Author Topic: 'You've discovered a very rare file. This file might be dangerous' of our app.  (Read 2113 times)

0 Members and 1 Guest are viewing this topic.

Offline Vladislav K

  • Newbie
  • *
  • Posts: 4
Hello,
I'm working on application development for private companies use.
A user can download an executable from our site. Moreover, before download, we update resources and then sign resulting binary. So each user gets quite changed program.
The problem is that users get a warning I wrote in the subject. And to install they should click 'More', 'I trust...' which is not convenient for them.
I've read this topic https://forum.avast.com/index.php?topic=205767.0.
As I understand signing doesn't help, only a larger user base or manual submitting to the false-positive form of each new build. And I'm not sure if this helps because of updating binary for each download.

Is there a solution for this issue or a way to configure the Avast in a local network to trust our application?

Here is virustotal report https://www.virustotal.com/gui/file/f0f3f569614bf9965c95e345eb25dc9b0c3bc0f6b1c6ab36b6822c5c0b5c606c/detection

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Vladislav K

  • Newbie
  • *
  • Posts: 4
Quote
Vendors who sign their applications with digital signatures can apply for whitelisting via their digital signature. This type of whitelisting is provided to a limited number of digital signatures, and only if the software developer has a clean track record.

So we should wait for a clean track record and then apply for whitelisting via digital signature?
« Last Edit: March 27, 2019, 11:17:34 AM by Vladislav K »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
So we should wait for a clean track record and then apply for whitelisting via digital signature?
If you don't have a clean track record, you probably won't get approved.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Vladislav K

  • Newbie
  • *
  • Posts: 4
Ok, so we can't do anything but wait.
Thanks.

Offline Vladislav K

  • Newbie
  • *
  • Posts: 4
Also, forgot to ask.
If we upload the app to the Avast Threat Labs to mark it as safe. But we patch the application resources (some configs) before download, will it still be counted by Avast as the old app we uploaded before? Or it's treated as a new one?
« Last Edit: March 27, 2019, 02:48:31 PM by Vladislav K »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Ok, so we can't do anything but wait.
Thanks.
You're welcome. Everything else needs to be answered from Threat Lab.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11849
    • AVAST Software
A modified file is a different file, so I'm afraid there's no point in whitelisting it (well, unless some actual detection is reported - as a false positive).
I'd say the only way is the digital signature.