Author Topic: Nox App Player - False Positive?  (Read 11755 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Nox App Player - False Positive?
« on: March 26, 2017, 01:12:12 AM »
I've had Nox installed for some time now and I know it's a pretty popular android emulator. Today I had checked my laptop and found the "uninst.exe" file in the "Program Files (x86)/Bignox" folder infected with a Win32:DH-AI malware. I later scanned the file on my PC and it treated it the same way and went to the virus chest.

It never had a problem earlier, and I see no reports of the virus anywhere else so I was thinking it was just caused by a virus definitions update or something, but I just want to be sure if it was a false positive or something.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76017
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Nox App Player - False Positive?
« Reply #1 on: March 26, 2017, 09:43:39 AM »
Test the file at VT (https://www.virustotal.com) and post the link to the result here.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: Nox App Player - False Positive?
« Reply #2 on: March 26, 2017, 10:48:20 PM »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37697
  • F-Secure user
Re: Nox App Player - False Positive?
« Reply #3 on: March 26, 2017, 10:56:09 PM »
So I guess that means it's safe and just a false positive?
Yepp    ;)      First submission 2016-11-09 23:12:30 UTC ( 4 months, 2 weeks ago )



Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89640
  • No support PMs thanks
Re: Nox App Player - False Positive?
« Reply #4 on: March 26, 2017, 11:00:27 PM »
https://www.virustotal.com/en/file/06e28f3b170f08f7794ad03875df8018be4b228b169f022b2c381fce12575ac4/analysis/1490561098/

So I guess that means it's safe and just a false positive?

Whilst it is a good start, there are certain things that aren't scanned for in an on-demand scan, which is done by the virus total site.

There occasions that uninstall functions might look suspicious, given what they can/programmed to do, run around deleting things files, registry entries, etc.

There have been a few detections of Win32:DH-AI that were FPs, so yes this should be submitted to avast as a possible FP. If this file is in the virus chest, right click on it and select Submit to virus lab...
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free  24.8.6127 (build 24.8.9372.862) UI 1.0.814/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2297
Re: Nox App Player - False Positive?
« Reply #5 on: March 27, 2017, 08:59:14 AM »
Hello,
send us the detected file through https://www.avast.com/false-positive-file-form.php

Milos