Author Topic: TextSecure (Android) / Android:Banker-BW [Trj]  (Read 4179 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
TextSecure (Android) / Android:Banker-BW [Trj]
« on: June 29, 2014, 01:44:21 PM »
Avast mobile is reporting an open source project, TextSecure, as a trojan.  The author, Moxie Marlinspike, has advised said report is a false positive (See https://twitter.com/moxie/status/482968149491335169, for example).

Offline Filip Havlicek

  • Avast team
  • Massive Poster
  • *
  • Posts: 2647
Re: TextSecure (Android) / Android:Banker-BW [Trj]
« Reply #1 on: June 29, 2014, 01:47:36 PM »
Hi,

I notified our viruslab. I'd expect an answer tomorrow :)

Filip

REDACTED

  • Guest
Re: TextSecure (Android) / Android:Banker-BW [Trj]
« Reply #2 on: June 29, 2014, 01:49:10 PM »
Thanks!  I use this app more than any on my phone, so having to approve it every 15 minutes is driving me up a wall, lol.

Offline Filip Havlicek

  • Avast team
  • Massive Poster
  • *
  • Posts: 2647
Re: TextSecure (Android) / Android:Banker-BW [Trj]
« Reply #3 on: June 29, 2014, 02:14:29 PM »
You can actually add it to ignore list if you go to AMS->Virus Scanner->Log (I think), when you tap on the infected app/file, there should be an ignore option which adds it to a permanent ignore list.

Filip
« Last Edit: June 30, 2014, 07:21:19 AM by Filip Havlicek »

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2294
Re: TextSecure (Android) / Android:Banker-BW [Trj]
« Reply #4 on: June 30, 2014, 05:45:57 AM »
Hello,
thank you for notice. False positive will be fixed.
Sorry for any inconvenience.

Milos

Offline Nikolaos Chrysaidos

  • Avast team
  • Newbie
  • *
  • Posts: 15
  • SEC.MALW/ANDROID
Re: TextSecure (Android) / Android:Banker-BW [Trj]
« Reply #5 on: June 30, 2014, 11:10:40 AM »
Fixed
Nikolaos Chrysaidos - avast! VirusLab | Android Malware Analyst

REDACTED

  • Guest
Re: TextSecure (Android) / Android:Banker-BW [Trj]
« Reply #6 on: June 30, 2014, 03:07:57 PM »
Thank you!

A quick question for anybody: How do I unignore TextSecure?

Offline Filip Havlicek

  • Avast team
  • Massive Poster
  • *
  • Posts: 2647
Re: TextSecure (Android) / Android:Banker-BW [Trj]
« Reply #7 on: June 30, 2014, 04:14:21 PM »
At the same place as you ignored it, there should be a button at the top right (or in the menu depending on your device) leading to the list of ignored files.

Filip

REDACTED

  • Guest
Re: TextSecure (Android) / Android:Banker-BW [Trj]
« Reply #8 on: June 30, 2014, 05:36:08 PM »
You mention on twitter that your manual verification in fact found some malicious code, yet you stop alarming people about TextSecure. Can you shed some light on to why? Is there a threat now or not?

Offline Filip Havlicek

  • Avast team
  • Massive Poster
  • *
  • Posts: 2647
Re: TextSecure (Android) / Android:Banker-BW [Trj]
« Reply #9 on: July 01, 2014, 02:47:56 PM »
Hi,

actually it was a kind of a misunderstanding. The detection itself catches malware, but it was also catching TextSecure. So TextSecure was indeed a false positive, but the detection was changed a bit and wasn't disabled so the detection itself is now correct as well. Those two things got mixed up together somehow during the communication between teams. So basically both statements are correct :)

Filip