Author Topic: False positive  (Read 3512 times)

0 Members and 1 Guest are viewing this topic.

guta89

  • Guest
False positive
« on: July 06, 2012, 06:35:13 PM »
How can i report a false positive?

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: False positive
« Reply #1 on: July 06, 2012, 06:40:06 PM »
You can report a possible false positive here: http://www.avast.com/contact-form.php

There is the possibility of legal detection.
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89224
  • No support PMs thanks
Re: False positive
« Reply #2 on: July 06, 2012, 08:55:19 PM »
You could also check the offending/suspect file at: VirusTotal - Multi engine on-line virus scanner and report the findings here, post the URL in the Address bar of the VT results page. You can't do this with the file securely in the chest, you need to Open the chest and right click on the file and select 'Extract' it to a temporary (not original) location first, see below.

Create a folder called Suspect in the C:\ drive. Now exclude that folder in the File System Shield, Expert Settings, Exclusions, Add, type (or copy and paste) C:\Suspect\*
That will stop the File System Shield scanning any file you put in that folder.

If only GData and avast detect it - GData uses avast as one of its two scanners so counts as 1 detection and almost certainly an FP.
Send the sample to avast as a False Positive:
Open the chest and right click on the file and select 'Submit to virus lab...' complete the form and submit, the file will be uploaded during the next update. A link to this topic wouldn't hurt.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

guta89

  • Guest
Re: False positive
« Reply #3 on: July 06, 2012, 10:34:42 PM »
The file is kavremover.exe. I tried to download,but avast has stopped it.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Re: False positive
« Reply #4 on: July 06, 2012, 10:39:24 PM »
This is Kaspersky Removal Tool. Did you check it against the Virustotal scanner to see if it is a legit file? Is avast the only one flagging it, as that could be a sign of it being a FP,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: False positive
« Reply #5 on: July 06, 2012, 10:43:17 PM »
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

guta89

  • Guest
Re: False positive
« Reply #6 on: July 07, 2012, 12:11:34 AM »
from support.kaspersky.com

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Re: False positive
« Reply #7 on: July 07, 2012, 12:20:58 AM »
Could have been a false packer detect - binayries,
Given clean here: http://vscan.urlvoid.com/analysis/17a04bf49a4c9a8d4d1b316bd45e0ea6/a2F2cmVtb3Zlci1leGU=/
Suspicious here: http://zulu.zscaler.com/submission/show/2d656ab36507c2f407123b779775b435-1341613048
Something here, IDS alerts: http://urlquery.net/report.php?id=84321 Some botnet spoof  executable flowbit alert
(possibly bad PCAP) users of Kaspersky Removal Tool don't wanna drop that executable, net admins might (pol)

polonus
« Last Edit: July 07, 2012, 12:33:34 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: False positive
« Reply #8 on: July 07, 2012, 12:24:06 AM »
Is it Sandbox?
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."