Avast WEBforum

Other => Viruses and worms => Topic started by: DWay17 on April 08, 2021, 07:39:55 AM

Title: curl of cygwin64 false positiv
Post by: DWay17 on April 08, 2021, 07:39:55 AM
Moin,
curl.exe should be a false positiv:
https://www.virustotal.com/gui/file/9f46c7137973e213e2bfcf7750fe403dfa726a337cd034ac2b422348d94f859c/detection (https://www.virustotal.com/gui/file/9f46c7137973e213e2bfcf7750fe403dfa726a337cd034ac2b422348d94f859c/detection)

kind regards
Title: Re: curl of cygwin64 false positiv
Post by: Asyn on April 08, 2021, 07:46:26 AM
You can report a suspected FP (File/Website) here: https://www.avast.com/false-positive-file-form.php
Title: Re: curl of cygwin64 false positiv
Post by: polonus on April 08, 2021, 09:29:24 AM
Hi Dway17,

In your VT report 1 engine flagged it as malicious. Cylance says unsafe.

Normally curl.exe is found to be "above board", but not under all circumstances.
The malicious variant is flagged as Trojan.Agent/Generic (a generic find).

Also read here: https://www.freefixer.com/library/file/curl.exe-70424/

One could check using freefixer or MBAM.

Wait for a final verdict from avast team, as they are the only ones to come and unblock.

Have a nice day,

polonus