Announcement

Collapse
No announcement yet.

How to report False Positive to us?

Collapse
This topic is closed.
X
This is a sticky topic.
X
X
  • Filter
  • Time
  • Show
Clear All
new posts

  • Warcraft 3 False Positive

    IObit Malware Fighter

    OS: Windows 7
    Version: 1.1.1.2
    Define Version: 1048
    Time Elapsed: 00:34:24
    Objects Scanned: 71272
    Threats Found: 1
    Save Time: 8/2/2011 12:04:19 AM

    |Name|Type|Description|ID|
    Trojan.Agent, FILE, C:\Program Files\Warcraft III\Warcraft III.exe, 4064959

    VirusTotal report is here

    I know for a fact that this is a false positive. I also am guessing that this program would create a false positive for the expansion called "The Frozen Throne"

    Both of these programs have been known to cause false positive in some antivirus programs in the past even after a fresh install from the CD. Seems those Antivirus programs corrected their DB to correct it.

    I'm going to add this to my ignore list until it is corrected. As well I'm going to add the Frozen Throne expansion to my ignore list once I install it if it is detected.
    ==========
    Jay

    Comment


    • False positive for Lotus notes

      Please note that the following was a false positive and stopped my Lotus Notes email system from working (now restored). I attach the report file below.

      Sincerely,

      Chris Holmes


      IObit Malware Fighter

      OS: Windows XP
      Version: 1.1.1.2
      Define Version: 1049
      Time Elapsed: 00:14:27
      Objects Scanned: 52263
      Threats Found: 1
      Save Time: 02/08/2011 11:30:08

      |Name|Type|Description|ID|
      Trojan.Backdoor - Quarantined, FILE, C:\Program Files\lotus\notes\nlnotes.exe, 4046285

      Comment


      • IMF False Positive CRYSIS?

        IObit Malware Fighter

        OS: Windows 7
        Version: 1.1.1.2
        Define Version: 1049
        Time Elapsed: 00:24:08
        Objects Scanned: 63768
        Threats Found: 1
        Save Time: 02/08/2011 17:58:38

        |Name|Type|Description|ID|
        Trojan.Dropper, FILE, C:\games\Electronic Arts\Crytek\Crysis WARHEAD\Bin32\CryAnimation.dll, 4071181

        I'm pretty sure this is a false positive as CRYSIS doesn't give your PC malware lol. P.S I just scanned this with Avast and it didn't detect anything so this is a sure 100% false positive.
        Last edited by TheGamer29; Aug. 2nd, 2011, 18:09.

        Comment


        • IObit Malware Fighter

          OS: Windows XP
          Version: 1.1.1.2
          Define Version: 1050
          Time Elapsed: 00:46:23
          Objects Scanned: 61433
          Threats Found: 3
          Save Time: 8/6/2011 5:42:51 PM

          |Name|Type|Description|ID|
          Trojan.Generic, FILE, C:\System Volume Information\_restore{EBEB4AB1-0344-48B8-807F-DDCFB32D5691}\RP369\A0018523.exe, 4050731
          Trojan.Crypt, FILE, C:\Program Files\AutoIt3\Examples\My Stuff\SageSet_Cleaner.exe, 4059639
          Trojan.Crypt, FILE, C:\Documents and Settings\RENSIM\Desktop\Suo16_Sage_Clean.exe, 4059639


          I am not sure about the first virus as reported in the restore point section. However, I wrote the next two in autoit and... Suo16_Sage_Clean.exe is a tool I use in the IObit ToolBox.

          These are not viruses.

          Thanks,
          Valuater
          MVP at Auoit3.com Forums
          Home = ClickTask.com

          Comment


          • Originally posted by Valuater View Post
            IObit Malware Fighter

            OS: Windows XP
            Version: 1.1.1.2
            Define Version: 1050
            Time Elapsed: 00:46:23
            Objects Scanned: 61433
            Threats Found: 3
            Save Time: 8/6/2011 5:42:51 PM

            |Name|Type|Description|ID|
            Trojan.Generic, FILE, C:\System Volume Information\_restore{EBEB4AB1-0344-48B8-807F-DDCFB32D5691}\RP369\A0018523.exe, 4050731
            Trojan.Crypt, FILE, C:\Program Files\AutoIt3\Examples\My Stuff\SageSet_Cleaner.exe, 4059639
            Trojan.Crypt, FILE, C:\Documents and Settings\RENSIM\Desktop\Suo16_Sage_Clean.exe, 4059639


            I am not sure about the first virus as reported in the restore point section. However, I wrote the next two in autoit and... Suo16_Sage_Clean.exe is a tool I use in the IObit ToolBox.

            These are not viruses.

            Thanks,
            Valuater
            hi Valuater

            fter investigation, we have assured that it's a false positive. Sorry for the trouble we have caused to you.

            We will solve this issue in our later update definition 1051.

