Should "false" Positives Be Ignored?

seekermeister

Old School
Guru
Gold Member
VIP
Local time
11:05 PM
Messages
6,618
Location
Indian Territory
I just installed an update for a video recorder that I use (GETFlv) and Comodo popped an alert for the Trojware.Win32.Spy.Banker.Gen@1. Most of what I found Googling are non-English returns, but one I found from Virus Total indicated that only 4 out of 43 scanners balked on this program, and each of those four identified it by a different name.

https://www.virustotal.com/file/460...840daad22fe315b8313fdebfab9de0c53af/analysis/

That makes it appear that it is a false positive, but considering the nature of the trojan that it sees:

Steal bank account information from your PC, and:
The Trojan can be configured to perform any of the following actions:
Captures Screenshots
Checks the title of active Internet Explorer Windows to see if it matches any preconfigured strings.
Delete all the URL cache and cookies.
Display a fake login screen for certain South American banking sites
Gather email addresses
May display a preconfigured message box
May search for and delete predetermined files
Record keystrokes
Register itself as a service
Replace the contents of hosts file
Search for and deletes files
Send an email with the collected information to the remote attacker
Monitor active Internet Explorer windows for user access to various web sites, particularly those of financial institutions.
I would like to be sure. Some might say to just not use the program, but it is quite expensive, and one that I use almost daily, so I wouldn't like that idea.

Am I just making too much of it or not?
 

My Computer

Computer Manufacturer/Model Number
DIY
OS
W7x64 Pro, SuSe 12.1/** W7 x64 Pro, XP MCE
CPU
Phenom II 1090T w/Noctua NH-D14 /**4400+ X2 w/CM Hyper TX 3
Motherboard
ASRock 890FX Deluxe 4/**A8N-SLI
Memory
2 x 2GB Patriot PGS34g1600LLKA/**4x1GB Corsair VS
Graphics Card(s)
EVGA GTX460 SC/**EVGA 8800GTS
Sound Card
Asus Xonar D2X/**Xonar D1
Monitor(s) Displays
Acer X233H, Dell E152FPc /**LG M237-WD
Screen Resolution
1920x1080 & 1024x768/**1980x1080
Hard Drives
WDC 2TB, 1.5TB, 1TB, 500GB,Seagate 500GB , Maxtor 80GB /**500GB Seagate & WDC 1TB Black
PSU
CM RS600 w/ APC BX1000G/**Antec 500 TP w/ APC BX1000
Case
HAF922/**Antec 1040IIB
Cooling
3x200mm, 1x140 and 1x120mm/**5x80mm fans
Keyboard
Logitech Media USB/**Saitek Eclipse
Mouse
Cordless Trackman Wheel/**Ditto
Internet Speed
3.3Mbps
Other Info
SB 560 5.1 w/ Sennheiser RS140/**Creative T20 speakers, Dvico FusionHDTV7 Gold RT, Cisco E3000, HP 5510V AIO, Linksys E3000, Belkin F5U237 hub and **F5D8055 adapter
(** = 2nd rig)
Well... the trouble is, figureing out if it is really false or not :(.

Of course if it is a false positive then yes you can ignore it, but how do you know? Frequently with new virii or morphing ones, only a handfull or even one av scanner will even pick it up and it may be legit. On the other hand I've written code myself that managed to trip at virus scanner by accident in the past. There are now so many signatures and code is a fairly random set of bytes that it does just happen sometimes.

The only way to really get to the bottom of it is to contact the maker of the software and work it out with them... It's not unheard of for a companies build machine to get infected and then produce infected files for DL :(

Edit: Just a couple months ago I got a driver disk for a 4x2 HDMI switch that MSE flagged as having a virus on in the driver on the CD! Company was not responsive and so I just didn't install it...
 

