Author Topic: Alot of False Positives  (Read 4320 times)

0 Members and 1 Guest are viewing this topic.

Offline Justin_22

  • Avast Evangelist
  • Poster
  • ***
  • Posts: 445
  • Free your soul and let it fly
Alot of False Positives
« on: December 03, 2008, 09:39:29 PM »
Virustotal results for SmitfraudFix.exe

AhnLab-V3    -    -    -
AntiVir    -    -    DR/Tool.Reboot.F.162
Authentium    -    -    W32/Backdoor2.DAHB
Avast    -    -    -
AVG    -    -    -
BitDefender    -    -    -
CAT-QuickHeal    -    -    -
ClamAV    -    -    Trojan.Killproc-1
DrWeb    -    -    Tool.Prockill
eSafe    -    -    Suspicious File
eTrust-Vet    -    -    -
Ewido    -    -    -
F-Prot    -    -    W32/Backdoor2.DAHB
F-Secure    -    -    Rogue:W32/IeDefender.CT
Fortinet    -    -    Misc/PrcViewer
GData    -    -    -
Ikarus    -    -    -
K7AntiVirus    -    -    -
Kaspersky    -    -    not-a-virus:RiskTool.Win32.Reboot.f
McAfee    -    -    potentially unwanted program PrcViewer
Microsoft    -    -    -
NOD32    -    -    Win32/PrcView
Norman    -    -    -
Panda    -    -    Adware/MalwareAlarm
PCTools    -    -    -
Prevx1    -    -    -
Rising    -    -    -
SecureWeb-Gateway    -    -    Trojan.Dropper.Tool.Reboot.F.162
Sophos    -    -    -
Sunbelt    -    -    Trojan.FakeAlert
Symantec    -    -    -
TheHacker    -    -    -
TrendMicro    -    -    PAK_Generic.001
VBA32    -    -    BackDoor.IRC.Chazz.38
ViRobot    -    -    Not_a_virus:RiskTool.Reboot.1478876
VirusBuster    -    -    -

   ::)
Avast!  2014 beta - Sandboxie - K9 Web Protection

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89033
  • No support PMs thanks
Re: Alot of False Positives
« Reply #1 on: December 03, 2008, 09:49:37 PM »
Colour me confused, but what has this got to do with avast as it doesn't report this acording to your VT results, so not an avast false positive ?

Your title is misleading in that I though you are saying avast (since you post it in the avast forums) has a lot of false positives, rather than something a little clearer, e.g. smitfraud.exe detected by many AVs as infected. But even that still casts guilt if you don't add (but not by avast).

But it isn't uncommon for a tool to be tarred with the same brush as to what it is hoping to detect or detecting some of the tools it uses to detect or eliminate the problem.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Alot of False Positives
« Reply #2 on: December 03, 2008, 11:08:49 PM »
Wow... it's a common cleaning tool and it's being detected as infected...
Just to be sure, maybe testing the MD5 of the file.
The best things in life are free.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89033
  • No support PMs thanks
Re: Alot of False Positives
« Reply #3 on: December 03, 2008, 11:22:54 PM »
As I said not unusual for tools to get pinged because of what they do/contain to remove infection.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Alot of False Positives
« Reply #4 on: December 03, 2008, 11:44:06 PM »
Hi DavidR,

Well it is quite common that some of these tools running to cleanse malware, are detected by scanners because they have similar characteristics as malware, and in the hands of the unscrupulous could be used maliciously, therefore they are flagged as "riskware".
So to say these are simple FP's is too simply put and out of perspective. This is the so-called grey area. In mentioned case as it is used for deleting malware, the scanners have to exclude it. But who decide between the way these executables are used?

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89033
  • No support PMs thanks
Re: Alot of False Positives
« Reply #5 on: December 04, 2008, 12:45:37 AM »
I'm not the one calling them false positives, just that avast isn't calling it anything but the topic title makes it look like avast has a lot of false positives.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

samuelvirucide

  • Guest
Re: Alot of False Positives
« Reply #6 on: December 04, 2008, 01:37:52 AM »
 ;D Hi Justin XP
    what is your reason why you put smitfraudfix.exe in virus total scanner?Are you testing its reliability?
THanks ;D

   

Offline Justin_22

  • Avast Evangelist
  • Poster
  • ***
  • Posts: 445
  • Free your soul and let it fly
Re: Alot of False Positives
« Reply #7 on: December 04, 2008, 03:16:39 AM »
DavidR I wasnt saying that Avast! has a lot of False Positives, I should have made the name of the topic clarify what the post contained more. And SamuelVirucide I uploaded SmitfraudFix.exe to virustotal because it was flagged by Kaspersky online scanner 7 as a "HackTool" and was interested to see how many scanners flagged it as malware.

-Justin
Avast!  2014 beta - Sandboxie - K9 Web Protection