Avast False positive

Avast is giving false positive on Logitech Media Server 8.0 download…
hxtp://downloads.slimdevices.com/nightly/8.0/lms/e1939f546ee3b153f4c77025e05195a299e760a1/LogitechMediaServer-8.0.0-1596276608.exe

Please make that live link non-clickable like with - or hxtp
This until a final verdict has been received on you reporting a FP.
Download IP relations has detectections: https://www.virustotal.com/gui/ip-address/99.84.245.56/relations

polonus

FP, will be fixed in next update

relations 2020-05-30
4
/ 70 Win32 EXE GOMPLAYERGLOBALSETUP53_NEW.EXE
2020-06-17
1
/ 73 Win32 EXE Download Manager
https://www.virustotal.com/gui/file/94446b489d377b6ceb5e17ab2688744620dd744def11145ef631c2093a3c8f5e/detection
maybe suspicious file

Well it isn’t detected by Avast, so I wonder why you posted it in this Avast False positive topic. I did a fresh scan.
https://www.virustotal.com/gui/file/94446b489d377b6ceb5e17ab2688744620dd744def11145ef631c2093a3c8f5e/detection which has the same 4 detections. So almost two months later if this really was a virus (good detection) I would have expected more detections as the information is normally sent to those that didn’t detected it.

Of the ones that detected this, 3 basically consider it a PUA Potentially Unwanted Application and the other a heuristic detection which is more prone to false positive detections.

I assume that it is, was your comment on the Community section referring to this topic (which is totally unrelated to the link you gave) stating that it isn’t an FP in my opinion is incorrect.

Still getting false positives on logitech media server downloads at downloads.slimdevices.com

Be vigilant dear end-users,

The mis-detections or FPs could be language dependant, we have experienced that elsewhere, some downloads in english are OK,
while those for french language are flagged or not available bcause of errors etc. :wink:

Always check you deal with the correct download url (the " real McCoy"so to say) with right https address over correct DNS,
preferably via DoH, so it is not tampered with.

There is an awful lot of compromittal and manipulations going on by malcreants and cybercriminals online lately.
It is almost like the “Interwebs"is coming äpart at the seams” :smiley:

polonus

Have you reported it here:
Reporting Possible False Positive File or Website - https://www.avast.com/false-positive-file-form.php.

That said given my previous post about 3 of the detections essentially being considered PUP or Unwanted Application. For Avast to have detected this you would have had to enable PUPs in the scanning settings.

So do you have a screenshot of the Avast Alert window that you can attach (it might help) ?

Though this is strange given what JanK said 2 weeks ago.

Yes, I’ve reported it on https://www.avast.com/false-positive-file-form.php and I continue to get false positive “URL:BLACKLIST” on the downloads.slimdevices.com website. I’ve attached the screen snip as you requested.

I just visited downloads.slimdevices.com and no alert, see attached image 1.

Visiting the sub-folder for LogitechMediaServer_v7.9.3 no issue/alert.

But I did get an alert when I tried to download the latest 7.93 .exe file, but downloading the same 7.93 .msi file resulted in no alert and downloaded successfully and no alert during the download, images 2 & 3.

I’ve been assured by Logitech that all these are false positives. And here’s 2 more .exe files from this site that Avast delivers a FP on.

You would have to literally report these files individually giving the full URL as the site in itself isn’t detected as URL Blacklisted.

But it appears that this is only triggered on the .exe files, I tried the Nightly build for .msi version of 7.9 and 8.0 with no alert.

Reporting Possible False Positive File or Website - https://www.avast.com/false-positive-file-form.php and give the URL for the .exe file/s triggering the alert…

UK Gov Coronavirus data website is today affected by Webshield. Only part of webpage is displayed when default all shields active.
I first turned off Behaviour shield but was not that.
If Webshield is turned off then page displays properly with all graphs and data displayed as expected.
https://coronavirus.data.gov.uk/cases

I have submitted FP form to Avast.

I don’t appear to have a problem with that link, with the web shield all graphs and data appear to be correct, e.g. on strange blanks, etc. The actual graphs function as you mouse over them giving daily data and you can view individual countries.

I was using latest version of Firefox.

@DavidR. Seems OK today. I replied in the other thread.