Author Topic: [Solved] Autosandbox false positive: LibreOffice 3.6.6 (two components)  (Read 5732 times)

0 Members and 1 Guest are viewing this topic.

Tetsuo

  • Guest
Hello,

Just wanted to report some recent  Autosandbox (Avast! Free AV 8.0.1483) false positive:

Two LibreOffice 3.6.6 components: Base & Math.

Best regards

EDIT: just in case, Autosandbox is set to Ask (yeah...)
« Last Edit: April 13, 2013, 11:17:40 AM by Tetsuo »

Tetsuo

  • Guest
Re: Autosandbox false positive: LibreOffice 3.6.6 (two components)
« Reply #1 on: April 13, 2013, 11:17:06 AM »
Problem solved. Thank you, Avast! people.

Regards

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9404
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: Autosandbox false positive: LibreOffice 3.6.6 (two components)
« Reply #2 on: April 13, 2013, 11:17:55 AM »
Was it an actual detection or just an Auto Sandbox trigger?
Visit my webpage Angry Sheep Blog

Tetsuo

  • Guest
Re: Autosandbox false positive: LibreOffice 3.6.6 (two components)
« Reply #3 on: April 13, 2013, 11:23:25 AM »
Was it an actual detection or just an Auto Sandbox trigger?

Autosandbox is set to "Ask", so it's hard to tell for me.   This happens quite often with  brand-new versions of both Base and Math -  basically, the file prevalence is low.
Anyway, as in the past, the issue was solved quite soon.

By the way, on the new Avast! website I cannot find the link for reporting false positive...

EDIT: info added
« Last Edit: April 13, 2013, 11:31:24 AM by Tetsuo »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76213
  • Urlaub/Vacation
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Autosandbox false positive: LibreOffice 3.6.6 (two components)
« Reply #4 on: April 13, 2013, 11:27:19 AM »
By the way, on the new Avast! website I cannot find the link for reporting false positive...

You can report FPs here: http://www.avast.com/contact-form.php
W8.1 [x64] - Avast PremSec 22.7.7366.BC [UI.713] - Firefox ESR 91.11 [NS/uBO/PB] - Thunderbird 91.11
Avast-Tools: Secure Browser 103.0 - Cleanup 22.2 - SecureLine 5.18 - DriverUpdater 22.2 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Tetsuo

  • Guest
Thanks a lot, good guy Asyn :D

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76213
  • Urlaub/Vacation
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Thanks a lot, good guy Asyn :D

You're welcome. :)
W8.1 [x64] - Avast PremSec 22.7.7366.BC [UI.713] - Firefox ESR 91.11 [NS/uBO/PB] - Thunderbird 91.11
Avast-Tools: Secure Browser 103.0 - Cleanup 22.2 - SecureLine 5.18 - DriverUpdater 22.2 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

spywar

  • Guest
Re: Autosandbox false positive: LibreOffice 3.6.6 (two components)
« Reply #7 on: April 13, 2013, 11:53:15 AM »
Was it an actual detection or just an Auto Sandbox trigger?

Autosandbox is set to "Ask", so it's hard to tell for me.   This happens quite often with  brand-new versions of both Base and Math -  basically, the file prevalence is low.
Anyway, as in the past, the issue was solved quite soon.

By the way, on the new Avast! website I cannot find the link for reporting false positive...

EDIT: info added
If it's triggered by AutoSandbox but not detected by it then it's not a FP ... Just let it analyse and then press "continue execution".

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76213
  • Urlaub/Vacation
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Autosandbox false positive: LibreOffice 3.6.6 (two components)
« Reply #8 on: April 13, 2013, 11:55:53 AM »
If it's triggered by AutoSandbox but not detected by it then it's not a FP ... Just let it analyse and then press "continue execution".

It's solved already..!! ;)
W8.1 [x64] - Avast PremSec 22.7.7366.BC [UI.713] - Firefox ESR 91.11 [NS/uBO/PB] - Thunderbird 91.11
Avast-Tools: Secure Browser 103.0 - Cleanup 22.2 - SecureLine 5.18 - DriverUpdater 22.2 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9404
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
He said that already but i still don't see it as an issue. Issue would be if Auto Sandbox would falsely detect and quarantine it. Otherwise it's no different than usual heuristics that do exactly the same thing even on LibreOffice files. Exceptt hat AV doesn't tell you that its doing that. It just does it in the background.
Visit my webpage Angry Sheep Blog

Tetsuo

  • Guest
Re: [Solved] Autosandbox false positive: LibreOffice 3.6.6 (two components)
« Reply #10 on: April 13, 2013, 01:16:03 PM »
Again, Autosandbox is set to Ask (i.e., it cannot falsely quarantine it without user permission). The file's prevalence was low. That's it.

Thanks again, now let's check other more important open threads.

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9404
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: [Solved] Autosandbox false positive: LibreOffice 3.6.6 (two components)
« Reply #11 on: April 13, 2013, 04:13:08 PM »
Actually thats not entirely true. The quarantine process is automatic, you just decide what to even Auto Sandbox and what not. Unless they changed the behavior lately...
Visit my webpage Angry Sheep Blog

Tetsuo

  • Guest
Re: [Solved] Autosandbox false positive: LibreOffice 3.6.6 (two components)
« Reply #12 on: April 13, 2013, 05:46:54 PM »
Autosandbox log:

Autosandbox candidate:
C:\Programmi\LibreOffice 3.6\program\smath.exe
   [Source: local://*C:\WINDOWS\system32\msiexec.exe      ]
   [Opened by: C:\WINDOWS\Explorer.EXE]
   [Reason: 0x00020000]
    --> Result: Not sandboxing (based on user's decision).


The point is that those programs were signed and common and should have not been sandboxed in any way. In fact they (Avast!) immediately corrected the issue, that probably was caused by low file's prevalence.

EDIT: info added

PS - Listen, I have a life and yesterday evening I only reported an autosandbox FP that was fixed quite soon. So I guess it's time to stop this now...
« Last Edit: April 13, 2013, 05:54:30 PM by Tetsuo »

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9404
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: [Solved] Autosandbox false positive: LibreOffice 3.6.6 (two components)
« Reply #13 on: April 13, 2013, 05:54:13 PM »
Like i'm not allowed to ask anything about it... ???
Visit my webpage Angry Sheep Blog

Tetsuo

  • Guest
Re: [Solved] Autosandbox false positive: LibreOffice 3.6.6 (two components)
« Reply #14 on: April 13, 2013, 07:38:25 PM »
I just wanted to say that having provided all the relevant  information on my end, I'd prefer not to monitor this "closed" thread any more.

Have a nice weekend