Announcement

Collapse
No announcement yet.

How to report False Positive to us?

Collapse
This topic is closed.
X
This is a sticky topic.
X
X
  • Filter
  • Time
  • Show
Clear All
new posts

  • Tim Xue
    started a topic How to report False Positive to us?

    How to report False Positive to us?

    Hello Everyone,

    Before reporting false positives, please read the following guidelines and requirements, and provide us with the requested information as below:

    1) Save a scan log first and post it here.
    Please use the latest version of IObit Malware Fighter to run a scan. This will help us know the detailed information of the scan result.

    Scan Log Example:

    IObit Malware Fighter

    OS: Windows 8
    Version: 2.4.1.15
    Define Version: 1383
    Time Elapsed: 00:19:53
    Objects Scanned: 66821
    Threats Found: 1
    Save Time: 20/10/2014 13:54:27

    |Name|Type|Description|ID|
    Trojan.Generic, FILE, C:\Program Files\tixati\errorreporter.exe, 4123518

    2) Upload and scan the reported file (take errorreporter.exe for an example) mentioned in the scan log to Virus Total and give us the report link.

    How to upload and scan a file at VirusTotal

    Go to Virus Total
    • Click Choose File
    • On the left of the window that opens click My Computer
    • Open (C:)
    • Find the reported file according to the full path in the scan log
    • Double click the file name, and it will disappear in the VirusTotal box.
    • Click Scan it! and wait (you may be in a queue)
    • When the scan has finished, copy the address from the address bar to post here.

    3) Zip the reported file (take errorreporter.exe for an example) with password "infected", update it to Wikisend, and give us the download link.
    Our specialists are unable to make a conclusive analysis without a sample.

    Our IObit Specialist Team will do further investigation and reply to you with a result ASAP.

    Thank you.

  • enoskype
    replied


    ATTENTION! THIS TOPIC IS CLOSED



    Hi All,

    Please do not post your false positive reports in this topic!

    Open a NEW TOPIC under False Positive Reports by IObit Products section as described in the first post of this topic.

    Thank you and cheers.

    Leave a comment:


  • enoskype
    replied
    Hi Navyeagle, Welcome to IObit Forum!

    Please start a topic under False Positive Reports by IObit Products sub section with IMF malware report content.


    To check whether it is false positives, please provide IObit with more information below:

    1. Upload all the reported file to Virus Total and supply the report links.
    2. Zip the file and upload it to Wikisend and give us the download link.

    You can look at THIS post as an example.

    Thank you very much.

    Cheers.

    Leave a comment:


  • Navyeagle
    replied
    Greetings Shipmates I also have a false positive running IOBIT Malware Fighter 2.5. I will zip to you per the last instructions given prior...copy or should I await for further instructions...over

    Leave a comment:


  • cjrees
    replied
    ORIGINAL PC files infected?

    Some of these files are part of the ORIGINAL factory image of the PC, so it seems unlikely they are infected.

    IObit Malware Fighter

    OS: Windows 7
    Version: 1.3.0.3
    Define Version: 1128
    Time Elapsed: 00:39:22
    Objects Scanned: 85289
    Threats Found: 8
    Save Time: 04/05/2012 22:51:51

    |Name|Type|Description|ID|
    Trojan.Generic, FILE, C:\Users\Dad\Documents\Bookshop\PC\Old Disk\Toshiba\Drivers\Touchpad\Alps\Apoint.exe, 4074972
    Trojan.Generic, FILE, C:\IRIS Payroll Basics\MonthendCleardown.exe, 4020096
    Trojan.Spyware, FILE, D:\DRIVERS\09 WLAN + Bluetooth\Intel® PROSetWireless Bluetooth Software V1.0.1\XP\x32\Lang\setupCSY.dll, 4040458
    Trojan.Spyware, FILE, D:\DRIVERS\09 WLAN + Bluetooth\Intel® PROSetWireless Bluetooth Software V1.0.1\XP\x32\Lang\setupITA.dll, 4040458
    Trojan.Spyware, FILE, D:\DRIVERS\09 WLAN + Bluetooth\Intel® PROSetWireless Bluetooth Software V1.0.1\XP\x32\Lang\setupPLK.dll, 4040458
    Trojan.Spyware, FILE, D:\DRIVERS\09 WLAN + Bluetooth\Intel® PROSetWireless Bluetooth Software V1.0.1\VistaWin7\vs32\Lang\setupCSY.dll, 4040458
    Trojan.Spyware, FILE, D:\DRIVERS\09 WLAN + Bluetooth\Intel® PROSetWireless Bluetooth Software V1.0.1\VistaWin7\vs32\Lang\setupITA.dll, 4040458
    Trojan.Spyware, FILE, D:\DRIVERS\09 WLAN + Bluetooth\Intel® PROSetWireless Bluetooth Software V1.0.1\VistaWin7\vs32\Lang\setupPLK.dll, 4040458

    Leave a comment:


  • enoskype
    replied
    Hi the5berks, welcome to IObit Forum! :-D

    PLease have a look at
    userinit.exe - is it FP? [SOLVED by db 1062] thread.

