Author Topic: False positive: ImageShrink.exe  (Read 11379 times)

0 Members and 1 Guest are viewing this topic.

saanvi

  • Guest
False positive: ImageShrink.exe
« on: December 29, 2011, 02:45:26 AM »
Hi anybody. I renamed .exe into .log and attached it. This simple utility has no rootkits; I've used it on my site and visitors reporting that it contains a rootkit (when file checking by Avast! web shield).

Offline Coolmario88

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1556
  • Bronies make the web go round
Re: False positive: ImageShrink.exe
« Reply #1 on: December 29, 2011, 02:56:49 AM »
The log is giving me a popup when i try to look at it.. an avast popup (see pic)
OS: Windows 11 64-bit
Webbrowser: Mozilla Firefox
PC Specs: Intel i5-12400f, Nvidia RTX 3050, 16gb ram, 1.5TB SSD(s).

saanvi

  • Guest
Re: False positive: ImageShrink.exe
« Reply #2 on: December 29, 2011, 03:00:17 AM »
The log is giving me a popup when i try to look at it.. an avast popup (see pic)
There is no rootkit in this file - I've told that it's a false positive. ;)

true indian

  • Guest
Re: False positive: ImageShrink.exe
« Reply #3 on: December 29, 2011, 06:15:37 AM »
i have sent the sample as a FP to avast virus lab..lets see  ;)

saanvi

  • Guest
Re: False positive: ImageShrink.exe
« Reply #4 on: December 29, 2011, 06:18:30 AM »
i have sent the sample as a FP to avast virus lab..lets see  ;)
Thanks, I just did it too. ;D

true indian

  • Guest
Re: False positive: ImageShrink.exe
« Reply #5 on: December 29, 2011, 06:20:45 AM »
can u upload the file here:

www.virustotal.com

and post the link to results here please.

Offline Coolmario88

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1556
  • Bronies make the web go round
Re: False positive: ImageShrink.exe
« Reply #6 on: December 29, 2011, 06:24:47 AM »
I have downloaded the file.. I uploaded it. 
http://www.virustotal.com/file-scan/report.html?id=81ae16f063cedad86fe2f63732dbd29e7764a58a6b4ba5d8fe523c9bb9124e1b-1325135834

the MD5 for virus total is: 65bf5ca5d39fbf509139cbd529644c8e    (Just incase the link doesn't work)

Also the file is detected by 13/ 43 antiviruses.
« Last Edit: December 29, 2011, 06:26:33 AM by Coolmario88cp »
OS: Windows 11 64-bit
Webbrowser: Mozilla Firefox
PC Specs: Intel i5-12400f, Nvidia RTX 3050, 16gb ram, 1.5TB SSD(s).

true indian

  • Guest
Re: False positive: ImageShrink.exe
« Reply #7 on: December 29, 2011, 06:27:39 AM »
interesting results..lets see what the avast virus lab has to say about this.
« Last Edit: December 29, 2011, 06:32:35 AM by true indian »

saanvi

  • Guest
Re: False positive: ImageShrink.exe
« Reply #8 on: December 29, 2011, 06:32:07 AM »
can u upload the file here:

www.virustotal.com

and post the link to results here please.
Here the results:

http://www.virustotal.com/file-scan/report.html?id=81ae16f063cedad86fe2f63732dbd29e7764a58a6b4ba5d8fe523c9bb9124e1b-1280262252

It's strange that Avast! didn't mark file as a suspicious. What "another" Avast! they have? :)

true indian

  • Guest
Re: False positive: ImageShrink.exe
« Reply #9 on: December 29, 2011, 06:33:33 AM »
this seems to be a different file...did u upload the file that u gave us??

saanvi

  • Guest
Re: False positive: ImageShrink.exe
« Reply #10 on: December 29, 2011, 06:34:11 AM »
Well, it's more and more interesting in comparing with Coolmario88cp results...

saanvi

  • Guest
Re: False positive: ImageShrink.exe
« Reply #11 on: December 29, 2011, 06:34:55 AM »
this seems to be a different file...did u upload the file that u gave us??
No, the file is the same - md5 signature shows it. Just renamed extension.

true indian

  • Guest
Re: False positive: ImageShrink.exe
« Reply #12 on: December 29, 2011, 06:35:30 AM »
can u attach the file in log format which u uploaded at VT

In that case avast catches it when it is in log format and not in exe format??

Offline Coolmario88

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1556
  • Bronies make the web go round
Re: False positive: ImageShrink.exe
« Reply #13 on: December 29, 2011, 06:36:16 AM »
this seems to be a different file...did u upload the file that u gave us??
No, the file is the same - md5 signature shows it. Just renamed extension.
Strange.. I didn't rename the file at all.
OS: Windows 11 64-bit
Webbrowser: Mozilla Firefox
PC Specs: Intel i5-12400f, Nvidia RTX 3050, 16gb ram, 1.5TB SSD(s).

true indian

  • Guest
Re: False positive: ImageShrink.exe
« Reply #14 on: December 29, 2011, 06:37:20 AM »
In that case avast catches it when it is in log format and not in exe format??

there seems to be something fishy... ::)