            Thanks!!!
            IObit Support Team

            Comment


            • Trogan.Generic, Agent, and Trace

              Went to attached the report file,says its invalid! Maybe I should just uninstall this malware software, what a pain! I cut and pasted here anyway:

              IObit Malware Fighter

              OS: Windows XP
              Version: 1.1.1.2
              Define Version: 1061
              Time Elapsed: 01:39:24
              Objects Scanned: 79989
              Threats Found: 5
              Save Time: 9/16/2011 12:00:51 PM

              |Name|Type|Description|ID|
              Trojan.Generic - Quarantined, FILE, C:\WINDOWS\system32\init32.exe, 4072817
              Trojan.Generic - Quarantined, FILE, C:\WINDOWS\system32\userinit.exe, 4072817
              Trojan.Generic - Quarantined, FILE, C:\WINDOWS\system32\dllcache\userinit.exe, 4072817
              Trojan.Generic - Quarantined, FILE, C:\WINDOWS\ServicePackFiles\i386\userinit.exe, 4072817
              Trojan.Trace - Quarantined, FILE, C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP2099\A0249357.exe, 200350

              Comment


              • Hi the5berks, welcome to IObit Forum! :-D

                PLease have a look at
                userinit.exe - is it FP? [SOLVED by db 1062] thread.

                Also, if there is a starting problem, the solution is in THIS post by Cicely .

                Cheers.
                enoskype

                - Beauty lies in the eye of the beholder and belongs to the man who can appreciate it. -

                Comment


                • ORIGINAL PC files infected?

                  Some of these files are part of the ORIGINAL factory image of the PC, so it seems unlikely they are infected.

                  IObit Malware Fighter

                  OS: Windows 7
                  Version: 1.3.0.3
                  Define Version: 1128
                  Time Elapsed: 00:39:22
                  Objects Scanned: 85289
                  Threats Found: 8
                  Save Time: 04/05/2012 22:51:51

                  |Name|Type|Description|ID|
                  Trojan.Generic, FILE, C:\Users\Dad\Documents\Bookshop\PC\Old Disk\Toshiba\Drivers\Touchpad\Alps\Apoint.exe, 4074972
                  Trojan.Generic, FILE, C:\IRIS Payroll Basics\MonthendCleardown.exe, 4020096
                  Trojan.Spyware, FILE, D:\DRIVERS\09 WLAN + Bluetooth\Intel® PROSetWireless Bluetooth Software V1.0.1\XP\x32\Lang\setupCSY.dll, 4040458
                  Trojan.Spyware, FILE, D:\DRIVERS\09 WLAN + Bluetooth\Intel® PROSetWireless Bluetooth Software V1.0.1\XP\x32\Lang\setupITA.dll, 4040458
                  Trojan.Spyware, FILE, D:\DRIVERS\09 WLAN + Bluetooth\Intel® PROSetWireless Bluetooth Software V1.0.1\XP\x32\Lang\setupPLK.dll, 4040458
                  Trojan.Spyware, FILE, D:\DRIVERS\09 WLAN + Bluetooth\Intel® PROSetWireless Bluetooth Software V1.0.1\VistaWin7\vs32\Lang\setupCSY.dll, 4040458
                  Trojan.Spyware, FILE, D:\DRIVERS\09 WLAN + Bluetooth\Intel® PROSetWireless Bluetooth Software V1.0.1\VistaWin7\vs32\Lang\setupITA.dll, 4040458
                  Trojan.Spyware, FILE, D:\DRIVERS\09 WLAN + Bluetooth\Intel® PROSetWireless Bluetooth Software V1.0.1\VistaWin7\vs32\Lang\setupPLK.dll, 4040458

                  Comment


                  • Greetings Shipmates I also have a false positive running IOBIT Malware Fighter 2.5. I will zip to you per the last instructions given prior...copy or should I await for further instructions...over

                    Comment


                    • Hi Navyeagle, Welcome to IObit Forum!

                      Please start a topic under False Positive Reports by IObit Products sub section with IMF malware report content.


                      To check whether it is false positives, please provide IObit with more information below:

                      1. Upload all the reported file to Virus Total and supply the report links.
                      2. Zip the file and upload it to Wikisend and give us the download link.

                      You can look at THIS post as an example.

                      Thank you very much.

                      Cheers.
                      enoskype

                      - Beauty lies in the eye of the beholder and belongs to the man who can appreciate it. -

                      Comment




                      • ATTENTION! THIS TOPIC IS CLOSED



                        Hi All,

                        Please do not post your false positive reports in this topic!

                        Open a NEW TOPIC under False Positive Reports by IObit Products section as described in the first post of this topic.

                        Thank you and cheers.
                        enoskype

                        - Beauty lies in the eye of the beholder and belongs to the man who can appreciate it. -

                        Comment

                        Working...
                        X