Author Topic: potential false positive - again  (Read 5729 times)

0 Members and 1 Guest are viewing this topic.

Offline BTIsaac

  • Full Member
  • ***
  • Posts: 100
potential false positive - again
« on: November 09, 2013, 12:57:08 AM »
Hi. Just recently, an app that was working fine a few hours ago has been identified as Android:Bankun-D trojan. The app in question is Dark Avengers, an android game published by the company Gamevil, and has been on my phone for almost a year now. Considering this, and the fact that no other suspicious objects were detected, I'm guessing that this could be a false positive, but I'm not 100% certain. Should I report a false positive?

Just to avoid unnecessary questions later:
I'm using a Samsung tablet running android 4.1.2, and my avast mobile security version is 3.0.6542 with virus definition version 131108-01
« Last Edit: December 18, 2013, 04:13:45 PM by BTIsaac »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: potential false positive
« Reply #1 on: November 09, 2013, 01:05:38 AM »
If able to, upload the app to www.virustotal.com and test with 40+ malware scanners
Post link to scan result here

Offline BTIsaac

  • Full Member
  • ***
  • Posts: 100
Re: potential false positive
« Reply #2 on: November 09, 2013, 01:09:27 AM »
If able to, upload the app to www.virustotal.com and test with 40+ malware scanners
Post link to scan result here

Uhm... I'm not exactly sure how I'm supposed to upload an app. I'm guessing my phone needs to be rooted, but it's not.
If I report a false positive, how exactly will the people receiving the report proceed?
« Last Edit: November 09, 2013, 01:12:05 AM by BTIsaac »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: potential false positive
« Reply #3 on: November 09, 2013, 01:36:01 AM »
Quote
If I report a false positive, how exactly will the people receiving the report proceed?
avast lab will then correct the detection if it is wrong


You can upload files and report issues to avast  here : http://www.avast.com/contact-form.php  (select subject according to Your case)


Offline BTIsaac

  • Full Member
  • ***
  • Posts: 100
Re: potential false positive
« Reply #4 on: November 09, 2013, 08:00:52 AM »
I already reported a false positive using the option in the avast app. How long before I can expect some sort of result? What if the detection is genuine? Will I get some form of feedback?

Offline BTIsaac

  • Full Member
  • ***
  • Posts: 100
Re: potential false positive
« Reply #5 on: November 09, 2013, 11:49:29 AM »
One more thing. It would seem that there are multiple people complaining about the same problem in the app store, but they seem to be under the impression that there's a problem with the app itself. I find it unlikely that all of them somehow acquired the same virus that infected the same app on all devices, leaving everything else untouched, especially since some of them have already reinstalled the app, and their probleem persists.
I'm more convinced at this point that this is indeed a false positive.
« Last Edit: November 09, 2013, 12:13:52 PM by BTIsaac »

Offline Filip Havlicek

  • Avast team
  • Massive Poster
  • *
  • Posts: 2647
Re: potential false positive
« Reply #6 on: November 09, 2013, 07:59:12 PM »
Hi,

I guess that it might take a few days. I can try to speed things up if you remind me to do so on Monday.

Filip

Offline BTIsaac

  • Full Member
  • ***
  • Posts: 100
Re: potential false positive
« Reply #7 on: November 09, 2013, 08:21:39 PM »
Whoa, talk about a few days. I'll keep it in mind.

Offline BTIsaac

  • Full Member
  • ***
  • Posts: 100
Re: potential false positive
« Reply #8 on: November 11, 2013, 05:48:22 AM »
Just calling in to remind anyone concerned. At first, it would appear that the problem was fixed, and the program started launching, but avast stopped it again.

Offline Flippy

  • Avast team
  • Jr. Member
  • *
  • Posts: 45
Re: potential false positive
« Reply #9 on: November 11, 2013, 08:24:21 AM »
Hello,
we really sorry for any inconvenience. This detections cause false positive with your app. It should be fixed in next update.

Thank you and have a nice day!
Filip Chytrý
Malware Analyst

Offline BTIsaac

  • Full Member
  • ***
  • Posts: 100
Re: potential false positive
« Reply #10 on: November 11, 2013, 11:05:00 AM »
So it WAS false positive. I'm more relieved than anything. Part of me was worried that something might actually be wrong with the app, be it a design flaw, or a third party infection.

kalakala

  • Guest
Re: potential false positive
« Reply #11 on: November 13, 2013, 03:05:13 PM »
https://www.virustotal.com/en/file/0aff89e9e0f1108cbf783a48b92e87130364c509b7abb9929c18d74012f55cce/analysis/1384350051/
both 1.2.5. and 1.2.6 triggered the trojan warning
this is a very popular game on android by respected dev company,
this problem should be high priority to correct!

Offline Flippy

  • Avast team
  • Jr. Member
  • *
  • Posts: 45
Re: potential false positive
« Reply #12 on: November 13, 2013, 03:37:39 PM »
Hello, sorry it was false positive and it will be fixed in next update. Thank you and best regards, Filip Chytrý

Offline BTIsaac

  • Full Member
  • ***
  • Posts: 100
Re: potential false positive - again
« Reply #13 on: December 18, 2013, 04:20:47 PM »
I do not wish to start a new topic on the subject, so I'm reviving this ome.

This app has been targeted for the third time now. This time, it's identified as a potentially unwanted program Android:Secapk-D
To be honest, it's getting more than a little frustrating, to see one of the most well known mobile games getting repeatedly misidentified as a threat, by one of the most trusted anti virus programs.

Offline Flippy

  • Avast team
  • Jr. Member
  • *
  • Posts: 45
Re: potential false positive - again
« Reply #14 on: December 19, 2013, 09:19:52 AM »
Hello, we are really sorry for any inconvenience. Detections was fixed yesterday. Reason why this game has been flagged is multiple. 1) It have some suspicious privileges 2) new version wasnt on our clean set.

We really sorry for any inconvenience and if there will be posibillity to submit all new version of this app in viruslab we will highly appreciate it.

Best regards,
Filip Chytrý