Author Topic: false positive  (Read 3136 times)

0 Members and 1 Guest are viewing this topic.

smfd

  • Guest
false positive
« on: July 31, 2011, 05:41:06 PM »
Hello forum, i have a problem

I work in a internet service provider. We use authorisation program to authorise users on our server. Today many people who use avast phoned me and said they can't work in the internet cos authorisation program was detected as malware and deleted by the antivirus

Please help me to solve this problem

The program can be downloaded here http://www.elite-net.org/auth.exe

Thank you!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89159
  • No support PMs thanks
Re: false positive
« Reply #1 on: July 31, 2011, 05:58:39 PM »
Avast isn't alone in finding it suspect, http://www.virustotal.com/file-scan/report.html?id=0fc7fc461697c6f57ca784904d49533b54d7aeba07544d98e778a19240686d04-1312124288.

However the Win32:Malware-gen is a generic signature (the -gen bit) and more prone to misdetection, since most of the VT detections are also generic, suspicious/heuristic it should be analysed.

There is an on-line contact form, http://www.avast.com/contact-form.php?loadStyles for:  * Sales inquiries; Technical issues; Website issues; Report false virus alert in file; Report false virus alert on website; Press (Media), issues.
- If you are reporting an FP, then you get another input field open, click Browse button and navigate to the file or enter the web URL for the site you wish to submit for review, etc.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

smfd

  • Guest
Re: false positive
« Reply #2 on: July 31, 2011, 07:50:49 PM »
Several days ago avira also detected this program as virus (i also contacted them) and I've sent it to virustotal - the result was 12/43. But virustotal also said that that file was already scanned and the result is 4/43.

Thank you for the link - sent the file via contact form.
« Last Edit: July 31, 2011, 07:53:59 PM by smfd »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37552
  • Not a avast user
Re: false positive
« Reply #3 on: July 31, 2011, 08:06:53 PM »
SOPHOS lab
Quote
SophosLabs has analyzed the submitted file(s) and have determined it is a false positive detection.

auth.exe -- identity created/updated


Avira lab
Quote
The file 'auth.exe' has been determined to be 'FALSE POSITIVE'.In particular this means that this file is not malicious but a false alarm.Detection will be added to our virus definition file (VDF) with one of the next updates.Detection will be removed from our virus definition file (VDF) with one of the next updates.


« Last Edit: August 01, 2011, 11:43:47 AM by Pondus »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89159
  • No support PMs thanks
Re: false positive
« Reply #4 on: July 31, 2011, 08:44:35 PM »
Several days ago avira also detected this program as virus (i also contacted them) and I've sent it to virustotal - the result was 12/43. But virustotal also said that that file was already scanned and the result is 4/43.

Thank you for the link - sent the file via contact form.

You're welcome, hopefully it will be quickly analysed and the detection corrected.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33923
  • malware fighter
Re: false positive
« Reply #5 on: August 01, 2011, 01:33:55 AM »
Hi DavidR,

I have run the executable in question through Anubis. Here are the results of the Analysis Report:
http://anubis.iseclab.org/?action=result&task_id=180a4941b8eae2d441d260896425ad586&format=html
There it is being classified as a (medium risk) download and low risk risktool, so could be classified as a PUP, but as users know what it is meant to do and have installed it themselves intentionally, then it should be OK.
The generic flag could be because of the \​NameSpace_Catalog5 Winsock2 monitoring key settings and or similar key settings for  \Protocol_Catalog9 but these have to do with the network settings by the program.
Device Control Communications Control Code is also found in certain Trojan-Spy variants.
The mutex, _SHuassist.mtx, is also found with certain risktools.
I.M.O. more than likely a False Positive,

polonus
« Last Edit: August 01, 2011, 01:35:45 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!