Author Topic: False Positive  (Read 3456 times)

0 Members and 1 Guest are viewing this topic.

Antbates1991

  • Guest
False Positive
« on: June 05, 2009, 07:56:31 PM »
Here is a false positive from avast on Virtual box hard disc files, you get this with all Windows Based Operating Systems in a Virtual Box Hard Disc File.
VPS 090604-0/ 04/06

I have reported this false positive many times before using the link on the virus alert but it hasn't been removed.
See Screen Shot
*I cant send you the files as they are both 20GB


Program Website: http://www.virtualbox.org/
« Last Edit: June 06, 2009, 10:21:13 AM by Antbates1991 »

Antbates1991

  • Guest
Re: False Posative
« Reply #1 on: June 05, 2009, 07:57:02 PM »
2nd Screen Shot

John2009

  • Guest
Re: False Posative
« Reply #2 on: June 05, 2009, 08:53:28 PM »
Scan the file at www.virustotal.com and post the results.

Offline jsejtko

  • Avast team
  • Full Member
  • *
  • Posts: 171
    • ALWIL Software
Re: False Posative
« Reply #3 on: June 05, 2009, 09:07:05 PM »
Hello,

unfortunatly it is impossible to scan those files at virustotal, because they are 20GB. I'll try to check signature for this alert, but you can add both files into exclusion lists in avast before we release the fix.

Regards

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11873
    • AVAST Software
Re: False Posative
« Reply #4 on: June 05, 2009, 09:16:06 PM »
My guess is that there are uncrypted virus signatures inside of the image (e.g. from MS Defender) - and possibly many more.
So, I don't think this can be fixed; I suggest to add the file into the list of exclusions.

Offline jsejtko

  • Avast team
  • Full Member
  • *
  • Posts: 171
    • ALWIL Software
Re: False Posative
« Reply #5 on: June 05, 2009, 09:30:24 PM »
Igor is right -> the signature looks to be good and there is known issue with MS Defender and its unencrypted virus database file. Please add full path of those files (system images) into exlusion lists, there will not be any other fix.

Regards

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11873
    • AVAST Software
Re: False Posative
« Reply #6 on: June 05, 2009, 09:45:43 PM »
Well, I think the virus database file is encrypted - but when loaded, it's decrypted into memory. And since the virtual image contains the memory of the virtual machine...

Antbates1991

  • Guest
Re: False Posative
« Reply #7 on: June 05, 2009, 11:09:32 PM »
Thanks for the help :)