False Positives.
False Positive - Malware - AntiVirus
I’m a little annoyed really at some of the people I deal with mainly on a daily basis with there arrogance and proval to be right, it’s a shame they can’t work as a team really or even consider someone elses opion,
We had a customer, this customer has a file which is classed as a really dangerous infected file.. Our AV Research Team agree after being sent the file, this is dangerous and will remain detected.. amuzing,
I’ve scanned the file via VirusTotal, and wow.. 17 other AV Vendors agree with them.. 17/40.. that’s not a definiate identification I feel.. but still, I’ve analysed the file myself in my vmware honeypot and via several malware analysis sites and I cannot see why these people feel it’s infected..
I understand that AV Teams share signatures for the best, our internal AV Team use ClamAV and a few others to keep our database uptodate.. however, hen recieveing a file, I don’t know ‘how’ they analysed it.. or if they even bothered, but they determined my analysis of the file to be incorrect and wrong, and thus it should be still detected as a virus, /sigh.
I don’t know why people dont bother to do there job properly, neither do I understand why they don’t believe there own inhouse support team, but thats not really my concern, it’s been a eye opener for myself, I have helped the customer myself and removed this file from her internal database, just a shame it will prob come back.. I even submitted this issue to the one person I consider highest ranked in the Company (that I have access to speak to directly) to be informed it would be looked into.. it wasn’t and is still detected as an infected program.. ah well.
I’ve now sent this file to AVG, Sophos, Prevz, Fortinet, Panda and various others.. Bitdefender have checked the file and said it’s not infected, so has Sunbelt.. who so far have had the best support person,
I am bitterly dissapointed with Kaspersky, I had high hopes for that AV Checker, but after the recent VB100 awards, it’s obvious why they are so lazy at dealing with anything, I got a reply from them informing me they already detect the file and nothing more should be done.. I replied to the email, but several weeks afterwards, they didn’t bother to reply.. how arrogant, I’d love to speak to there Virus Researcher and say ‘hey, do you have a fucking clue what you’re doing in your job? or do you just sit around all day doing fuck all.’ – if the customer is always right, and they viewed me as a customer or a potentional customer, why wasn’t my request taken seriously.. and why did they not even bother to reply to me?
Well, i’ve emailed several companies, and submitted the file to them.. they can analyse it inhouse with there own ‘pro’ AV Teams and make a choice.. infected or not. – we shall see what they come back with..
Here is the current VirusTotal Results.. lets give it a week or so and see how many of them have upheld my request and actually bothered to CHECK the file themselfs.. Oh, and I may add I did email the developer of the file in question, G.D.G Software and spoke to the developer there, he informed me the file is clean too (supprisingly) – the irony behind this is the infection was found when a customer of my company reported it and I took it to analyse and then send to our AV Team.. the dev and various other companies think this is not infected.. I wonder who the last AV Company will be on the VirusTotal list to actually bother checking this file and detecting it as clean.. I have a feeling that as the company I work for was one of the first ones to ‘see’ this file it’s ironic that they will be the last to bother removing it and detecting it as clean..
Ah well, we are not allowed to deal with AV Cases anymore, our highly trained AV Monkeys are to handle them all.. because they know they are right, no matter what.
So much for Team Work.. – I would be bitching directly at our AV Team, but I feel rude telling them they are wrong, and despite submitting the file in the first place and informing them I consider it clean, and providing a full trace of the file and an analysis report, they informed me by writing in these exact terms (including case) ‘this file IS infected and will continue to be detected’ – Thanks Guys, nice to get the feeling you bothered to actually analyse the file.
