Author Topic: False positive  (Read 2523 times)

0 Members and 1 Guest are viewing this topic.

Theliel

  • Guest
False positive
« on: May 23, 2007, 01:42:50 AM »
Well, I found a false positve.

File in cuestiom are uninstall.exe from ZoomPlayer 5.5 alpha.
Virus: Win32:Zlob-YG
Virus definition: 742-1 22/05/07

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89065
  • No support PMs thanks
Re: False positive
« Reply #1 on: May 23, 2007, 01:47:58 AM »
You could also check the offending/suspect file at: VirusTotal - Multi engine on-line virus scanner I feel virustotal is the better option as it uses the windows version of avast (more packers supported) and there are currently 32 different scanners.
Or Jotti - Multi engine on-line virus scanner if any other scanners here detect them it is less likely to be a false positive. Whichever scanner you use, you can't do this with the file in the chest, you will need to move it out.

If it is indeed a false positive, add it to the exclusions lists (Standard Shield, Customize, Advanced, Add and Program Settings, Exclusions) and Restore it to its original location, periodically check it (scan it in the chest), there should still be a copy in the chest even though you restored it to the original location. When it is no longer detected then you can also remove it from the Standard Shield and Program Settings, exclusions.

Send the sample to virus@avast.com zipped and password protected with password in email body and false positive/undetected malware in the subject. Or you can also add the file to the User Files (File, Add) section of the avast chest where it can do no harm and send it from there (select the file, right click, email to Alwil Software). No need to zip and PW protect when the sample is sent from chest.

Also see False Positives, how to report it to avast! and what to do to exclude them until the problem is corrected.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Theliel

  • Guest
Re: False positive
« Reply #2 on: May 23, 2007, 01:56:47 AM »
ah, thank Davidr, I didn't know send to avast the file.

Anyway, with jotti the only what detect virus are avast, and in Virus total avast and two suspicious (eSafe and Fortinet) so i sure are a false positive :). (prior i woite this post, i was scanned file in both services)

thank for the info

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89065
  • No support PMs thanks
Re: False positive
« Reply #3 on: May 23, 2007, 02:03:38 AM »
Your welcome, yes it most certainly looks like an FP.

Those two multi engine scanners are great for this king of thing (suspect file), I prefer VirusTotal as you probably guessed by my previous post.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security