Jump to content
IObit Forum
Top Free Driver Updater Tools Best 25 PC Optimization Software Best 22 Antimalware Best 22 Uninstaller Software IObit Coupons & Discount Offers PC Optimizer Mac Boost Advice IObit Coupons A Good Utility Program From IObit IObit Promo Codes IObit Coupon Codes IObit Coupons and Deals FAQs Driver Booster Pro Review

How to report False Positive to us?


Recommended Posts

False Positive with Calibre 0.6.33 [sOLVED]

 

Running calibre.exe 0.6.33 downloaded from

http://www.calibre-ebook.com/download_windows

throws up Agent.AKHH threat alert when starting up.

 

calibre.exe cannot be added to ignore list because scan shows that the problem is with a plugin file and not the exe.

 

Updated 360 from ver1.3 to 1.4 still same problem.

 

 

 

Virus Total scan:

http://www.virustotal.com/analisis/3dd3fd54d6604ce3734cd3a55dcf87aaadf80910c497f08ba441118f7533a966-1263251207

 

http://www.virustotal.com/analisis/b37ea9c0406426ed02b73af1465fc5cfb25ade61a9b47f8af3027952834e7151-1263225436

 

 

============================

 

IObit Security 360

 

OS:Windows XP

Version:1.4.0.11

Define Version:1307

Time Elapsed:00:00:50

Objects Scanned:3329

Threats Found:1

 

|Name|Type|Description|ID|

Agent.AKHH, File, C:\Program Files\Calibre2\plugins\lzx.pyd, 12-629

Link to comment
Share on other sites

False Positive

 

Hi All,

 

ID number 12-639 (threat name: Agent.AKHH) in current definitions version 1307 is a false positive. We will remove this data in our next update, Definitions Version: 1308.

 

Sorry for the inconvenience at present.

Link to comment
Share on other sites

What To Do With Quarantined Agent.AKHH? [sOLVED]

 

I am a novice at all this so this may sound a dumb question, but if I have just run an Iobit scan and this has shown up - Agent.AKHH - and it has been placed in quarantine, what do I do with it? Restore it or leave it there? (I ran the scan just before the latest update). The full path was:

 

Agent.AKHH, File, C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\it.lproj\SoftwareUpdateLocalized.dll, 12-629

 

The same scan also quarantined

Trojan.Patched, File, C:\WINDOWS\$NtServicePackUninstall$\advapi32.dll, 12-650

 

is this a false positive too and what should I do with it?

Link to comment
Share on other sites

Possible Fales Positives [sOLVED]

 

Dear IObit,

 

Here's the scan report:

IObit Security 360

 

OS:Windows XP

Version:1.4.0.11

Define Version:1308

Time Elapsed:00:11:22

Objects Scanned:58982

Threats Found:1

 

|Name|Type|Description|ID|

Agent.AKHH, File, C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\it.lproj\SoftwareUpdateLocalized.dll, 12-629

 

 

and here's the result from VirusTotal:

http://www.virustotal.com/analisis/e5e623c629fad49da000493a8dfc11807c575fab4c02eb899e0e9c633528486b-1263311658

 

Thanks for your kind attention!

Link to comment
Share on other sites

restore quarantined files

 

I am a novice at all this so this may sound a dumb question, but if I have just run an Iobit scan and this has shown up - Agent.AKHH - and it has been placed in quarantine, what do I do with it? Restore it or leave it there? (I ran the scan just before the latest update). The full path was:

 

Agent.AKHH, File, C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\it.lproj\SoftwareUpdateLocalized.dll, 12-629

 

The same scan also quarantined

Trojan.Patched, File, C:\WINDOWS\$NtServicePackUninstall$\advapi32.dll, 12-650

 

is this a false positive too and what should I do with it?

 

Hi Chiffy,

 

ID number 12-650 is also a false positive, which has also been removed in the latest definitions version 1308. Please update your IObit Security 360 to the latest version to solve these false positive.

 

You can try this way to restore the quarantined file.

 

Solution: Open IObit Security 360-> click Quarantine on the top-> select the quarantined items falsely reported-> click Restore.

Link to comment
Share on other sites

Dear IObit,

 

Here's the scan report:

IObit Security 360

 

OS:Windows XP

Version:1.4.0.11

Define Version:1308

Time Elapsed:00:11:22

Objects Scanned:58982

Threats Found:1

 

|Name|Type|Description|ID|

Agent.AKHH, File, C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\it.lproj\SoftwareUpdateLocalized.dll, 12-629

 

 

and here's the result from VirusTotal:

http://www.virustotal.com/analisis/e5e623c629fad49da000493a8dfc11807c575fab4c02eb899e0e9c633528486b-1263311658

 

Thanks for your kind attention!

 

Hi Samtso,

 

Please update your IObit Security 360 again to see whether it will still detect this item.

