I hate false positives

Page 1 of 2 12 LastLast

  1. Posts : 451
    Windows 7 Home Premium x64
       #1

    I hate false positives


    Malware is bad, but false positives are almost as bad, in my experience.

    I know no single antimalware is perfect, and free programs aren't near the quality of pay programs, and you often have to run 2 or more to find everything. MSE is.... well, it's free and part of Window sand while it offers live protection and is okay at catching a lot of bad stuff, I've had a few false positives with it, generally jpeg files and it only happens on occasion. I think it's an instance of the new definitions set having a bug that flags an image file the second it's created on the hard drive. It's happened... maybe 3 times for me and I know the files were safe otherwise.

    I haven't had a malware infection for months. I was clean as of March, at the very least. I run MSE, Malwarebytes and SAS, with TDSSkiller on hand. I run a scan once a week and, at most, I find the same few tracking cookies. Between Adblock Plus, NoScript and Spybot's immunizations, I'm dodging the stuff the infects through browsers.

    This morning I was playing freeware game Gungirl 2 on my secondary Dell XP computer, and on exiting the game I get a popup that says "stdst.exe has stopped working". A program not quitting right on exit isn't a big deal in itself, I've gotten somewhat used to it for certain games, especially freeware titles... Google that up and find lots of mentions of malware. So I have to run scans on both PCs and files on the Dell were taken off the Gateway.

    EXCEPT I'm not infected as it seems stdst.exe is also a legit part of Multimedia Fusion and games made with it tend to have that internal program name- which likely explains why the program's icon in the notice box was that of the game. So I spent 15 minutes freaking out over nothing, apparently.
      My Computer


  2. Posts : 6,330
    Multi-Boot W7_Pro_x64 W8.1_Pro_x64 W10_Pro_x64 +Linux_VMs +Chromium_VM
       #2

    I agree false positives are a problem.
    When you find a questionable file, you can upload it to VirusTotal.
    That will scan it with a LOT of scanners.
    If only 1 or 2 show an issue while 40+ say it's ok, it's probably an FP.
    https://www.virustotal.com/en/

    Upload your stdst.exe and see what VT reports...
      My Computer


  3. Posts : 25,847
    Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
       #3

    David could you explain the method of uploading to VirusTotal. I have never got it to work.
      My Computer


  4. Posts : 10,485
    W7 Pro SP1 64bit
       #4

    Layback Bear said:
    David could you explain the method of uploading to VirusTotal. I have never got it to work.
    If by "never got it to work" you mean that you encounter a problem during the upload process - then that is happening to several people that use IE10. The work around is to try again or use another browser.

    I hate false positives-ie10-virustotal.png
      My Computer


  5. Posts : 25,847
    Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
       #5

    I use Firefox.
    Let me try to explain.
    Lets say I want to upload aaaaa.exe
    Where on my computer do I copy/paste aaaaa.exe to able to upload to that site. It won't let me just type it in or copy/paste.
    What method do you use?
      My Computer


  6. Posts : 10,485
    W7 Pro SP1 64bit
       #6

    I select Choose File...

    I hate false positives-ie10-virustotal.png

    ...and then navigate my way to the file.
      My Computer


  7. Posts : 6,330
    Multi-Boot W7_Pro_x64 W8.1_Pro_x64 W10_Pro_x64 +Linux_VMs +Chromium_VM
       #7

    I use the Choose File and navigate to it...same as Usernameissues
    I use Firefox...
      My Computer


  8. Posts : 6,330
    Multi-Boot W7_Pro_x64 W8.1_Pro_x64 W10_Pro_x64 +Linux_VMs +Chromium_VM
       #8

    I just tried Left mouse clicking in the VT file selection field.
    It opened the File Upload (Explorer) window to the directory I last uploaded a file from.
      My Computer


  9. Posts : 25,847
    Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
       #9

    I'm thick headed so Bear with me. The file is not on my computer.
    I have to copy/paste from a post and put it somewhere and then upload to virustotal.
    This from post #1
    stdst.exe

    I know I'm missing some stupid little step somehow.
      My Computer


  10. Posts : 6,330
    Multi-Boot W7_Pro_x64 W8.1_Pro_x64 W10_Pro_x64 +Linux_VMs +Chromium_VM
       #10

    If I understand correctly, you want to scan a file that is not on your computer.
    I've never done that, but I found this in the VT documentation:
    They have an "Uploader" utility program you can install that may do what you want.

    Fetching and scanning online files

    Another handy option will have VirusTotal fetch and scan an online file without you even having to download it first. Type in the URL, or right-click it and choose "Copy link location" to cut and paste it, and then click the Get and upload button. The file will skip through your computer's memory, but will never be saved to your hard drive (by default). You will get the usual list of results and can then decide whether you want the download.
    Source: https://www.virustotal.com/en/docume...total-uploader
      My Computer


 
Page 1 of 2 12 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 03:13.
Find Us