> advapi32.dll: AdjustTokenPrivileges

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89234
  • No support PMs thanks
Re: Detected Win32:Adware-gen Fairuse wizard 2 False Positive??
« Reply #1 on: October 01, 2008, 11:48:45 PM »
It would certainly seem so as GData has two scanning engines, one of them avast, so that would make just one detection.

If you send the sample again, your having a few hits with the generic (-gen suffix) signatures ???
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

puppetj

  • Guest
Re: Detected Win32:Adware-gen Fairuse wizard 2 False Positive??
« Reply #2 on: October 02, 2008, 12:52:40 AM »
yeah i did, and what do u mean by "your having a few hits with the generic (-gen suffix) signatures"

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89234
  • No support PMs thanks
Re: Detected Win32:Adware-gen Fairuse wizard 2 False Positive??
« Reply #3 on: October 02, 2008, 01:23:33 AM »
You have had a couple of other FPs Win32:Adware-gen with some alcohol 120% files.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

puppetj

  • Guest
Re: Detected Win32:Adware-gen Fairuse wizard 2 False Positive??
« Reply #4 on: October 02, 2008, 02:29:37 AM »
yeah but that was an Win32:Tiny-WL [trj]

why?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89234
  • No support PMs thanks
Re: Detected Win32:Adware-gen Fairuse wizard 2 False Positive??
« Reply #5 on: October 02, 2008, 02:45:13 AM »
It is just that you haven't had much luck with FPs.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security