Author Topic: FileZilla False Positive? FileZilla_3.11.0.1_win64-setup.exe  (Read 6784 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Is Avast still doing false positives on Filezilla?  Note the version and the location the file is sourced from.

Filezilla web site say they trust sourceforge.net so who do I trust?

I downloaded this from the soundforge.net
http://sourceforge.net/projects/filezilla/files/FileZilla_Client/3.11.0.1/FileZilla_3.11.0.1_win64-setup.exe/download?accel_key=57%3A1432465143%3Ahttps%253A//filezilla-project.org/download.php%253Ftype%253Dclient%3Ac37ab1bf%24735becda88582f3f0d5db51cfaebf19f0e436b16&click_id=e3e25412-0203-11e5-9c17-0200ac1d1d8b&source=accel

Avast prompts me that it is a threat - Avast Harden mode prevented a program from starting on your computer.

I am using version 3.5.1 as it doesn't seem to have any problem with that version.  Would love to know if Avast is getting it wrong.

Thanks.


« Last Edit: May 24, 2015, 04:04:09 PM by LateralNW »

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: FileZilla False Positive? FileZilla_3.11.0.1_win64-setup.exe
« Reply #1 on: May 24, 2015, 04:37:21 PM »
Report it as a (possible) false positive:
https://blog.avast.com/tag/false-positive/

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: FileZilla False Positive? FileZilla_3.11.0.1_win64-setup.exe
« Reply #2 on: May 24, 2015, 04:47:35 PM »
seems to containe PUP crap ... not shown on VT but also detected by Norman/BlueCoat as  BundlePack.IC
https://www.virustotal.com/nb/file/17cdbf85c925baba6be58c080484bd5200fcee7c370dc2ffbf04e9f9d45ee75c/analysis/1432478773/

Info here confirms the detection name given by Comodo

Quote
  Authenticode signature block
Copyright
Publisher Funnel Delivery (Fried Cookie Ltd.)
Product Web
File version
Description Web Setup
Comments This installation was built with Inno Setup.
Signature verification  Signed file, verified signature
Signers   
  • Funnel Delivery (Fried Cookie Ltd.)
  • GlobalSign CodeSigning CA - G2
  • GlobalSign


« Last Edit: May 25, 2015, 03:11:17 PM by Pondus »

REDACTED

  • Guest
Re: FileZilla False Positive? FileZilla_3.11.0.1_win64-setup.exe
« Reply #3 on: May 24, 2015, 05:15:30 PM »
seems to containe PUP crap ... not shown on VT but also detected by Norman/BlueCoat as  BundlePack.IC
https://www.virustotal.com/nb/file/17cdbf85c925baba6be58c080484bd5200fcee7c370dc2ffbf04e9f9d45ee75c/analysis/1432478773/


Thanks for the heads up.  So it would seem that the program is still getting crap put in it even from a respectable site.

It would be nice if Avast actually identified why it blocks a program. 

The link you gave showed the infection as different possibilities which also doesn't help working out what to expect. 

Looks like I'll stick with the old version of Filezilla 3.5.1



Offline Gopher John

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2098
Re: FileZilla False Positive? FileZilla_3.11.0.1_win64-setup.exe
« Reply #4 on: May 25, 2015, 01:30:52 AM »
I downloaded Filezilla 3.11.0.1 from http://tcpdiag.dl.sourceforge.net/project/filezilla/FileZilla_Client/3.11.0.1/FileZilla_3.11.0.1_win64-setup.exe and Avast didn't alert on it back on May 22nd nor just now.  MalwareBytes scan also had no issues with the download or install.
AMD A6-5350M APU with Radeon HD Graphics, 8.0GB RAM, Win7 Pro SP1 64bit, IE11
i7-3610QM 2.3GHZ, 8.0GB Ram,  Nvidia GeForce GT 630M 2GB, Win7 Pro SP1 64bit, IE 11
Common to both: Avast Premium Security 19.7.2388, WinPatrol Plus, SpywareBlaster 5.5, Opera 12.18, Firefox 68.0.2, MBam Free, CCleaner


