Author Topic: False positive : JS:Pdfka-gen [Expl]  (Read 13276 times)

0 Members and 1 Guest are viewing this topic.

Offline mrapi

  • Full Member
  • ***
  • Posts: 137
False positive : JS:Pdfka-gen [Expl]
« on: January 16, 2012, 05:44:45 PM »
Hi,please reanalyze the file attached,Avira Lab report for it shows that is clean,but Avast detect it as JS:Pdfka-gen [Expl]

https://www.virustotal.com/file/05128fb49caaeb3a49f19d1c674239395f42403257e741dc55d9bcbad545c2e1/analysis/1326731619/

Avira Lab report:
Dear Sir or Madam,

Thank you for your email to Avira's virus lab.
Tracking number: INC00947588.

We received the following archive files:
File ID    Filename    Size (Byte)    Result
26496057    S1001_nr2_121211.zip    146.37 KB    OK

A listing of files contained inside archives alongside their results can be found below:
File ID    Filename    Size (Byte)    Result
26496058    S1001_nr2_121211.pdf    156.62 KB    CLEAN


Please find a detailed report concerning each individual sample below:
Filename    Result
S1001_nr2_121211.pdf    CLEAN

Thanks!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33905
  • malware fighter
Re: False positive : JS:Pdfka-gen [Expl]
« Reply #1 on: January 16, 2012, 06:26:49 PM »
Maybe you already were infected by this malware, but did not have the Adobe file installed for it yet to wake up the malcode for it to become active. It is a detection for exploit code, in order for the exploit to work it has to be able to exploit a vulnerability in your PDF reader. First trick is that it tries to have you open it, and apparently you did.
Maybe you have to wait for essexboy here to have a look. It could well that some adware brought this malware along. Well wait for him to have a look. With 6 on VT alerting this it sure is no FP,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: False positive : JS:Pdfka-gen [Expl]
« Reply #2 on: January 16, 2012, 06:30:10 PM »
Posting a VT scan wont help unless you also send the file to avast lab.....


« Last Edit: January 16, 2012, 06:32:41 PM by Pondus »

Offline mrapi

  • Full Member
  • ***
  • Posts: 137
Re: False positive : JS:Pdfka-gen [Expl]
« Reply #3 on: January 16, 2012, 06:44:07 PM »
Sample file sent with topic link.

Thanks !

Offline mrapi

  • Full Member
  • ***
  • Posts: 137
Re: False positive : JS:Pdfka-gen [Expl]
« Reply #4 on: January 16, 2012, 08:03:34 PM »
Hi Pondus,you sent me a personal message but I'm not allowed  to reply to you,
I got : An Error Has Occurred! You are not allowed to send personal messages.

So I answered mailing again to virus@... (link topic in subject)
Thanks

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33905
  • malware fighter
Re: False positive : JS:Pdfka-gen [Expl]
« Reply #5 on: January 17, 2012, 01:04:50 AM »
Hi mrapi,

Welcome to the forums. Stay with us and when you have reached 20 postings the PM function will be available to you also. Stay safe and secure,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline mrapi

  • Full Member
  • ***
  • Posts: 137
Re: False positive : JS:Pdfka-gen [Expl]
« Reply #6 on: January 17, 2012, 06:20:51 AM »
k,thanks for clarifications,file sent to Pondus mailbox

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: False positive : JS:Pdfka-gen [Expl]
« Reply #7 on: January 17, 2012, 12:43:00 PM »
Sophos lab

Quote
SophosLabs has analyzed the submitted file(s) and determined they are not malicious and can safely be authorized.

S1001_nr2_121211.pdf -- can be authorised


Norman lab
Quote
S1001_nr2_121211.pdf : Clean!
« Last Edit: January 17, 2012, 05:29:44 PM by Pondus »

Offline mrapi

  • Full Member
  • ***
  • Posts: 137
Re: False positive : JS:Pdfka-gen [Expl]
« Reply #8 on: January 17, 2012, 01:04:42 PM »
What about Avast lab?
Sophos lab

Quote
SophosLabs has analyzed the submitted file(s) and determined they are not malicious and can safely be authorized.

S1001_nr2_121211.pdf -- can be authorised

Offline Sirmer

  • Avast team
  • Sr. Member
  • *
  • Posts: 324
Re: False positive : JS:Pdfka-gen [Expl]
« Reply #9 on: January 17, 2012, 06:49:42 PM »
Hello,
it will be fixed in next VPS.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: False positive : JS:Pdfka-gen [Expl]
« Reply #10 on: January 17, 2012, 06:52:51 PM »
So was it my upload that did it....or     ;D


EDIT: guess it was....just got the mail   ;)

Offline mrapi

  • Full Member
  • ***
  • Posts: 137
Re: False positive : JS:Pdfka-gen [Expl]
« Reply #11 on: January 17, 2012, 08:46:39 PM »
Hello,good news,thanks !
Hello,
it will be fixed in next VPS.

Offline mrapi

  • Full Member
  • ***
  • Posts: 137
Re: False positive : JS:Pdfka-gen [Expl]
« Reply #12 on: January 18, 2012, 10:10:03 AM »
Fixed after today update !
Thanks!