Author Topic: [Solved] False positives reported but not corrected  (Read 14050 times)

0 Members and 1 Guest are viewing this topic.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
« Last Edit: May 23, 2011, 02:13:17 PM by Tech »
The best things in life are free.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: False positives reported but not corrected
« Reply #2 on: May 21, 2011, 02:58:18 AM »
The best things in life are free.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: False positives reported but not corrected
« Reply #3 on: May 21, 2011, 09:54:38 PM »
Still being detected with 110521-1 :'(
The best things in life are free.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: False positives reported but not corrected
« Reply #4 on: May 21, 2011, 10:08:46 PM »
Thanks Polonus, but what do you think? False positives or not?

I think these dedections are FPs.
Where did you report them..??
Here..?? http://www.avast.com/contact-form.php?loadStyles
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: False positives reported but not corrected
« Reply #5 on: May 21, 2011, 11:11:39 PM »
Where did you report them..??
From Chest.
They always said that these files, reported from Chest, have high priority.

Here..?? http://www.avast.com/contact-form.php?loadStyles
No.
Did not lose time to that... and won't.
Why don't they correct the false positive?  >:(
The best things in life are free.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: False positives reported but not corrected
« Reply #6 on: May 21, 2011, 11:18:26 PM »
Hi Tech,

If a scan at VT or VirScan only turns out to be flagged by avast and not by GData as well, then here I could smell  a FP,
and things that smell like a duck, sound like a duck and walk and swim like a duck in most cases turn out to be a genuine duck,

polonus

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: False positives reported but not corrected
« Reply #7 on: May 21, 2011, 11:21:02 PM »
Thanks Polonus.
What more can I do? :'(

Do you have similar files .etl in your computer?
Are they being flagged?
The best things in life are free.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: False positives reported but not corrected
« Reply #8 on: May 22, 2011, 12:30:31 AM »
Hi Tech,

This issue is one year old: http://forum.avast.com/index.php?topic=60305.0

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline calcu007

  • Avast Evangelist
  • Poster
  • ***
  • Posts: 482
  • I'm lamma!
Re: False positives reported but not corrected
« Reply #9 on: May 22, 2011, 05:53:07 AM »
Try using virus@avast.com  Maybe you will get a reply. Try posting in Avast subforum, that is more read than this
« Last Edit: May 22, 2011, 06:02:26 AM by calcu007 »
Asus Intel i7 8GB RAM , Win 8.1 64 bit, Avast IS

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: False positives reported but not corrected
« Reply #10 on: May 22, 2011, 07:22:29 PM »
Try using virus@avast.com
They always advocate the opposite for false positives.

Maybe you will get a reply. Try posting in Avast subforum, that is more read than this
Well, false positives were always posted here.

The problem is that they do not say anything about...
Why does this happen to me?

The false positive continues... 110522-1
The best things in life are free.

Offline calcu007

  • Avast Evangelist
  • Poster
  • ***
  • Posts: 482
  • I'm lamma!
Re: False positives reported but not corrected
« Reply #11 on: May 22, 2011, 08:41:38 PM »
I had send false positive there and had personal replies and in the forum. You will not lose if try both
Asus Intel i7 8GB RAM , Win 8.1 64 bit, Avast IS

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11849
    • AVAST Software
Re: False positives reported but not corrected
« Reply #12 on: May 22, 2011, 08:48:57 PM »
I don't think that's a real false positive - the detection has been for more than a year, and it looks OK to me.
I'd say something (other product's virus signatures from memory?) somehow got into these files. Though I admit I have no idea what those .etl files are.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: False positives reported but not corrected
« Reply #13 on: May 22, 2011, 09:06:10 PM »
I don't think that's a real false positive - the detection has been for more than a year, and it looks OK to me.

It does..??
Did you look at the VT results in Tech's original post..?
I think we need a reply from the viruslab guys here..!! ;)
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: False positives reported but not corrected
« Reply #14 on: May 22, 2011, 09:06:59 PM »
Igor, we need a virus analyst's answer.
I can imagine that "other product's virus signatures from memory" can be the issue.
First detection was after a KillSwitch being running. See snapshot.

The detection occur with the files into Chest. The files must be "corrupted" then. How?

I'm about to delete that files...
Event Trace Log (ETL) files are binary files created by Microsoft Tracelog, a program that creates logs using the events from the kernel in Microsoft operating systems; contains binary log data at the trace level, such as disk accesses or page faults; used to log high-frequency events while tracking the performance of an operating system.
http://www.fileinfo.com/extension/etl

These files could be converted to text files: http://msdn.microsoft.com/en-us/library/bb801253%28v=office.12%29.aspx
The best things in life are free.