False Trojan report with our Zappit Software

I have written to Avast support but have not received a response, so trying this forum. Here is problem:

Cloudeight owns and is the developer for Zappit system cleaner; the program has been available for a few years and has not been updated for over 2 years, so no changes have been made recently. Avast is reporting a false positive on our software and this has just started happening with your most recent updates.

Home page for Zappit: http://zappit.net

Our downoad is set up with Cnet’s Download.com and certified clean as well; you can go there directly to test the download: http://www.download.com/Zappit-System-Cleaner/3000-2144_4-10568472.html?tag=lst-0-1

Please let us know as soon as possible when to expect this problem to be corrected.

Regards,

Cloudeight Internet LLC

What was it saying it was infected with ?

I’m just an avast user but I was unable to reach that URL with firefox. Download.com may stop direct linking to downloads, found it is better to start at the information page http://www.download.com/3000-2144_4-10568472.html.

If you are getting a virus warning that you believe is a false positive, then if you can zip and password protect (‘virus’, will do) the suspect file and send it to virus @ avast.com (no spaces).

Give a brief outline of the problem (possibly a link to this thread), the fact that you believe it to be a false positive and include the password in the body of the email and False Positive as the subject. Some info on the avast version and VPS number (see about avast {right click avast icon}) will also help.

I sent this information to virus@avast.com several days ago with no response. I followed the instructions on another post in this forum to first check at http://virusscan.jotti.org which I did (nothing found) and then send info to virus@avast.com with zipped file.

I own the software (we are the developer), we know it does not have a trojan; the “trojan” alert just started showing up with the lastest Avast definitions. We have not updated the program for about 2 years; its the same program that has been download over 200,000 times with no problems;it was also tested on Cnets Download.com .

I have uploaded the file to our server so you can access: http://www.zappit.net/cnet/zappit_full.exe

Error is Win32 Trojan-gen; here is a screenshot of the error: http://www.zappit.net/cnet/avast.jpg

If you prefer zip I have uploaded it: http://www.zappit.net/cnet/zappit_full.zip

[i]Here are the instructions I followed from this forum:
[Mini Sticky] False Positives
« on: October 10, 2004, 07:43:03 AM » Quote


I wrote this as a small tutorial on how to treat false positives.
It might help if you encounter any from time to time (i have only 1 in 1 year ).

If you encounter alert for which you think that it’s a false positive, do the following:

Check the file with this service:
http://virusscan.jotti.org

  • if file is detected with any other antivirus too (like Kaspersky), than its most probably not a false positive. Treat it with caution.
  • false positive files are usually detected as: Win32:Trojan-Gen
    (this usually happens because of strong generic detection)
  • if scan still shows that only avast! detects the file, then it could be a virus detected only by avast!. If you think that it’s still a false positive,then follow the next step:

Pack the “infected” file into ZIP archive and lock it with password “virus” (without quotes) and attach it to e-mail.
Write the same password inside mail body, so Alwil virus analysts will know the password right away without guessing.
You can also add web address to that file (or webpage of the file/program) if it’s on the internet.
Add your own note on why do you think that it’s a false positive. Every info helps Alwil staff.
Send the mail to: virus@avast.com

You’ll probably get a reply mail about file info (if it was really a false positve) after some time.
If not, check the file with Explorer extension when new VPS is released.
This way you’ll know if the false positive was fixed.

Until then, you can add the “false positive” file into exclusions:
Left click on “a” ball next to the clock and select Standard Shield.
Click Customize… and select Advanced tab.
Now just enter full path (path plus filename with extension) into the line and press [Enter] on keyboard.

This will exclude the file from scan, so you can use it untill false positive is resolved. Do this with caution or if you’re 100% sure that the alert was false positive for that file.

Alwil staff deals with false positives very fast, so they are usually fixed on next VPS update, or even immediately if the false positive is found in any widely used program.[/i]

Thanks!

Well I believe there is no direct response unless they require more information and this isn’t usual. Though I’m surprised it hasn’t been resolved as they are normally quick to resolve any FP.

Thanks for trying to help; it is frustrating for this to happen as we have spent many years building up a great reputation and unfortunately, many will assume it is a trojan and not much we can do.

I resent all the info to virus@avast.com in hopes of a response. I had hoped avast staff monitored the forum more closely.

8

I have downloaded the zip and put it in the avast chest and emailed it from there (took ages on dial-up) as submissions from the chest are filtered. Hopefully that may generate a quicker response.

You’re a doll… thanks!!
8

I was told that this FP is already solved in the latest update.
Can you please verify it?

Thanks and apologies for the slower response.

Indeed it is, with VPS 0778-0

Just wanted to thank everyone here on the forum for their help and thanks to Avast for updating and fixing the problem. All of us at Cloudeight appreciate it very much!

8
http://thundercloud.net

No problem, glad I could help.

A belated welcome to the forums.