Author Topic: Likely false positive uninstall program ?  (Read 6181 times)

0 Members and 1 Guest are viewing this topic.

Offline davexnet

  • Poster
  • *
  • Posts: 540
Likely false positive uninstall program ?
« on: December 03, 2010, 08:00:01 PM »
Hi, I get a notification on a file called remove.exe when I scan the HDD.
It's in a sound card drive package, apparently the uninstall program.

Here's the virustotal link:
http://www.virustotal.com/file-scan/report.html?id=d0304a38b75810789bbb6d847c8c99bc26b2d29bb6eac7902e4b4fbc7173e2f1-1291402476

Thanks for any info.
AMD FX-4300 4GB DDR3
avast free 2279 (Windows XP), MBAM free

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37600
  • Not a avast user
Re: Likely false positive uninstall program ?
« Reply #1 on: December 03, 2010, 08:40:13 PM »
ThreatExpert's awareness of the file "remove.exe":
http://www.threatexpert.com/files/remove.exe.html

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37600
  • Not a avast user
Re: Likely false positive uninstall program ?
« Reply #2 on: December 04, 2010, 05:39:05 PM »
Malwarebytes did not add detection for the file

Norman analysis: File is not malicious - REMOVE.EXE : Clean!





Sample sendt avast! ... ;)





« Last Edit: December 04, 2010, 05:46:25 PM by Pondus »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89280
  • No support PMs thanks
Re: Likely false positive uninstall program ?
« Reply #3 on: December 04, 2010, 06:20:47 PM »
Some uninstall functions will get pinged, simply because of what they do and this remove.exe. The win32:CIH actions filled the first 1024 KB of the host's boot drive with zeros and then attacked certain types of BIOS.

So I don't know exactly what remove.exe does, as some removal tools may overwrite what was removed, but I rather doubt that it is a good detection, given the low number of hits on the VT Results and Prevx calling it a 'Medium Risk Malware' which is at odds with the severity of win32:CIH. Other than prevx only avast and gdata detect anything (counts as one), see below.

http://en.wikipedia.org/wiki/CIH_%28computer_virus%29

If only GData and avast detect it - GData uses avast as one of its two scanners so counts as 1 detection and almost certainly an FP.
Even though Pondus has sent a sample, I would say you should also - Send the sample to avast as a False Positive:
Open the chest and right click on the file and select 'Submit to virus lab...' complete the form and submit, the file will be uploaded during the next update.

- In the meantime (if you accept the risk), add the full path to the file to the exclusions lists:
File System Shield, Expert Settings, Exclusions, Add and
avast Settings, Exclusions

Restore it to its original location, periodically check it (scan it in the chest), there should still be a copy in the chest even though you restored it to the original location. When it is no longer detected then you can also remove it from the File System Shield and avast Settings, exclusions lists.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37600
  • Not a avast user
Re: Likely false positive uninstall program ?
« Reply #4 on: December 04, 2010, 06:38:22 PM »
Quote
Other than prevx only avast and gdata detect anything (counts as one), see below
Prevx have removed detection ....

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89280
  • No support PMs thanks
Re: Likely false positive uninstall program ?
« Reply #5 on: December 04, 2010, 07:27:27 PM »
Definitely now only counts as one and highly likely an FP.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline misak

  • Moderator
  • Sr. Member
  • *
  • Posts: 234
    • Personal page (CZE)
Re: Likely false positive uninstall program ?
« Reply #6 on: December 04, 2010, 11:57:01 PM »
File is detected correctly. File REMOVE.exe is wise (un) installer and one of included file contains part of old virus CIH v1.2 TTIT. Virus couldn't be active, but is still there. So better detect, than sorry :-)

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89280
  • No support PMs thanks
Re: Likely false positive uninstall program ?
« Reply #7 on: December 05, 2010, 12:06:17 AM »
Thanks for the input misak.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37600
  • Not a avast user
Re: Likely false positive uninstall program ?
« Reply #8 on: December 05, 2010, 06:05:14 AM »
File is detected correctly. File REMOVE.exe is wise (un) installer and one of included file contains part of old virus CIH v1.2 TTIT. Virus couldn't be active, but is still there. So better detect, than sorry :-)
Thanks for the good explanation why some AV chose to detect and some don`t

And Norman confirmes that
Quote
Hi,
Might contain some part of  CIH infection, it seems to be corrupted. It wont infect other files anymore, its dead.

« Last Edit: December 06, 2010, 12:09:36 PM by Pondus »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37600
  • Not a avast user
Re: Likely false positive uninstall program ?
« Reply #9 on: December 06, 2010, 12:11:06 PM »
Avira lab

Quote
Thank you for your email to Avira's virus lab.
Tracking number: INC00644556.


A listing of files alongside their results can be found below:File ID    Filename   Size (Byte)   Result
25970556    REMOVE.EXE    172.63 KB    DAMAGED FILE (UNKNOWN)



Please find a detailed report concerning each individual sample below: Filename   Result    REMOVE.EXE    DAMAGED FILE (UNKNOWN)


The file 'REMOVE.EXE' has been determined to be 'DAMAGED FILE (UNKNOWN)'. In particular this means that this file is damaged and not working properly. We could not find any malicious content. However the heuristic detection module may still detect this particular file even though it is damaged. In that case we will not adjust and remove detection for this damaged file.