    Also, if there is a starting problem, the solution is in THIS post by Cicely .

    Cheers.

    Leave a comment:


  • the5berks
    replied
    Trogan.Generic, Agent, and Trace

    Went to attached the report file,says its invalid! Maybe I should just uninstall this malware software, what a pain! I cut and pasted here anyway:

    IObit Malware Fighter

    OS: Windows XP
    Version: 1.1.1.2
    Define Version: 1061
    Time Elapsed: 01:39:24
    Objects Scanned: 79989
    Threats Found: 5
    Save Time: 9/16/2011 12:00:51 PM

    |Name|Type|Description|ID|
    Trojan.Generic - Quarantined, FILE, C:\WINDOWS\system32\init32.exe, 4072817
    Trojan.Generic - Quarantined, FILE, C:\WINDOWS\system32\userinit.exe, 4072817
    Trojan.Generic - Quarantined, FILE, C:\WINDOWS\system32\dllcache\userinit.exe, 4072817
    Trojan.Generic - Quarantined, FILE, C:\WINDOWS\ServicePackFiles\i386\userinit.exe, 4072817
    Trojan.Trace - Quarantined, FILE, C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP2099\A0249357.exe, 200350

    Leave a comment:


  • hxin
    replied
    Originally posted by Valuater View Post
    IObit Malware Fighter

    OS: Windows XP
    Version: 1.1.1.2
    Define Version: 1050
    Time Elapsed: 00:46:23
    Objects Scanned: 61433
    Threats Found: 3
    Save Time: 8/6/2011 5:42:51 PM

    |Name|Type|Description|ID|
    Trojan.Generic, FILE, C:\System Volume Information\_restore{EBEB4AB1-0344-48B8-807F-DDCFB32D5691}\RP369\A0018523.exe, 4050731
    Trojan.Crypt, FILE, C:\Program Files\AutoIt3\Examples\My Stuff\SageSet_Cleaner.exe, 4059639
    Trojan.Crypt, FILE, C:\Documents and Settings\RENSIM\Desktop\Suo16_Sage_Clean.exe, 4059639


    I am not sure about the first virus as reported in the restore point section. However, I wrote the next two in autoit and... Suo16_Sage_Clean.exe is a tool I use in the IObit ToolBox.

    These are not viruses.

    Thanks,
    Valuater
    hi Valuater

    fter investigation, we have assured that it's a false positive. Sorry for the trouble we have caused to you.

    We will solve this issue in our later update definition 1051.

    Thanks!!!

    Leave a comment:


  • Valuater
    replied
    IObit Malware Fighter

    OS: Windows XP
    Version: 1.1.1.2
    Define Version: 1050
    Time Elapsed: 00:46:23
    Objects Scanned: 61433
    Threats Found: 3
    Save Time: 8/6/2011 5:42:51 PM

    |Name|Type|Description|ID|
    Trojan.Generic, FILE, C:\System Volume Information\_restore{EBEB4AB1-0344-48B8-807F-DDCFB32D5691}\RP369\A0018523.exe, 4050731
    Trojan.Crypt, FILE, C:\Program Files\AutoIt3\Examples\My Stuff\SageSet_Cleaner.exe, 4059639
    Trojan.Crypt, FILE, C:\Documents and Settings\RENSIM\Desktop\Suo16_Sage_Clean.exe, 4059639


    I am not sure about the first virus as reported in the restore point section. However, I wrote the next two in autoit and... Suo16_Sage_Clean.exe is a tool I use in the IObit ToolBox.

    These are not viruses.

    Thanks,
    Valuater

    Leave a comment:


  • TheGamer29
    replied
    IMF False Positive CRYSIS?

    IObit Malware Fighter

    OS: Windows 7
    Version: 1.1.1.2
    Define Version: 1049
    Time Elapsed: 00:24:08
    Objects Scanned: 63768
    Threats Found: 1
    Save Time: 02/08/2011 17:58:38

    |Name|Type|Description|ID|
    Trojan.Dropper, FILE, C:\games\Electronic Arts\Crytek\Crysis WARHEAD\Bin32\CryAnimation.dll, 4071181

    I'm pretty sure this is a false positive as CRYSIS doesn't give your PC malware lol. P.S I just scanned this with Avast and it didn't detect anything so this is a sure 100% false positive.
    Last edited by TheGamer29; Aug. 2nd, 2011, 18:09.

