False positive

Hi, file is too big (~20Mb) for mail submission so i will post here. I am author for a tool for StarCraft: Brood War game:
http://www.teamliquid.net/forum/brood-war/414636-mca64launcher

Problem is with NSIS generated installer, cause when i scan all files included then all is clear. When generating installer then for AVAST is a virus.

.exe http://9rax.com/mca64/download.php
NSIS script: https://github.com/mca64/mca64Launcher/blob/master/Instalator/mca64Launcher.nsi

Please fix it.

hello

If the samples was sent through the contact it will be fixed.
http://www.avast.com/contact-form.php

virustotal 7 / 54 detection threat
https://www.virustotal.com/en/file/33563e467ac7a66f54c37da840d7ec88d1beeadf1ec30ba04b56535c34e94a74/analysis/1405548039/

Send the file to analyze to virus@avast.com in the subject line in zip or rar
password protected “virus” or “infected”.

please,submit a support ticket

https://support.avast.com/Tickets/Submit

you can send files from avast chest
how to use the chest http://www.avast.com/faq.php?article=AVKB21

now looks clean for avast https://www.virustotal.com/pl/file/33563e467ac7a66f54c37da840d7ec88d1beeadf1ec30ba04b56535c34e94a74/analysis/1405582301/

thank you. I hope for next releases no more problems with NSIS

you’re welcome

false positive is a reality ,I can not guarantee that
there will be problem again. :slight_smile:

https://www.virustotal.com/en/file/7b4677089ac3490b56f6a4c0a98d83d79b014651fc2548b7513cced0402c4344/analysis/1409319080/

informed the virus analyst
wait response.

than you

it seems that the previous topic was removed
because it did not get the time, since this is just a scan on VT.

thank you again. Now avast users can install my applicaton.

You’re welcome.

To mca640 and everyone else who reads this post:

In cases like this we (as fellow users) can’t do much about the problem.
But we can checked things and give a (strong) indication if it is a false positive or not.
At the end it is up to avast to investigate and if needed fix things.

But please keep reporting things like this.
If someone doesn’t know that there is something wrong, they can’t fix it :wink:

Please recheck latest version

link: http://mca64.com/mca64Launcher/download.php
problem: Win32:Malware-gen

thank You.

Please reclassify

link: http://mca64.com/mca64Launcher/mca64Launcher2.0.0.109.exe
status: Win32:Malware-gen

Thank You!

False Positives can be reported here https://support.avast.com

avast is not the only one to detecte
https://www.virustotal.com/en/file/5d85983e22d827919874053af574dec7993a9395bc2953356423d8b359b21ed0/analysis/1417971535/
https://www.metascan-online.com/en/scanresult/file/8b1078c03dcb4e5b96a6f014b7a38135

URL blacklist check
https://www.virustotal.com/en/url/3335c07bf5c8b2bbfe2a6a432ca6b34fb5893cc1840ac5de7fd63929466121d5/analysis/1417971750/

IP history
https://www.virustotal.com/en/ip-address/95.85.60.9/information/

i send in the past mails to https://support.avast.com

and never got respond. Only when i posted here there was reaction.

Hello,

can you please upload this file on our ftp and send here a msg with the file name? We will check it and in case of a problem fix it.

Sorry for your inconvenience,

Jan

https://www.virustotal.com/en/file/c79e5a4aab17a93d29e6928b8de8e1fca8daf6afa9550bba8af744d541d72c88/analysis/1419968217/

please fix it false positive, file can be downloaded form here http://mca64.com/mca64Launcher/download.php

use Viruses and Worms forum section for reporting false positives and malware problems

you can report to avast lab here https://support.avast.com/ → avast virus lab

URL given above is blacklisted, see info here
https://www.virustotal.com/en/url/fe732938fcc915d745cd5f3d68c5728846f8cbe3aa81058723b541418306166b/analysis/1442217552/

file scan
https://www.virustotal.com/en/file/47e027311086b621548cc5acf783dd990e12373c34f1260bea4489cddd6cdf88/analysis/1442245332/

https://www.metascan-online.com/#!/results/file/76f881c101724f28bd72b1b90bca8f92/regular

Advanced heuristic and reputation engines

TrendMicro-HouseCall TROJ_GEN.R03EC0OHK15.
Symantec reputation Suspicious.Insight

is detected as FileRepMetagen [Malware] and Win32:Malware-gen

it was fixed in update VPS 150914-01