Author Topic: False Positive  (Read 11163 times)

0 Members and 1 Guest are viewing this topic.

BKKKPewsey

  • Guest
False Positive
« on: December 16, 2009, 04:15:14 PM »
Here we go again!!! Avast showing 2 dll files which are part of epson status monitor has having Win32:malware gen. This after last update (current VPS version 091216-0). Files in question are EBAPI4.DLL & E_FBA6FIE.DLL   ???

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11849
    • AVAST Software
Re: False Positive
« Reply #1 on: December 16, 2009, 04:16:08 PM »
Did you submit these files are false positives?

BKKKPewsey

  • Guest
Re: False Positive
« Reply #2 on: December 16, 2009, 04:21:17 PM »
Not yet just found out in last 5 mins thought I would give u guys heads up first

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89032
  • No support PMs thanks
Re: False Positive
« Reply #3 on: December 16, 2009, 04:25:39 PM »
You could also confirm or deny the detection by checking the offending/suspect file/s at: VirusTotal - Multi engine on-line virus scanner and report the findings here the URL in the Address bar of the VT results page. You can't do this with the file securely in the chest, you need to extract it to a temporary (not original) location first, see below.

Create a folder called Suspect in the C:\ drive, e.g. C:\Suspect. Now exclude that folder in the Standard Shield, Customize, Advanced, Add, type (or copy and paste) C:\Suspect\* That will stop the standard shield scanning any file you put in that folder. You should now be able to export any file in the chest to this folder and upload it to VirusTotal without avast alerting.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

BKKKPewsey

  • Guest
Re: False Positive
« Reply #4 on: December 16, 2009, 04:29:23 PM »
Already checked with virustotal only Avast is flagging alarm after submitting rescan

spg SCOTT

  • Guest
Re: False Positive
« Reply #5 on: December 16, 2009, 04:30:46 PM »
Hmmm...I have 'EBAPI4.DLL' and it scans clean... ??? With VPS 091216-0
(even on VT)

Where is your one located?

BKKKPewsey

  • Guest
Re: False Positive
« Reply #6 on: December 16, 2009, 04:34:54 PM »
C:\Windows\System32\spool\drivers\w32x86\3

BKKKPewsey

  • Guest
Re: False Positive
« Reply #7 on: December 16, 2009, 04:36:55 PM »
Wifes laptop has just received update VPS and showing virus alert too

BKKKPewsey

  • Guest
Re: False Positive
« Reply #8 on: December 16, 2009, 05:11:43 PM »
Further info for u guys file version for EBAP14.dll is V5.15.0.0 Hope that helps (printer only 1 month old)  :)

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11849
    • AVAST Software
Re: False Positive
« Reply #9 on: December 16, 2009, 05:17:20 PM »
To fix the problem, we need that file... so please use the "Report as false positive" link in the virus warning window to submit the file (or, you can pack it into a password-protected archive and send it by e-mail to virus@avast.com, together with the password).
Thanks.

Vicenarian

  • Guest
Re: False Positive
« Reply #10 on: December 16, 2009, 05:39:22 PM »
Yeah I have this problem too...all these files are being flagged as false positives:

Win32:Malware-gen" has been found in

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FBA6FJA.DLL

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EBAPI4.DLL

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EBAPI4.DLL

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EBPBIDI.DLL

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FBA6FIA.DLL

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FBAPFIA.DLL

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FBAPFJA.DL

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FBL6FIA.DLL

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FBL6FJA.DLL




I already sent them in for analysis, but I have no idea what the program version is...as the Epson printer suite contains like 3 different pieces of software...one to manage fax, another to manage network printing, and another to manage some other stuff, but I can say I just bought this printer (an Epson Worforce 610) last week, so it is very new.

I have a theory why this is happening though...When you install this printer, it gives you the option to install either network or usb drivers. Of course, being a wifi printer, I installed and am using the networking drivers. Thus, this might be one reason behind the files being flagged as a trojan (trojan being something that operates over a network)?

Allblack

  • Guest
Re: False Positive
« Reply #11 on: December 16, 2009, 07:13:39 PM »
I have just encountered this problem

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2294
Re: False Positive
« Reply #12 on: December 16, 2009, 08:48:09 PM »
Hello,
thank you for notice. Fixed false positive will be released soon.

Milos

Tony53

  • Guest
Re: False Positive
« Reply #13 on: December 16, 2009, 08:53:25 PM »
Same thing happening here. What has happened to avast! Once is an unfortunate mistake, twice is sheer incompetence.

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2294
Re: False Positive
« Reply #14 on: December 16, 2009, 09:30:31 PM »
Same thing happening here. What has happened to avast! Once is an unfortunate mistake, twice is sheer incompetence.
Hi,
sending the same useless post don't help fix the false positive.

Milos