Author Topic: False Positive Win32:GenMalicious-IWR [Trj] in Maxthon Installer  (Read 3334 times)

0 Members and 3 Guests are viewing this topic.

REDACTED

  • Guest
Avast! is detecting an almost certain false positive (Win32:GenMalicious-IWR [Trj]) in the Maxthon Mx V4.4.8.2000 Installer (portable and general).



Virus Total

https://www.virustotal.com/en/file/c8768c8624c2a29c70ebacece1dec776fc295bf0817238d126fc5aa615b92111/analysis/

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: False Positive Win32:GenMalicious-IWR [Trj] in Maxthon Installer
« Reply #1 on: March 03, 2016, 04:21:29 PM »
You can report it by using this form: https://www.avast.com/en-us/false-positive-file-form.php
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Re: False Positive Win32:GenMalicious-IWR [Trj] in Maxthon Installer
« Reply #2 on: March 03, 2016, 04:32:30 PM »
Does it come bundled with PUP/WebGuard as AhnLab say?

WebGuard  >>  https://forums.malwarebytes.org/index.php?/topic/158097-removal-instructions-for-web-guard/


REDACTED

  • Guest
Re: False Positive Win32:GenMalicious-IWR [Trj] in Maxthon Installer
« Reply #3 on: March 03, 2016, 05:19:33 PM »
You can report it by using this form: https://www.avast.com/en-us/false-positive-file-form.php

OK thanks.

EDIT: I can't upload the file, it takes too long then times out.
« Last Edit: March 03, 2016, 05:49:10 PM by daveweb »

REDACTED

  • Guest
Re: False Positive Win32:GenMalicious-IWR [Trj] in Maxthon Installer
« Reply #4 on: March 03, 2016, 05:27:08 PM »
Does it come bundled with PUP/WebGuard as AhnLab say?

WebGuard  >>  https://forums.malwarebytes.org/index.php?/topic/158097-removal-instructions-for-web-guard/

I doubt it. I've been using Maxthon for over five years and I've never seen anything like this before.  Maxthon have two concomitant Windows releases: V4.9.1.1000 and V4.4.8.2000. The V4.9.1.1000 installer doesn’t flag anything.

V4.4.8.2000 was released barely hours ago though, and is showing f/p’s on only three AV’s according to VT.

This is almost certainly a false positive.
« Last Edit: March 03, 2016, 05:28:58 PM by daveweb »

REDACTED

  • Guest
Re: False Positive Win32:GenMalicious-IWR [Trj] in Maxthon Installer
« Reply #5 on: March 03, 2016, 09:11:58 PM »
Problem seems to be fixed.  8)