Author Topic: Application detected as malware?  (Read 4190 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Application detected as malware?
« on: October 19, 2016, 07:24:50 PM »
Hello,

Our company Android app, CADSYS, is being reported as a false positive by Avast. 5 other antivirus programs clears the app, only Avast marks it as malicious. We decided to pull the app immediately when this was reported. Do we need to re-publish the app for you to update Avast to pass as positive?

Our business model relies heavily on security, so this is catastrophy for us. A quick reply would be much appreciated.

Regards,

Robert


REDACTED

  • Guest
Re: Application detected as malware?
« Reply #2 on: October 19, 2016, 07:30:10 PM »
Sorry, what does that link have to do with my issue? It is just another person reporting a similar issue but with other apps?

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Application detected as malware?
« Reply #3 on: October 19, 2016, 07:36:52 PM »
There was a little problem in the latest detection database, making avast detecting a lot of apps als malicious while they are not.
That problem has been solved.

If you have the latest detection database and your app is still detected, you need to let avast know.
https://www.avast.com/false-positive-file-form.php
or
https://support.avast.com

REDACTED

  • Guest
Re: Application detected as malware?
« Reply #4 on: October 19, 2016, 07:58:20 PM »
I see. I have the latest updated database, still getting the error. Will use the link you provided to report it. Will they get back to me once it has been resolved, or will I just have to keep checking? Plus, do you know the turn around on an issue like this?

Thanks a million, Eddy.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Application detected as malware?
« Reply #5 on: October 19, 2016, 08:01:54 PM »
avast will not contact you unless they need/want more information.
They will just solve the problem if it is a false positive.

Often it is solved in the next database update.
It depend ofcourse how busy it is, if there is a holiday, a weekend and such.

Offline Ondra Cermak

  • AMS
  • Avast team
  • Full Member
  • *
  • Posts: 181
Re: Application detected as malware?
« Reply #6 on: October 19, 2016, 11:29:02 PM »
Hi, it was a false positive and is fixed by now. Tell your users to ignore the result, update the virus database of Avast Mobile Security (Settings / Updates) and then run the scan again. The correct version of virus database should be 161019-01 or newer.

Thanks and sorry for the inconvenience

Ondra

REDACTED

  • Guest
Re: Application detected as malware?
« Reply #7 on: October 20, 2016, 02:18:34 AM »
Hello Ondrej,

Definitions are updated to the version you mentioned. I uninstall the app, reinstall and Avast did not mark it as a virus. On a second Avast sweep, it said it was suspect, quoting: APK:CloudRep [susp]

How come it is ok on the first pass but not the second?

Regards, Bob

REDACTED

  • Guest
Re: Application detected as malware?
« Reply #8 on: October 20, 2016, 03:16:50 AM »
Hello Ondrej,

Never mind my last message. Was able to find out that that has to do with apps that has not had many downloads, and since it is a development build it has only a single installation, which makes sense.

https://forum.avast.com/index.php?topic=179031.0

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Application detected as malware?
« Reply #9 on: October 20, 2016, 08:40:44 AM »
You are correct about the APK:CloudRep [susp] detection.

Little info (I put it really simple):
APK = Guess that speaks for itself :)

CloudRep = Cloud Reputation
In order to have a reputation, there must be a certain amount of avast users having it installed/using it.

[susp] = Suspicious
Something that isn't hardly used/installed should be (and is) considered suspicious.
Ofcourse there can be (as it is in your case) a legitimate reason for it.

The mistake that many people make is thinking this message means the app is malicious.
But basically it only says "This app is not used by many users, make sure it is trusted if you want to use it"

Good luck with the development.