Avast WEBforum

Other => Viruses and worms => Topic started by: REDACTED on November 21, 2017, 03:31:56 PM

Title: False Positive
Post by: REDACTED on November 21, 2017, 03:31:56 PM
Hello Everyone.
I've been using Avast Free for over 2 years.
Several years ago I purchased the programs of this developer:
http://soft4boost.com/

Today in the morning I tried to update some of them. However, I was unpleasantly surprised: Avast alarms that the file is infection: FileRepMalware. I sent it to your virus laboratory and from there it came the answer that the file is really infected. I wrote to the developers and they told me that this is a false positive. I sent one of their programs to viristotal.com and received the following report:
https://www.virustotal.com/#/file/cff8981c1c60e43b48b94c857d6a2f15e5ac13ca45ff59a55daeded412666bd2/detection

It looks like it really is. I'm at a loss - I'm really used to using these programs and the Avast antivirus. What should I do? :(
Title: Re: False Positive
Post by: Pondus on November 21, 2017, 05:43:05 PM
As the text under this forum section Name say > No virus or FP here

Use Viruses and Worms section.
In sticky post at top there you find how to report instructions

Title: Re: False Positive
Post by: bob3160 on November 21, 2017, 10:36:10 PM

Submitting files from the Virus Chest to Avast Virus Lab
https://www.avast.com/faq.php?article=AVKB21#idt_07
Title: Re: False Positive
Post by: nalo89 on November 22, 2017, 02:12:43 AM
I had the same problem with Avast Free reading a number of Nirsoft files in the Nirsoft Launcher as being pup's and malware etc.I opened the Behaviour shield and excluded the self run folder and content being read and also used the global exclusion facility. I was still getting files being seen as false positives and opening the virus chest saw that Avast in Appdata/Roaming was the cause so I excluded it also from reading and then went back to the Virus Chest and restored all the affected Nirsoft files.
Title: Re: False Positive
Post by: REDACTED on November 22, 2017, 09:38:28 AM
As the text under this forum section Name say > No virus or FP here

Use Viruses and Worms section.
In sticky post at top there you find how to report instructions

Sorry.
I don't know how move topic to another section, so I created the new one:
https://forum.avast.com/index.php?topic=211108.0
Title: Re: False Positive
Post by: Milos on November 22, 2017, 10:37:57 AM
Hello,
digital signature was used for signing SW, which is on the deceptor list: https://customer.appesteem.com/deceptors

Milos
Title: Re: False Positive
Post by: REDACTED on November 23, 2017, 07:53:10 AM
Thank you for a link, Milos.

I see the reason: "The application exaggerates the number of invalid registry keys, lists the normal browser extensions as problems, browser history and junk files as problems. The overall exaggerated scanning result leads misleading urgency for user to take action fixing the problems."

I do not agree with this point, so I've been using this application successfully for a year and a half. In any case, I hope that the guys from Soft4Boost will be able to solve this problem.

I'm wondering why avast on this basis issues alarm report about a completely different program?
https://www.virustotal.com/#/file/cff8981c1c60e43b48b94c857d6a2f15e5ac13ca45ff59a55daeded412666bd2/detection

It is obvious that this is a false positive for this program, isn't it?
Title: Re: False Positive
Post by: Milos on November 23, 2017, 11:18:09 AM
Hello,
using the same certificate for signing both clean and PUP/adware apps makes mess in classification and the certificate cannot be trusted. Solution for an author of the app is to obtain new certificate and use it only for clean apps and/or get certification from AppEsteem.

Milos
Title: Re: False Positive
Post by: REDACTED on November 23, 2017, 02:50:02 PM
Hello.

As a user, I see that Avast gives a false positive alarm to a completely clean file. Why does he do, it make me care less. If Avast is positioning itself as a good antivirus, it should try to fix it. Such situations harm the reputation of any antivirus software. Do you agree with me?
Title: Re: False Positive
Post by: Milos on November 24, 2017, 10:08:07 AM
Hello,
from the provided information it is not "completely clean file".

Milos
Title: Re: False Positive
Post by: REDACTED on November 24, 2017, 11:08:31 AM
Of course, because Avast\AVG alarms to this file, so the file is not "completely clean file":
https://www.virustotal.com/#/file/cff8981c1c60e43b48b94c857d6a2f15e5ac13ca45ff59a55daeded412666bd2/detection

Bravo!
Title: Re: False Positive
Post by: polonus on November 24, 2017, 02:09:14 PM
@krisdima,

You base your view probably on this report a Belize based firm Comodo certification for unnamed Russian owner(s):
https://www.reasoncoresecurity.com/signer-sorentio-systems-ltd-00ee7a82a1605277bf31c11500157b4d6b.aspx

Controversy and questionable web reputation also as adware-"somoto" forced installation>  http://www.urlvoid.com/scan/soft4boost.com/
No verifiable data http://news.softodrom.ru/ap/b21639.sh

polonus (volunteer website security analyst and website error-hunter)
Title: Re: False Positive
Post by: REDACTED on November 24, 2017, 08:56:33 PM
Thank you for your information - it makes you wonder about the Soft4Boost as a company. Bur I have a positive experience with the use of programs from Soft4Boost and Avast Free both. The programs of Soft4Boost have more value for me, cause I buy the purchase for these programs but as for avast, i use the free version - this is natural from the point of view of psychology.

Anyway, I remain in my opinion - to my mind this is a false positive alarm:
https://www.virustotal.com/#/file/cff8981c1c60e43b48b94c857d6a2f15e5ac13ca45ff59a55daeded412666bd2/detection
Title: Re: False Positive
Post by: Pondus on November 24, 2017, 09:13:17 PM
Well I would not call bad reputation a false positive   

Title: Re: False Positive
Post by: bob3160 on November 25, 2017, 06:12:10 PM
Well I would not call bad reputation a false positive   
A crook can also be a nice person or good product. That doesn't change the fact, he/she/it is still a crook. :)