Results 1 to 6 of 6

Thread: Checking if False Positive

Hybrid View

  1. #1
    Rex's Mom Guest

    Checking if False Positive

    while running aČ, Avast lept up with a warning about a
    program in the AČ Archive folder. Then while running Avast,
    it (Avast) complained about something in aČ.

    should one investigate (and what's the best way to do that?)
    or should one just accept 'their' word for it and quarantine?
    --

    Rex's Mom




  2. #2
    David H. Lipman Guest

    Re: Checking if False Positive

    From: "Rex's Mom" <labsrgreat@invalid.com>

    | while running aČ, Avast lept up with a warning about a
    | program in the AČ Archive folder. Then while running Avast,
    | it (Avast) complained about something in aČ.
    |
    | should one investigate (and what's the best way to do that?)
    | or should one just accept 'their' word for it and quarantine?

    Quarantines *should* be encrypted to avoid other anti malware utilities from flagging what
    is found within the respective vendor's quarantine. However, this isn't always the case.

    If you are unsure if a file has been unjustly quarantined, submit a sample to a given
    qurantined item to Virus Total. If it is well recognized, purge that quarantined item from
    the cache/folder. If it is NOT well recognized, wait several days, a week or more and
    resubmit it. If it remains not well recognized or unrecognized then it may be a False
    Positive and you should contact the anti malware vendor of the software which quarantined
    the suspect. If it is a False Positive, it can the be restored from quarantine.


    Please submit a sample to Virus Total --
    http://www.virustotal.com/flash/index_en.html
    The submission will then be tested against many different AV vendor's scanners.
    That will give you an idea what it is and who recognizes it. In addition, unless told
    otherwise, Virus Total will provide the sample to all participating vendors.

    You can also submit a suspect, one at a time, via the following email URL...
    mailto:scan@virustotal.com?subject=SCAN

    When you get the report, please post back the exact results.

    --
    Dave
    http://www.claymania.com/removal-trojan-adware.html
    http://www.ik-cs.com/got-a-virus.htm



  3. #3
    Rex's Mom Guest

    Re: Checking if False Positive

    David H. Lipman wrote:

    > From: "Rex's Mom" <labsrgreat@invalid.com>
    >
    > | while running aČ, Avast lept up with a warning about a
    > | program in the AČ Archive folder. Then while running Avast,
    > | it (Avast) complained about something in aČ.
    > |
    > | should one investigate (and what's the best way to do that?)
    > | or should one just accept 'their' word for it and quarantine?
    >
    > Quarantines *should* be encrypted to avoid other anti malware utilities from flagging what
    > is found within the respective vendor's quarantine. However, this isn't always the case.
    >
    > If you are unsure if a file has been unjustly quarantined, submit a sample to a given
    > qurantined item to Virus Total. If it is well recognized, purge that quarantined item from
    > the cache/folder. If it is NOT well recognized, wait several days, a week or more and
    > resubmit it. If it remains not well recognized or unrecognized then it may be a False
    > Positive and you should contact the anti malware vendor of the software which quarantined
    > the suspect. If it is a False Positive, it can the be restored from quarantine.
    >
    >
    > Please submit a sample to Virus Total --
    > http://www.virustotal.com/flash/index_en.html
    > The submission will then be tested against many different AV vendor's scanners.
    > That will give you an idea what it is and who recognizes it. In addition, unless told
    > otherwise, Virus Total will provide the sample to all participating vendors.
    >
    > You can also submit a suspect, one at a time, via the following email URL...
    > mailto:scan@virustotal.com?subject=SCAN
    >
    > When you get the report, please post back the exact results.
    >

    thank you...will get on it in the next day or so and post back

    --

    Rex's Mom




Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •