Announcement

Collapse
No announcement yet.

How to report False Positive to us?

Collapse
This topic is closed.
X
This is a sticky topic.
X
X
  • Filter
  • Time
  • Show
Clear All
new posts

  • How to report False Positive to us?

    Hello Everyone,

    Before reporting false positives, please read the following guidelines and requirements, and provide us with the requested information as below:

    1) Save a scan log first and post it here.
    Please use the latest version of IObit Malware Fighter to run a scan. This will help us know the detailed information of the scan result.

    Scan Log Example:

    IObit Malware Fighter

    OS: Windows 8
    Version: 2.4.1.15
    Define Version: 1383
    Time Elapsed: 00:19:53
    Objects Scanned: 66821
    Threats Found: 1
    Save Time: 20/10/2014 13:54:27

    |Name|Type|Description|ID|
    Trojan.Generic, FILE, C:\Program Files\tixati\errorreporter.exe, 4123518

    2) Upload and scan the reported file (take errorreporter.exe for an example) mentioned in the scan log to Virus Total and give us the report link.

    How to upload and scan a file at VirusTotal

    Go to Virus Total
    • Click Choose File
    • On the left of the window that opens click My Computer
    • Open (C:)
    • Find the reported file according to the full path in the scan log
    • Double click the file name, and it will disappear in the VirusTotal box.
    • Click Scan it! and wait (you may be in a queue)
    • When the scan has finished, copy the address from the address bar to post here.

    3) Zip the reported file (take errorreporter.exe for an example) with password "infected", update it to Wikisend, and give us the download link.
    Our specialists are unable to make a conclusive analysis without a sample.

    Our IObit Specialist Team will do further investigation and reply to you with a result ASAP.

    Thank you.
    IObit Development Team

  • #2
    False positive 1

    Hello,

    IObit Security 360

    OS:Windows Vista
    Version:0.1.0.31
    Time:9/06/2009 17:01:00

    |Name|Type|Description|
    Misleading.SystemSecurity, File, C:\Users\gebruikers pc\Desktop\System Security Expert 2.9.appref-ms


    - its a shortcut -

    A False Positive on my own program.
    "System Security Expert 2009" -Shortcut-

    softpedia.com/get/System/Launchers-Shutdown-Tools/SYSBoost.shtml

    Comment


    • #3
      IObit Security 360

      OS:Windows XP
      Version:0.1.0.31
      Time:6/9/2009 10:46:43 AM

      |Name|Type|Description|
      Tracking Cookies, Cookies, Cookie:compaq_owner@ad.yieldmanager.com/
      Trojan.Downloader, File, C:\Program Files\Motorola Phone Tools\MPT_TEST_Info.exe


      The motorola phone sync-software-ha-ha please don't take this I won't know which way to go

      Comment


      • #4
        Registryeasy Software ???????

        Hello ,, IObit Security 360 is telling me that my REGISTRYEASY SOFTWARE is a Virus or Spyware .

        Please download at http://www.registryeasy.com/

        version 5.1

        Serial # ---->> 6021-8BFC-5TUD-VOJ0

        I hope you will download and run that software and then send me EMAIL ASAP to tell me if there are Bugs or Spam or something inside that Registry Checker software Because it is the one that I use the most to check and fix all my Registry problems .


        Regards
        Bill davis

        davis287@yahoo.com

        Comment


        • #5
          Hello,

          Using Windows 7 32bit, I know it may not be supported but I thought you may want to know what IObit found on my system. File was scanned at Virus Total and Jotti and no other scanner found anything suspicious.

          IObit Security 360

          OS:Windows 7
          Version:0.1.0.31
          Time:15/06/2009 9:10:29 PM

          |Name|Type|Description|
          Trojan.Agent, File, C:\Windows\system32\Winrpc32.dll

          p.s. I have Nod32 v4 and PrevX and they don't detect anything either.
          - -
          Michael...

