Author Topic: False Positives or Infected Files?  (Read 6200 times)

0 Members and 1 Guest are viewing this topic.

Offline brandon0413

  • Jr. Member
  • **
  • Posts: 20
False Positives or Infected Files?
« on: July 31, 2009, 04:46:14 PM »
These files seem to be part of a Bloomberg application that we use to get information about municipal bonds. We have recently been getting a few errors in the application pretty consistently.

04/09/2009 avast moved 3 copies of cvtres.exe to the virus chest claiming they were Win32:Trojan-gen {Other}:

submitted to virustotal 1 week ago: http://www.virustotal.com/analisis/f1bf23f41819eb03ce483d1e27fddbb0a01766c788282fbc863b08307db772fe-1248467085
submitted to virustotal today: http://www.virustotal.com/analisis/f1bf23f41819eb03ce483d1e27fddbb0a01766c788282fbc863b08307db772fe-1249048881


07/16/2009 avast moved 1 copy of csc.exe to the virus chest claiming it was Win32:Trojan-gen {Other}
07/19/2009 avast moved another copy of csc.exe from a different location to the virus chest claiming it was Win32:Spyware-gen [Trj]
I can't remember which one is which, but here they are:

submitted to virustotal 1 week ago: http://www.virustotal.com/analisis/3cb8933d96a9ae49a5943945b25c36b936ec188823003fab7b68acc87277507b-1248467413
submitted to virustotal 1 week ago: http://www.virustotal.com/analisis/24420e01050c20c625abfcf371a78dcc9f883999a58d683252f1b406e11269e7-1247728077

They are no longer detected by Avast but others detect something in them:

submitted to virustotal today: http://www.virustotal.com/analisis/24420e01050c20c625abfcf371a78dcc9f883999a58d683252f1b406e11269e7-1249048099
submitted to virustotal today: http://www.virustotal.com/analisis/24420e01050c20c625abfcf371a78dcc9f883999a58d683252f1b406e11269e7-1249048388

Jtaylor83

  • Guest
Re: False Positives or Infected Files?
« Reply #1 on: July 31, 2009, 05:44:21 PM »
All other AV vendors must be contacted to correct this false positive. All the detections appears to be generic/heuristic which be more prone to FPs.

Please submit cvtres.exe from the virus chest to Alwil so the detection can be corrected.

Offline brandon0413

  • Jr. Member
  • **
  • Posts: 20
Re: False Positives or Infected Files?
« Reply #2 on: July 31, 2009, 07:20:23 PM »
The file has been submitted.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: False Positives or Infected Files?
« Reply #3 on: July 31, 2009, 07:43:17 PM »
Thanks for helping increasing detection accuracy.
Hope they correct the false positives soon.
The best things in life are free.