Author Topic: avast! static analysis and Reaper DAW  (Read 3557 times)

0 Members and 1 Guest are viewing this topic.

screaminbug

  • Guest
avast! static analysis and Reaper DAW
« on: May 26, 2012, 11:14:47 AM »
Hello everyone,

I am using the latest version of avast! Free and when I run Reaper installation file reaper422_x64-install.exe downloaded from www . reaper . fm/download . php, avast windows pops up saying that "Static analysis finds the file suspicious" and suggests that I run in in sandbox. Now, I am pretty sure that there isn't any malware in there, but I'm curious, what does "static analysis" mean and why avast finds that file to be suspicious? It also says: "We did not find enough evidence to identify the file as malware. However you should still use extreme caution when accessing it".

Thank you!
« Last Edit: May 26, 2012, 12:21:15 PM by screaminbug »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: avast! static analysis and Reaper DAW
« Reply #1 on: May 26, 2012, 11:46:33 AM »
Quote
and suggests that I run in in sandbox. Now, I am pretty sure that there isn't any malware in there, but I'm curious,
then select.....run normal....and remeber my answer

upload suspicious file(s) to www.virustotal.com and test with 40+ malware scanners (if tested before, click rescan)
when you have the result, copy the URL in the address bar and post it here for us to see

alternative
Jotti http://virusscan.jotti.org/en
Metascan http://www.metascan-online.com/
VirSCAN http://virscan.org/

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: avast! static analysis and Reaper DAW
« Reply #2 on: May 26, 2012, 11:48:26 AM »
Quote
what does "static analysis" mean
http://en.wikipedia.org/wiki/Static_program_analysis

Offline AntiVirusASeT

  • Poster
  • *
  • Posts: 462
Re: avast! static analysis and Reaper DAW
« Reply #3 on: May 26, 2012, 12:04:17 PM »
i suggest that u keep the program sandboxed until someone more experienced checks out the webpage u provided.

meanwhile please change 'http' to 'hxxp' to remove link to that webpage just in case it is malicious.

i shall give some inputs though

1. scans on webpage by webutation, zscaler, sucuri, url void all come up clean.

2. reaper digital audio workstation seems legit...downloads are available at Cnet: http://download.cnet.com/Reaper-64-bit/3000-2170_4-75156560.html?tag=main;dropDownForm


screaminbug

  • Guest
Re: avast! static analysis and Reaper DAW
« Reply #4 on: May 26, 2012, 12:20:22 PM »
Thanks for your answers. I've already installed the software, and that's not an issue because I've used it before without any issues or problems and because many people use Reaper for home audio and music production as it's a well known digital audio workstation. The reason for my post was mainly to deduce what was the real reason for the warning I got. And BTW, none of the antivirus programs from virustotal found anything suspicious (including avast :)).

One entry I found in the avast! blog about static analysis explains:
Static analysis finds the file suspicious
Static analyses checks file content and looks for suspicious strings in file headers similar in virus definitions. Main static analysis reasons are:
Application is not signed
Use of executable file encryption/compression
The file prevalence/reputation is low
All new unknown files are potentially dangerous. Whenever they have become widespread, there will not be a reason to AutoSandbox them anymore.
The file origin/source is suspicious
The file is executed from a remote/removable media


I'm just curious to know how can I find out what the exact reason for warning was (i can rule out the last one).

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: avast! static analysis and Reaper DAW
« Reply #5 on: May 26, 2012, 12:29:38 PM »
some of that info.....or missing info... you find if you scroll down to the bottom of the Virustotal report and click "Additional information"

screaminbug

  • Guest
Re: avast! static analysis and Reaper DAW
« Reply #6 on: May 26, 2012, 01:14:34 PM »
Thanks, it makes sense now. Symantec flags it as Suspicious.Insight. So I'm guessing the reason for warning I've got is reputation, which is understandable, as it has relatively small user base and therefore a low adoption rate so it's in the "unproven" state in various reputation-based systems. It would be nice that avast gave some more info about that kind of stuff.