          Comment


          • #6
            Originally posted by davis287 View Post
            Hello ,, IObit Security 360 is telling me that my REGISTRYEASY SOFTWARE is a Virus or Spyware .

            Please download at http://www.registryeasy.com/

            version 5.1

            Serial # ---->> 6021-8BFC-5TUD-VOJ0

            I hope you will download and run that software and then send me EMAIL ASAP to tell me if there are Bugs or Spam or something inside that Registry Checker software Because it is the one that I use the most to check and fix all my Registry problems .


            Regards
            Bill davis

            davis287@yahoo.com


            Please check my thread http://forums.iobit.com/showthread.p...7826#post17826
            IObit Development Team

            Comment


            • #7
              Is reporting possible FP over Send Feedback enough?

              Anyway:

              WXP SP 3

              Scan says this is a Trojan Agent - Smart Scan 10 min ago.

              C:\WinXP.Activation.v1.1.Swedish.exe

              If this is a FP - how long does it take before there is an update available that takes care of the FP?

              Best Regards
              Defensewall - Antivir - IObit 360 - Roboform
              Win Xp SP3, IE6

              Comment


              • #8
                Registry Fix 7.1 is a false positive!!!

                Originally posted by Tim Xue View Post
                Before reporting a false positive, please save a scan report first and post it here. This will help us know the detailed information about the scan result.
                I have previously reported this to you as feedback but received nothing helpful in response. The following is the last scan report from IObit 360:

                IObit Security 360

                OS:Windows XP
                Version:0.1.1.8
                Time:6/26/2009 12:35:49 PM

                |Name|Type|Description|
                Rogue.RegistryFix, File, C:\Program Files\RegistryFix7\logs\26-6-2009 (12-13-56).txt
                Rogue.RegistryFix, File, C:\Program Files\RegistryFix7\logs\26-6-2009 (12-16-17).txt
                Rogue.RegistryFix, File, C:\Program Files\RegistryFix7\logs\26-6-2009 (9-58-55).txt
                Rogue.RegistryFix, File, C:\Program Files\RegistryFix7\RegistryFix7Backup\6,26,2009_10,9,11.cab

                I have contacted the folks at Registry Fix and they have said that they have attempted to contact you about this issue. They have assured me that their program contains no malware. I have tested for it with other prominent detection tools and yours is the only one that shows Registry Fix 7.1 to be rouge-ware. Please consider removing Registry Fix 7.1 from your list of malware. Otherwise, explain your rationale and justify why you categorized it as such. Thanks.

                CAS

                Comment


                • #9
                  I believe it is a Rogue program. I went to download it and Avira stopped me saying its a Trojan, it said this, TR/Fake.RegFix. And if Avira says it I believe it. And of course a person that puts a product out will say its clean to sell it.

                  Comment


                  • #10
                    The Other Possibility

                    Avira and 360 may have tagged based on it's behavior-you know,if it walks like a duck and talks like a duck...
                    Great day and God bless horsepower & Mark Martin

                    Comment


                    • #11
                      Originally posted by cstortion View Post
                      I have previously reported this to you as feedback but received nothing helpful in response. The following is the last scan report from IObit 360:

                      IObit Security 360

                      OS:Windows XP
                      Version:0.1.1.8
                      Time:6/26/2009 12:35:49 PM

                      |Name|Type|Description|
                      Rogue.RegistryFix, File, C:\Program Files\RegistryFix7\logs\26-6-2009 (12-13-56).txt
                      Rogue.RegistryFix, File, C:\Program Files\RegistryFix7\logs\26-6-2009 (12-16-17).txt
                      Rogue.RegistryFix, File, C:\Program Files\RegistryFix7\logs\26-6-2009 (9-58-55).txt
                      Rogue.RegistryFix, File, C:\Program Files\RegistryFix7\RegistryFix7Backup\6,26,2009_10,9,11.cab

                      I have contacted the folks at Registry Fix and they have said that they have attempted to contact you about this issue. They have assured me that their program contains no malware. I have tested for it with other prominent detection tools and yours is the only one that shows Registry Fix 7.1 to be rouge-ware. Please consider removing Registry Fix 7.1 from your list of malware. Otherwise, explain your rationale and justify why you categorized it as such. Thanks.