 

It's a little weird as we do remove this string in our 1308 definitions version.:roll:

Link to comment
Share on other sites

Another False Positive? [sOLVED]

 

Hi Cicely,

 

No new update can be found. But it's quite strange, I just do another scan and here's the report:

IObit Security 360

 

OS:Windows XP

Version:1.4.0.11

Define Version:1308

Time Elapsed:00:11:00

Objects Scanned:59095

Threats Found:1

 

|Name|Type|Description|ID|

Trojan.Dialer, File, C:\Program Files\EASEUS\EASEUS Partition Master 4.1.1 Home Edition\bin\AutoUpdate.dll, 12-710

 

I noted the define version is still 1308, but no sight of the 12-629, instead it shows another threat, the 12-710.

 

Below is the link to the VirusTotal result:

http://www.virustotal.com/analisis/bc0d9e4a67203f6b0a73674b672a936a39f11cab39e33e70a6df5ea5cc3b013d-1263374455

 

Thanks for your kind attention.

Link to comment
Share on other sites

Hi Cicely,

 

No new update can be found. But it's quite strange, I just do another scan and here's the report:

IObit Security 360

 

OS:Windows XP

Version:1.4.0.11

Define Version:1308

Time Elapsed:00:11:00

Objects Scanned:59095

Threats Found:1

 

|Name|Type|Description|ID|

Trojan.Dialer, File, C:\Program Files\EASEUS\EASEUS Partition Master 4.1.1 Home Edition\bin\AutoUpdate.dll, 12-710

 

I noted the define version is still 1308, but no sight of the 12-629, instead it shows another threat, the 12-710.

 

Below is the link to the VirusTotal result:

http://www.virustotal.com/analisis/bc0d9e4a67203f6b0a73674b672a936a39f11cab39e33e70a6df5ea5cc3b013d-1263374455

 

Thanks for your kind attention.

 

hi samtso,

 

Most possible explain for the different scan report is that you performed your first scan right when we updated our database.;-)

 

For the ID 12-710 in 1308, we will remove it in today's update, definitions version 1309. And thank you for your information.

Link to comment
Share on other sites

Virus Software [sOLVED]

 

IObit Security 360

 

OS:Windows Vista

Version:1.3.0.10

Define Version:1308

Time Elapsed:00:33:55

Objects Scanned:82254

Threats Found:3

 

|Name|Type|Description|ID|

Tracking Cookies - Removed, Cookies, Cookie:jeannie johnson@mgnetwork.com/, 7-1979

Trojan.Dialer, File, C:\Program Files\CenturyLink Online Security\Anti-Virus\dbbackup\fsgkhs\fsuss.dll, 12-710

Trojan.Dialer, File, F:\Program Files\CenturyLink Online Security\Anti-Virus\dbbackup\fsgkhs\fsuss.dll, 12-710

This is part of my antivirus software provided by my internet provider.

Link to comment
Share on other sites

Hi cicely,

 

Most possible explain for the different scan report is that you performed your first scan right when we updated our database.;-)

 

Yes, I think so!

 

For the ID 12-710 in 1308, we will remove it in today's update, definitions version 1309.

 

Just finish a full scan with version 1309, the threat is gone!:grin:

 

Thanks a lot!

Link to comment
Share on other sites

false positive [sOLVED]

 

Dear IObit,

 

I think the 12-323 may be a false positive, please take a look to this report:

IObit Security 360

 

OS:Windows XP

Version:1.3.0.10

Define Version:1311

Time Elapsed:00:14:07

Objects Scanned:57751

Threats Found:5

 

|Name|Type|Description|ID|

Tracking Cookies - Removed, Cookies, Cookie:samueltso@www.googleadservices.com/pagead/conversion/1034747469/, 7-1856

Tracking Cookies - Removed, Cookies, Cookie:samueltso@bs.serving-sys.com/, 7-1516

Tracking Cookies - Removed, Cookies, Cookie:samueltso@imrworldwide.com/cgi-bin, 7-1508

Tracking Cookies - Removed, Cookies, Cookie:samueltso@serving-sys.com/, 7-1516

Trojan.Injector, File, D:\ForSetup\ACT2000\ACT\EarthLnk\SETUP.EXE, 12-323

 

 

and here's the result from VirusTotal:

http://www.virustotal.com/analisis/9428d5353130b9ef6b9cbf2d1067b20cc253e20c6a2d26e607c42db99158f951-1263982270

 

Thanks for your kind attention.

Link to comment
Share on other sites

  • 2 weeks later...

False positive here.

 

I have copied this post here so it will be sure to be noticed!! Thanks!:grin:

 

11-17-2009, 08:14 AM

burAK-47

Junior Member

Join Date: Nov 2009

Posts: 2

 

Damn NFO Viewer False Positive

 

--------------------------------------------------------------------------------

Made Full-Scan with:

IObit Security 360 v.1.3.0 Pro

Definitions: 1281

 

Damn NFO Viewer.exe is surely not a Virus...

