Author Topic: False positive on compiled report file  (Read 20758 times)

0 Members and 1 Guest are viewing this topic.

Offline mrapi

  • Full Member
  • ***
  • Posts: 137
False positive on compiled report file
« on: April 20, 2013, 07:15:04 AM »
Hi!
today avast detected one compiled report file as Win32.evo-Gen



Very strange, in virustotal list doesn't appear as detected: 
https://www.virustotal.com/en/file/30ce9d5c78a9e6fd16d6c2d2ba91ee084432837446aa4d3548707dc248640898/analysis/1366434116/
also file sent by AV interface.
Thanks

Offline Staticguy

  • Super Poster
  • ***
  • Posts: 1427
Re: False positive on compiled report file
« Reply #1 on: April 20, 2013, 01:31:53 PM »
It's good that you sent that file via Avast file submission. It will take them a while or so to review the file you submitted and update it's vps.
DELL Inspiron 15" 7000 Gaming, Windows 10 Home Version 21H1 (OS Build 19043.1237), Trend Micro Maximum Security 2021 (17.0.1333), Avast SecureLine VPN (5.12.5655), Windows Firewall, Unchecky 1.2

Offline mrapi

  • Full Member
  • ***
  • Posts: 137
Re: False positive on compiled report file
« Reply #2 on: April 20, 2013, 09:50:28 PM »
seems solved,thanks!

Offline mrapi

  • Full Member
  • ***
  • Posts: 137
Re: False positive on compiled report file
« Reply #3 on: June 04, 2013, 07:21:23 AM »
Hi,after update from today,problem is back for another compiled report file:



https://www.virustotal.com/en/file/b96971db5ae22aa64033fc0a470bacaa714f9c4b23f2caf69af426952f319a20/analysis/1370322858/

I also sent file from Avast interface
Thanks!

Offline mrapi

  • Full Member
  • ***
  • Posts: 137
Re: False positive on compiled report file
« Reply #4 on: June 06, 2013, 11:17:28 AM »
please fix that!

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: False positive on compiled report file
« Reply #5 on: June 06, 2013, 02:03:40 PM »
The first report looks to be 7-zip. Basically compresses files to a smaller size. The Second not sure. It's probably not so nice. I'd say you possibly have a virus that infecting all .exe files. If that's the case you might want to scan with MBAM (MalwareBytes Anti-Malware).
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user
Re: False positive on compiled report file
« Reply #6 on: June 06, 2013, 02:17:47 PM »
Quote
I'd say you possibly have a virus that infecting all .exe files.
malwarebytes does not detect infected files from fileinfectors.....it will only detect the executable

if there is a fileinfector, avast usually goes bananas and should give lots of alarms....


Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: False positive on compiled report file
« Reply #7 on: June 06, 2013, 02:18:58 PM »
Didn't know that. Ignore me.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline mrapi

  • Full Member
  • ***
  • Posts: 137
Re: False positive on compiled report file
« Reply #8 on: June 07, 2013, 08:00:46 AM »
Screenshots are made while I unpack the file because I put it into a zip file not to be detected/deleted
What is strange with this file is that if I scan it there is nothing found,but if I try to copy/move it,then is detected.

Rechecked with virustotal,nothing found : https://www.virustotal.com/en/file/b96971db5ae22aa64033fc0a470bacaa714f9c4b23f2caf69af426952f319a20/analysis/1370584897/

I put also file there :   hXXp://www.mediafire.com/download/5j2chzxxb4vten4/EXTRAS.zip

(change link from   hXXp... to  http... )

The first report looks to be 7-zip. Basically compresses files to a smaller size. The Second not sure. It's probably not so nice. I'd say you possibly have a virus that infecting all .exe files. If that's the case you might want to scan with MBAM (MalwareBytes Anti-Malware).
« Last Edit: June 07, 2013, 08:06:45 AM by mrapi »

Offline jefferson sant

  • Starting Graphoman
  • *
  • Posts: 6674
  • volunteer
Re: False positive on compiled report file
« Reply #9 on: June 07, 2013, 04:32:40 PM »
Screenshots are made while I unpack the file because I put it into a zip file not to be detected/deleted
What is strange with this file is that if I scan it there is nothing found,but if I try to copy/move it,then is detected.

Rechecked with virustotal,nothing found : https://www.virustotal.com/en/file/b96971db5ae22aa64033fc0a470bacaa714f9c4b23f2caf69af426952f319a20/analysis/1370584897/

I put also file there :   hXXp://www.mediafire.com/download/5j2chzxxb4vten4/EXTRAS.zip

(change link from   hXXp... to  http... )

The first report looks to be 7-zip. Basically compresses files to a smaller size. The Second not sure. It's probably not so nice. I'd say you possibly have a virus that infecting all .exe files. If that's the case you might want to scan with MBAM (MalwareBytes Anti-Malware).

please
you can use "http://www.avast.com/contact-form.php" for reporting  FPs.
« Last Edit: June 29, 2013, 05:02:23 AM by jefferson santiag »

true indian

  • Guest
Re: False positive on compiled report file
« Reply #10 on: June 07, 2013, 04:37:19 PM »
Evo-gen is only real time detection technology...not on-demand

Offline jefferson sant

  • Starting Graphoman
  • *
  • Posts: 6674
  • volunteer
Re: False positive on compiled report file
« Reply #11 on: June 07, 2013, 04:58:44 PM »
please fix that!

detection is correct
[/quote]
Evo-gen is only real time detection technology...not on-demand

confirmed
that's true.
« Last Edit: June 29, 2013, 05:02:49 AM by jefferson santiag »

Offline mrapi

  • Full Member
  • ***
  • Posts: 137
Re: False positive on compiled report file
« Reply #12 on: June 08, 2013, 08:44:08 AM »
please fix that!
detection is correct


So if detection is correct why today that was fixed?

Offline mrapi

  • Full Member
  • ***
  • Posts: 137
Re: False positive on compiled report file
« Reply #13 on: June 27, 2013, 03:30:05 PM »
From today problem is back,please fix tat is the THIRD TIME !!! :(
this time on another compiled report : please see this file http://www.mediafire.com/download/6uft9x7tm2asu35/CASHFLOW.zip

on Virustotal nothing reported :https://www.virustotal.com/en/file/0067313ba027e34ac2cde35a341c12cf2d990b6e44a3cf438c1bfecf793cde79/analysis/1372339451/

Offline mrapi

  • Full Member
  • ***
  • Posts: 137
Re: False positive on compiled report file
« Reply #14 on: June 28, 2013, 12:18:28 PM »
again,seems solved
maybe there is something wrong with detection shield :(