    Leave a comment:


  • chris.holmes
    replied
    False positive for Lotus notes

    Please note that the following was a false positive and stopped my Lotus Notes email system from working (now restored). I attach the report file below.

    Sincerely,

    Chris Holmes


    IObit Malware Fighter

    OS: Windows XP
    Version: 1.1.1.2
    Define Version: 1049
    Time Elapsed: 00:14:27
    Objects Scanned: 52263
    Threats Found: 1
    Save Time: 02/08/2011 11:30:08

    |Name|Type|Description|ID|
    Trojan.Backdoor - Quarantined, FILE, C:\Program Files\lotus\notes\nlnotes.exe, 4046285

    Leave a comment:


  • jasoncollege24
    replied
    Warcraft 3 False Positive

    IObit Malware Fighter

    OS: Windows 7
    Version: 1.1.1.2
    Define Version: 1048
    Time Elapsed: 00:34:24
    Objects Scanned: 71272
    Threats Found: 1
    Save Time: 8/2/2011 12:04:19 AM

    |Name|Type|Description|ID|
    Trojan.Agent, FILE, C:\Program Files\Warcraft III\Warcraft III.exe, 4064959

    VirusTotal report is here

    I know for a fact that this is a false positive. I also am guessing that this program would create a false positive for the expansion called "The Frozen Throne"

    Both of these programs have been known to cause false positive in some antivirus programs in the past even after a fresh install from the CD. Seems those Antivirus programs corrected their DB to correct it.

    I'm going to add this to my ignore list until it is corrected. As well I'm going to add the Frozen Throne expansion to my ignore list once I install it if it is detected.

    Leave a comment:


  • MoneyWonder
    replied
    Microsoft Flight Simulator X False Positive?

    IObit Security 360

    OS:Windows 7
    Version:1.6.1.2
    Define Version:2512
    Time Elapsed:00:33:44
    Objects Scanned:78313
    Threats Found:1

    |Name|Type|Description|ID|
    Trojan.Agent, File, C:\Microsoft Flight Simulator X\activate.exe, 12-68

    Never had a problem With this Software before and it hasn't flashed up on my Norton or security essentials, so is this a false positive? I Hope it is.
    I've submitted it as a sample.

    Leave a comment:


  • enoskype
    replied
    Hi dubyadd,

    Weather bug was a false positve, but have you made a search in the web for pointroll cookie?

    It is a tracking cookie and certainly not false positive by IS360.

    IS360 is doing what it is supposed to do.

    Cheers.

    Leave a comment:


  • dubyadd
    replied
    42 new threats-ridiculus

    Here is the report I got today, it takes so long to report these on the ignore list 1 at a time like I did with the 37 other files for weather bug, I will just uninstall this program , reinstall , run the scan again, if clear will keep, if shows again will just uninstall for a month until this is fixed. This is the second time I have had to do this. Isn't there a better program to do this with. Any suggestions, as this is getting too time consuming :roll:


    Obit Security 360

    OS:Windows Vista
    Version:1.6.0.2
    Define Version:2422
    Time Elapsed:01:09:04
    Objects Scanned:86455
    Threats Found:42

    |Name|Type|Description|ID|
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...08185815439572, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...65636411954764, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...98482276762372, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...32717289426543, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...36967928321596, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...04690427136923, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...05982620003628, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...75385964156327, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...39878605793564, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...57410251082296, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...87373113809782, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...96446058173086, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...03265966538983, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...76392511202558, 7-2045
    Tracking Cookies, Cookies, http://spd.pointroll.com/PointRoll/A...=0&set=1&bye=1, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...96402060504395, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...01936760356931, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...18348102789787, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...61935610682309, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...21849966671294, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...36466288363353, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...00166061150872, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...31305128476752, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...58227559450365, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...54929581369989, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...11982689694475, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...68887799374755, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...04379233341687, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...32808541879032, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...57466527031853, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...61080405046368, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...89162818672072, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...97619196038755, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...16035646966245, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...19882456216391, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...40267989941091, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...84928491786738, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...76787934356533, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...37952580920812, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...70743665687664, 7-2045
    Tracking Cookies, Cookies, http://t.pointroll.com/PointRoll/Tra...9E9-3E3F-0209-

    Leave a comment:

Working...
X