Offline Gopher John

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2098
Re: FileZilla False Positive? FileZilla_3.11.0.1_win64-setup.exe
« Reply #6 on: May 25, 2015, 02:31:44 AM »
I offered a link to what I consider a clean download.  VirusTotal results verify that the sourceforge link points to a modified file which has, at minimun, a pup added.
AMD A6-5350M APU with Radeon HD Graphics, 8.0GB RAM, Win7 Pro SP1 64bit, IE11
i7-3610QM 2.3GHZ, 8.0GB Ram,  Nvidia GeForce GT 630M 2GB, Win7 Pro SP1 64bit, IE 11
Common to both: Avast Premium Security 19.7.2388, WinPatrol Plus, SpywareBlaster 5.5, Opera 12.18, Firefox 68.0.2, MBam Free, CCleaner

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: FileZilla False Positive? FileZilla_3.11.0.1_win64-setup.exe
« Reply #7 on: May 25, 2015, 02:42:09 AM »
Your link also points to sourceforge  ;)

Offline Gopher John

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2098
Re: FileZilla False Positive? FileZilla_3.11.0.1_win64-setup.exe
« Reply #8 on: May 25, 2015, 02:51:38 AM »
Your link also points to sourceforge  ;)

But the file is clean. ;D
AMD A6-5350M APU with Radeon HD Graphics, 8.0GB RAM, Win7 Pro SP1 64bit, IE11
i7-3610QM 2.3GHZ, 8.0GB Ram,  Nvidia GeForce GT 630M 2GB, Win7 Pro SP1 64bit, IE 11
Common to both: Avast Premium Security 19.7.2388, WinPatrol Plus, SpywareBlaster 5.5, Opera 12.18, Firefox 68.0.2, MBam Free, CCleaner

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: FileZilla False Positive? FileZilla_3.11.0.1_win64-setup.exe
« Reply #9 on: May 25, 2015, 08:43:19 AM »
Both are clean, it is just that the first one is bundled with some extras. Some may want it, others not, thats why it is called PUP / Possible Unwanted Program 
if you compare file size ( 730kb  vs  6,2mb )   it seems the first one is just a downloader for the program, like the one from cnet and similar

« Last Edit: May 25, 2015, 03:09:40 PM by Pondus »

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: FileZilla False Positive? FileZilla_3.11.0.1_win64-setup.exe
« Reply #10 on: May 25, 2015, 01:10:27 PM »
Thanks Pondus. Seems that FilleZilla is doing something fishy... It's not the first time it is flagged as PUP...
The best things in life are free.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: FileZilla False Positive? FileZilla_3.11.0.1_win64-setup.exe
« Reply #11 on: May 25, 2015, 02:45:04 PM »
Strange is that both claim to be the 64 bit version, but if you look at the file details one is saying the original name is 32 bit.
According to the description both are the installers for the exact same application.

Strange thing is the two different original file names, the two different publishers... etc.
You would (could?) expect there is just one person that publish things.

LateralNW,
SourceForge is (at least in theory) a trusted site.
But that doesn't mean all software published there is/can be trusted.

REDACTED

  • Guest
Re: FileZilla False Positive? FileZilla_3.11.0.1_win64-setup.exe
« Reply #12 on: May 25, 2015, 10:26:00 PM »
If you wish to avoid downloading FileZilla (with included rubbish) then you need to click "download" the option in the menu on the left-hand side.

Then the "Show additional download options" link (located on the main page).

This should take you to the following url

https://filezilla-project.org/download.php?show_all=1

Select the relevant x32 or x64 build.

REDACTED

  • Guest
Re: FileZilla False Positive? FileZilla_3.11.0.1_win64-setup.exe
« Reply #13 on: September 02, 2015, 12:06:05 AM »
Just an update
I have since downloaded from this link and Avast did not complain.
so I am assuming that this particular downloadable file is free from malware/pup/virus etc.


https://filezilla-project.org/download.php?show_all=1
I selected for x64 bit windows
FileZilla_3.13.1_win64.zip

I noticed that when I attempted to do the same process again (to supply a link to this post) from the renewed link page that the file name was different, giving me the impression that there was a later version based on its file name!
I backed tracked and the link I have supplied is exactly the steps I took.

File details are
version 3.13.1.0
filezilla.exe ‎Monday, ‎24 ‎August ‎2015, ‏‎3:56:48 PM actual size 11.5 MB (12,098,520 bytes)

all the other files appear to be date stamped exactly the same as above.

certificate details


Hope that helps others who may have had this problem.