False-positive Detection Of My Application!, Please help me fix this issue...

i would like to let you know that my application is once again identified FALSE-POSITIVELY by your anti-virus as “Win32:Trojan-gen {Other}”, I have contacted you guys before and you fixed the issue but now it’s flagged again!

Scan result:


Avast	4.8.1335.0	2009.02.14	Win32:Trojan-gen {Other}

My application currently provided to over 5K users since last month and the only recommendation we can provide these users suffering from the FALSE-DETECTION of our application as a trojan is to SWITCH TO A DIFFERENT Anti-Virus company that doesn’t make this mistake…

I would very much appreciate it if something can be done about this terrible situation…

The application files for checking can be found here: (no installation just files…)

http://www.e-lephant.org/progfiles/S-Corp_(E)lephant_0.0.2.1_B-FP.rar

Pass: False-Positive

Please, Please, Please see to it’s fix.
Shlomi kalfa, S-Corp.
_________________________________________________________________________________________

Though it was fixed before, now the issue is re’Occuring - Please Fix it Again :frowning:
Here is the new report:
_________________________________________________________________________________________

I would like to let you know that my application is once again
identified FALSE-POSITIVELY by your anti-virus as Win32:Trojan-gen {Other}, I
have contacted you guys before and you fixed the issue but now it’s
flagged again!

Scan result:

Avast 4.8.1335.0 2009.06.01 Win32:Trojan-gen {Other}

My application currently provided to over 10K users since last month and
the only recommendation we can provide these users suffering from the
FALSE-DETECTION of our application as a trojan is to SWITCH TO A
DIFFERENT Anti-Virus company that doesn’t make this mistake…

I would very much appreciate it if something can be done about this
terrible situation…

The application files for checking can be found here: (no installation just files…)

http://www.e-lephant.org/progfiles/(E)lephant-FP.zip

(13,612 MB)
or here:

http://www.e-lephant.org/progfiles/(E)lephant-FP.rar

(4,254 MB)
Pass: infected

Please, Please, Please see to it’s fix.
Shlomi kalfa, S-Corp.

Hi schlomikalfa,

Send this FP to avast, and they may get it fixed in one of the forthcoming releases,
Thanks for reporting this, these are the risks of running generic av or heuristics,

polonus

is there any chance you might help me some more as to where/how do i send these files ?!?

Hi Shlomikalfa,

Your user could do the following in the mean time:
Create a folder called Suspect in the C:\ drive, e.g. C:\Suspect. Now exclude that folder in the Standard Shield, Customize, Advanced, Add, type (or copy and paste) C:\Suspect* That will stop the standard shield scanning any file you put in that folder. You should now be able to export any file in the chest to this folder and upload it to VirusTotal without avast alerting.

Reporting the apparent False Positive:
If it is indeed a false positive, see http://forum.avast.com/index.php?topic=34950.msg293451#msg293451, how to report it to avast! and what to do to exclude them until the problem is corrected.

Have a nice start of the week,
שלום

polonus aka Damian

I’ve sent an e-mail msg to:
virus@avast.com

As it mentioned in the thread you referred me to.

I truly hope my msg will not be over-looked and that the FP will be removed from my files!

Btw, Yes It Is A False-Positive !!!
תודה רבה.

Hi Shlomikalfa,

Glad to be of help, you’re welcome. No, I am sure it won’t be overlooked, just wait for the next iAVSUpdate and see if it is no longer flagged,

Surf safe and secure,

polonus

I would like to let you know that my application is once again
identified FALSE-POSITIVELY by your anti-virus as Win32:Trojan-gen {Other}, I
have contacted you guys before and you fixed the issue but now it’s
flagged again!

Scan result:

Avast 4.8.1335.0 2009.06.01 Win32:Trojan-gen {Other}

My application currently provided to over 10K users since last month and
the only recommendation we can provide these users suffering from the
FALSE-DETECTION of our application as a trojan is to SWITCH TO A
DIFFERENT Anti-Virus company that doesn’t make this mistake…

I would very much appreciate it if something can be done about this
terrible situation…

The application files for checking can be found here: (no installation just files…)

http://www.e-lephant.org/progfiles/(E)lephant-FP.zip

(13,612 MB)
or here:

http://www.e-lephant.org/progfiles/(E)lephant-FP.rar

(4,254 MB)
Pass: infected

Please, Please, Please see to it’s fix.
Shlomi kalfa, S-Corp.

Distributes WinZip 12 Keygen:
http://www.e-lephant.org/Download.php?ID=360

What ?!?!

THAT IS A WEB-SITE !!! WHAT DOES THAT HAS TO DO WITH MY PROGRAM ?!

sorry for the caps but statements like that gets me angry!

The program is not a virus, and surely not a trojan !!! are you blocking “FireFox” for being able to display warez sites ?! “Explorer”, “Chrome” or any other browser?!?!

The program as a built in web-browser … it doesn’t make it a virus or a trojan !!!

Please Fix the False-Positive Trojan Detection of my program!

Hi Shlomikalfa

Suspicious Inline Scripts are found on the website:
Long suspicious script

document.write(String.fromCharCode(60,83,67,82,73,80,84));document.write(' src="http://ads.adbrite....

Long suspicious script

document.write(String.fromCharCode(60,83,67,82,73,80,84));document.write(' src="http://ads.adbrite....

Long suspicious script

ocument.write(String.fromCharCode(60,83,67,82,73,80,84));document.write(' src="http://ads.adbrite....

Long suspicious script

ocument.write(String.fromCharCode(60,83,67,82,73,80,84));document.write(' src="http://ads.adbrite....

The site “an sich” is safe. But the suspicious script following the iFrame is flagged,

polonus

If you send a “false positive” link (no matter if true or not) to an obviously warez site… I’d certainly ignore you, once and for all.

@polonus
Are you claiming that the well known huge advertising company - Adbrite are in-fact Suspicious ?!?
What’s next ?! Google ?! MicroSoft ?!
And how does that have anything to do with my application ?!?

The application doesn’t hold any malicious / suspicious code, please remove it’s false-positive identification as a trojan! If you have any issues with the web-site … block it! but what does that program has to do with it?!

Is there anyone else i should address on the subject maybe ?! This is completely out of my logic how could you claim that the program is a ‘Trojan’ and blame the web-site for it !!!

@igor
Your opinions are nice but they are not of my interest, Thanks for responding.

Yours are not. Thread closed.