 

Virustotal Link:

http://www.virustotal.com/de/analisi...3a5-1257852850

Link to comment
Share on other sites

scarddlg.dll: false positive?

 

Hello,

in my opinion, Security360 reported a false positive.

 

Here's the report:

 

"IObit Security 360

 

OS:Windows XP

Versione:1.4.0.11

Versione database:1320

Tempo trascorso:00:03:05

Oggetti analizzati:47140

Minacce rilevate:1

 

| Nome | Tipo |Descrizione|ID|

Trojan.Agent, File, C:\WINDOWS\system32\scarddlg.dll, 12-1046"

 

 

No other antivirus or antimalware treats this file as infected.

Link to comment
Share on other sites

IObit Security 360

 

OS:Windows 7

Version:1.4.0.11

Define Version:1320

Time Elapsed:00:01:40

Objects Scanned:62968

Threats Found:2

 

|Name|Type|Description|ID|

Trojan.Agent, File, C:\Windows\winsxs\amd64_wiacn001.inf_31bf3856ad364e35_6.1.7600.16385_none_95eb24d2d4a0a55b\CNHW900.DLL, 12-1046

Trojan.Agent, File, C:\Windows\System32\DriverStore\FileRepository\wiacn001.inf_amd64_neutral_b7a0b2f53d745b5a\CNHW900.DLL, 12-1046

Link to comment
Share on other sites

Hello,

in my opinion, Security360 reported a false positive.

 

Here's the report:

 

"IObit Security 360

 

OS:Windows XP

Versione:1.4.0.11

Versione database:1320

Tempo trascorso:00:03:05

Oggetti analizzati:47140

Minacce rilevate:1

 

| Nome | Tipo |Descrizione|ID|

Trojan.Agent, File, C:\WINDOWS\system32\scarddlg.dll, 12-1046"

 

 

No other antivirus or antimalware treats this file as infected.

 

Dear Icaro0952

Thanks for your feedback

You can upload or send us your your suspicious file,and then we can further investigate it.

We are looking forward to your reply.

 

_________________

Iobit Support Team

Link to comment
Share on other sites

It's detecting Excel 07 as Trojan :evil:

 

IObit Security 360

 

OS:Windows 7

Version:1.4.0.11

Define Version:1322

Time Elapsed:00:01:01

Objects Scanned:46531

Threats Found:1

 

|Name|Type|Description|ID|

Trojan.Agnet, File, C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE, 9-41794

Link to comment
Share on other sites

Hi yowanvista,

 

I have uploaded EXCEL.EXE from my PC to VirusTotal, and the report is HERE .

 

But this should not be taken as the result, as your EXCEL.EXE file is under consideration

 

The summary is:

 

File EXCEL.EXE received on 2010.02.10 23:24:11 (UTC)

Current status: finished

 

Result: 0/41 (0%)

 

 

Cheers.

Link to comment
Share on other sites

Hi yowanvista,

 

I have uploaded EXCEL.EXE from my PC to VirusTotal, and the report is HERE .

 

But this should not be taken as the result, as your EXCEL.EXE file is under consideration

 

The summary is:

 

File EXCEL.EXE received on 2010.02.10 23:24:11 (UTC)

Current status: finished

 

Result: 0/41 (0%)

 

 

Cheers.

 

I360 will only detect MS EXCEL07 as trojan when excel.exe is running.

I have also scanned it with MSE and Avast, not malware

Link to comment
Share on other sites

360 reporting O2 software as Trojans

 

Hi your 360 program recently updated and the following scan reported what follows, just to be certain I googled the trojan mentioned and discovered that although it can be a serious customer it can also produce false positives, so I checked my O2 installation disc which they supplied with the router and the files reported are on the O2 disc. Therefore I suggest that 360 has indeed produced 2 false positive readings. Thanks for your time and here is the report:

 

IObit Security 360

 

OS:Windows XP

Version:1.4.0.11

Define Version:1326

Time Elapsed:00:45:39

Objects Scanned:73115

Threats Found:2

 

|Name|Type|Description|ID|

Trojan.Chifrax, File, C:\Program Files\O2\Utilities\RT-585n_82L0AH.exe, 11-5289

Trojan.Chifrax, File, C:\Program Files\O2\Utilities\RT-585v7_74K4EJ.exe, 11-5289

 

Any feedback would be welcome.

 

Thanks again - Dean

Link to comment
Share on other sites

false positive

 

IObit Security 360

 

OS:Windows XP

Version:1.4.1.11

Define Version:1326

Time Elapsed:01:01:42

Objects Scanned:61936

Threats Found:2

 

|Name|Type|Description|ID|

Spy.Matles.A, File, C:\Program Files\FamilySearch\Paf5\pstart.exe, 11-3163

Spy.Matles.A, File, C:\Program Files\ArcSoft\Software Suite\Funhouse\wdmcapture.dll, 11-3163

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...