| File HEViewer.exe received on 2009.10.22 09:14:19 (UTC) | |||
| Antivirus | Version | Last Update | Result |
| a-squared | 4.5.0.41 | 2009.10.22 | Trojan.Win32.Skillis!IK |
| AhnLab-V3 | 5.0.0.2 | 2009.10.22 | - |
| AntiVir | 7.9.1.42 | 2009.10.22 | - |
| Antiy-AVL | 2.0.3.7 | 2009.10.22 | Trojan/Win32.Skillis.gen |
| Authentium | 5.1.2.4 | 2009.10.21 | - |
| Avast | 4.8.1351.0 | 2009.10.21 | - |
| AVG | 8.5.0.420 | 2009.10.21 | - |
| BitDefender | 7.2 | 2009.10.22 | - |
| CAT-QuickHeal | 10.00 | 2009.10.22 | Trojan.Skillis.b |
| ClamAV | 0.94.1 | 2009.10.22 | - |
| Comodo | 2689 | 2009.10.22 | UnclassifiedMalware |
| DrWeb | 5.0.0.12182 | 2009.10.22 | - |
| eSafe | 7.0.17.0 | 2009.10.21 | - |
| eTrust-Vet | 35.1.7079 | 2009.10.22 | - |
| F-Prot | 4.5.1.85 | 2009.10.21 | - |
| F-Secure | 9.0.15300.0 | 2009.10.20 | - |
| Fortinet | 3.120.0.0 | 2009.10.22 | W32/Skillis.B!tr |
| GData | 19 | 2009.10.22 | - |
| Ikarus | T3.1.1.72.0 | 2009.10.22 | Trojan.Win32.Skillis |
| Jiangmin | 11.0.800 | 2009.10.22 | Trojan/Skillis.c |
| K7AntiVirus | 7.10.876 | 2009.10.21 | Trojan.Win32.Skillis.b |
| Kaspersky | 7.0.0.125 | 2009.10.22 | Trojan.Win32.Skillis.b |
| McAfee | 5778 | 2009.10.21 | - |
| McAfee+Artemis | 5778 | 2009.10.21 | - |
| McAfee-GW-Edition | 6.8.5 | 2009.10.22 | - |
| Microsoft | 1.5202 | 2009.10.22 | - |
| NOD32 | 4531 | 2009.10.22 | - |
| Norman | 6.03.02 | 2009.10.21 | - |
| nProtect | 2009.1.8.0 | 2009.10.22 | Trojan/W32.Skillis.564224 |
| Panda | 10.0.2.2 | 2009.10.21 | Suspicious file |
| PCTools | 4.4.2.0 | 2009.10.19 | - |
| Prevx | 3.0 | 2009.10.22 | High Risk Cloaked Malware |
| Rising | 21.52.32.00 | 2009.10.22 | - |
| Sophos | 4.46.0 | 2009.10.22 | Mal/Generic-A |
| Sunbelt | 3.2.1858.2 | 2009.10.22 | - |
| Symantec | 1.4.4.12 | 2009.10.22 | - |
| TheHacker | 6.5.0.2.050 | 2009.10.22 | Trojan/Skillis.b |
| TrendMicro | 8.950.0.1094 | 2009.10.22 | - |
| VBA32 | 3.12.10.11 | 2009.10.22 | Trojan.Win32.Skillis.b |
| ViRobot | 2009.10.22.2001 | 2009.10.22 | - |
| VirusBuster | 4.6.5.0 | 2009.10.21 | Trojan.Skillis.B |
| Additional information | |||
| File size: 564224 bytes | |||
| MD5…: e52082f5e5ed6bf70d9d6932b5b27633 | |||
| SHA1..: 24c54968a7e0507e069809caee5aa0277f864a43 | |||
| SHA256: eeb976718fb68a795a4d4bd2977d9dd5afd8500beaf1ec37ce9cc65caa3d3fa2 | |||
| ssdeep: 12288:9Kr5hQ03jFqTv/JFdEhU8KqUDT5D6G0y1+9lPJM:g7vqTv/JXIdUDT5+G0 vjJM |
|||
| PEiD..: - | |||
| PEInfo: PE Structure information( base data ) entrypointaddress.: 0x1a2001 timedatestamp…..: 0x2a425e19 (Fri Jun 19 22:22:17 1992) machinetype…….: 0x14c (I386)( 10 sections ) |
|||
| RDS…: NSRL Reference Data Set - |
|||
| pdfid.: - | |||
| trid..: Win32 Executable Generic (58.3%) Win16/32 Executable Delphi generic (14.1%) Generic Win/DOS Executable (13.7%) DOS Executable Generic (13.6%) Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%) |
|||
| ThreatExpert info: <a href=’http://www.threatexpert.com/report.aspx?md5=e52082f5e5ed6bf70d9d6932b5b27633′ target=’_blank’>http://www.threatexpert.com/report.aspx?md5=e52082f5e5ed6bf70d9d6932b5b27633</a> | |||
| sigcheck: publisher….: Guillaume Di Giusto copyright….: Copyright (c) 1998-2002 by Guillaume Di Giusto. All rights reserved. product……: HTML Executable description..: HTML Executable Runtime Viewer original name: HEVIEW.EXE internal name: HEVIEW file version.: 1.1.0.1 comments…..: This program is required by HTML publications to run correctly. signers……: - signing date.: - verified…..: Unsigned |
|||
| packers (Antiy-AVL): ASPack 2.12 | |||
| packers (F-Prot): Aspack | |||
| <a href=’http://info.prevx.com/aboutprogramtext.asp?PX5=13CE53B600706B0A9C1208CA459AF6004B5560E5′ target=’_blank’>http://info.prevx.com/aboutprogramtext.asp?PX5=13CE53B600706B0A9C1208CA459AF6004B5560E5</a> | |||
let’s see how long it takes before the VirusTotal list goes down.. and jesus it’s been a lot of work submitting these False Positives to people – some have automated sites, some have email addresses, some want it compressed with a specific password and others just dont care about False Positives.
16 Comments