                      CAS
                      This is a correct detection and is a rogue program. Remove immediately :neutral:
                      [COLOR="Red"]Malware and Security Wizard:twisted:[/COLOR]
                      [B][color=#e60a1b]N[/color][color=#ca1335]e[/color][color=#ae1b4f]w[/color] [color=#762c83]T[/color][color=#5a359c]h[/color][color=#3e3db6]r[/color][color=#2246d0]e[/color][color=#064eea]a[/color][color=#2246d0]t[/color] [color=#5a359c]C[/color][color=#762c83]o[/color][color=#922469]u[/color][color=#ae1b4f]n[/color][color=#ca1335]t[/color][/B] = [COLOR="Red"][B]~28,000! (not including variants)[/B][/COLOR] 8)

                      Comment


                      • #12
                        Bfd....

                        Originally posted by Mongoose View Post
                        I believe it is a Rogue program. I went to download it and Avira stopped me saying its a Trojan, it said this, TR/Fake.RegFix. And if Avira says it I believe it. And of course a person that puts a product out will say its clean to sell it.
                        Interestingly, Avast allows it without any problem! So does Windows Defender, AdAware, and SpyBot.

                        Comment


                        • #13
                          Originally posted by cstortion View Post
                          Interestingly, Avast allows it without any problem! So does Windows Defender, AdAware, and SpyBot.
                          Well Avast isn't to bad but cant detect as well as Avira. As for the others I wouldn't bother with them. I can say that I got an email just the other day where Avira got some big award for 100% detection rating. Spybot is ok but I perfer MalwareBytes over it. My main programs I use are Avira Free, MalwareBytes, and SuperAntiSpyware. I have been checking out IObit Security 360 lately and it could take the place of MalwareBytes, thats how good it seems.
                          Last edited by Mongoose; Jun. 27th, 2009, 03:15.

                          Comment


                          • #14
                            False positive reported on uninstaller package from Indigo Rose Corporation

                            Here's the Report:

                            IObit Security 360

                            OS:Windows XP
                            Version:0.1.1.8
                            Time:6/26/2009 11:21:07 PM

                            |Name|Type|Description|
                            Unwanted.SpywareVanisher, File, C:\WINDOWS\iun6002.exe

                            I looked around and found several sites that say this program should be ok, including a forum thread on Indigo Rose's site itself.

                            Here are a couple links:

                            http://www.file.net/process/iun6002.exe.html

                            http://www.indigorose.com/forums/showthread.php?t=4718

                            Interestingly, here's a link to what looks like a reputable site, but it says the file is most likely spyware. Not sure what to make of that.

                            http://www.auditmypc.com/process/iun6002.asp

                            Ok, that's all I've got. Hope it helps a little bit.

                            Thanks and have a great one.

                            Comment


                            • #15
                              False Positives from Jaduratna?

                              Upon installing IObit Security 360 and scanning my hard disks it reported Three things the first two I do not understand ?

                              Hijack.StartMenu, Registry Data, HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced Value=Start_ShowSearch
                              Hijack.StartMenu, Registry Data, HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced Value=Start_ShowMyDocs

                              I have opted for: search & MyDocs not to be shown on my start menu, and they dont, please could you free me from my ignorance and explain what these mean?

                              the other states:

                              Spyware.OnlineGames, File, C:\Program Files\lxarscan.dll

                              this file is for a Lexmark Printer and I have scanned this file with Avira Antivir & Avast & AVG none of which find anything amiss with this file, I do find it hard to believe that the only 3 things found infected are all false positives.

                              any help would be gratefully recieved, thankyou

                              Comment

                              Working...
                              X