Author Topic: False Positive (iroffer-dinoex-3.26-win32-cygwin-1.7.7.7z)  (Read 3191 times)

0 Members and 1 Guest are viewing this topic.

ecarson

  • Guest
False Positive (iroffer-dinoex-3.26-win32-cygwin-1.7.7.7z)
« on: March 19, 2011, 05:25:34 PM »
Not sure why Avast is detecting a Trojan.  Mind looking into this?

Download URL
http://iroffer.dinoex.de/attachments/download/665/iroffer-dinoex-3.26-win32-cygwin-1.7.7.7z

Virus Total Reputation
http://www.virustotal.com/file-scan/report.html?id=77873948e6ab5d3e3535c5237f57804828157a9b1a00328d76c42cd188a8aab5-1300550085
Result: 4 /43 (9.3%)
Two of those results are Avast.

No idea how to copy the popup information, my apologies.


doktornotor

  • Guest
Re: False Positive (iroffer-dinoex-3.26-win32-cygwin-1.7.7.7z)
« Reply #1 on: March 19, 2011, 05:27:22 PM »
Please sumbit as false positive (Report false virus alert on website).

http://www.avast.com/contact-form.php?loadStyles

ecarson

  • Guest
Re: False Positive (iroffer-dinoex-3.26-win32-cygwin-1.7.7.7z)
« Reply #2 on: March 19, 2011, 05:34:55 PM »
Completed.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: False Positive (iroffer-dinoex-3.26-win32-cygwin-1.7.7.7z)
« Reply #3 on: March 19, 2011, 05:41:26 PM »
Yes, could well be a False Positive: http://wepawet.iseclab.org/view.php?hash=fb7a68ae76670a77803f7902660e3c22&t=1300552294&type=js
because they even warn about this being flagged by av on their website:
Quote
Iroffer is not a virus, trojan or backdoor. It is a file server like FTP.
If you don't have installed this software yourself, but a scanner reports it on your harddisk, Iroffer has been installed by a malware after successful compromising your computer.
quote source link: http://webcache.googleusercontent.com/search?q=cache:SO7Qkv_Edi0J:iroffer.dinoex.de/wiki/1/export/special+malware+domain+iroffer.dinoex.de&cd=1&hl=nl&ct=clnk&gl=nl&source=www.google.nl

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!