My Computer

Computer Manufacturer/Model Number
Scratch built
OS
Windows 7 x64 Ultimate
CPU
i7 960
Motherboard
Asus P6X58D
Memory
12 Gig Corsair Dominator
Graphics Card(s)
Nvidia 480
Sound Card
Maudio Delta 44 + breakout box
Monitor(s) Displays
Dell UltraSharp U2410 24in and Samsung 21 dual monitors
Screen Resolution
1920x1200 and 1280x1024
Hard Drives
Primary: Intel X-25M G2 160G SSD
Secondary: Segate baracuda 1.0 TB
HDs in AHCI mode.
PSU
Corasair TX850
Case
Cooler Master HAF
Cooling
Corsair H50
Keyboard
Logitech G15 + N52 game pad
Mouse
Logitech MX518
Internet Speed
15kbs down 4.5kbps up
Other Info
WEI 7.6
CPU & RAM 7.6
Graphics 7.9
Hard disk 7.7
I don't use Comodo, but does it have a link to report what it found as a virus inside it's scanner program?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Well... the trouble is, figureing out if it is really false or not :(.

Of course if it is a false positive then yes you can ignore it, but how do you know? Frequently with new virii or morphing ones, only a handfull or even one av scanner will even pick it up and it may be legit. On the other hand I've written code myself that managed to trip at virus scanner by accident in the past. There are now so many signatures and code is a fairly random set of bytes that it does just happen sometimes.

The only way to really get to the bottom of it is to contact the maker of the software and work it out with them... It's not unheard of for a companies build machine to get infected and then produce infected files for DL :(

Edit: Just a couple months ago I got a driver disk for a 4x2 HDMI switch that MSE flagged as having a virus on in the driver on the CD! Company was not responsive and so I just didn't install it...

Yes, I sent an email to them about this, but the problem with that, is if the programmers were the type that would design their program for malicious purposes, they wouldn't admit it. I have not found that this company is particularly responsive, regardless of the nature of an enquiry, but since I have been using this program for a couple of years, I tend to doubt that the program is malicious. It's just that rather than have any suspicion, I would like to feel certain that it is safe.
 

My Computer

Computer Manufacturer/Model Number
DIY
OS
W7x64 Pro, SuSe 12.1/** W7 x64 Pro, XP MCE
CPU
Phenom II 1090T w/Noctua NH-D14 /**4400+ X2 w/CM Hyper TX 3
Motherboard
ASRock 890FX Deluxe 4/**A8N-SLI
Memory
2 x 2GB Patriot PGS34g1600LLKA/**4x1GB Corsair VS
Graphics Card(s)
EVGA GTX460 SC/**EVGA 8800GTS
Sound Card
Asus Xonar D2X/**Xonar D1
Monitor(s) Displays
Acer X233H, Dell E152FPc /**LG M237-WD
Screen Resolution
1920x1080 & 1024x768/**1980x1080
Hard Drives
WDC 2TB, 1.5TB, 1TB, 500GB,Seagate 500GB , Maxtor 80GB /**500GB Seagate & WDC 1TB Black
PSU
CM RS600 w/ APC BX1000G/**Antec 500 TP w/ APC BX1000
Case
HAF922/**Antec 1040IIB
Cooling
3x200mm, 1x140 and 1x120mm/**5x80mm fans
Keyboard
Logitech Media USB/**Saitek Eclipse
Mouse
Cordless Trackman Wheel/**Ditto
Internet Speed
3.3Mbps
Other Info
SB 560 5.1 w/ Sennheiser RS140/**Creative T20 speakers, Dvico FusionHDTV7 Gold RT, Cisco E3000, HP 5510V AIO, Linksys E3000, Belkin F5U237 hub and **F5D8055 adapter
(** = 2nd rig)
I don't use Comodo, but does it have a link to report what it found as a virus inside it's scanner program?
Yes, I did send it to them, but I'm more interested in a report to me, than to them.
 

My Computer

Computer Manufacturer/Model Number
DIY
OS
W7x64 Pro, SuSe 12.1/** W7 x64 Pro, XP MCE
CPU
Phenom II 1090T w/Noctua NH-D14 /**4400+ X2 w/CM Hyper TX 3
Motherboard
ASRock 890FX Deluxe 4/**A8N-SLI
Memory
2 x 2GB Patriot PGS34g1600LLKA/**4x1GB Corsair VS
Graphics Card(s)
EVGA GTX460 SC/**EVGA 8800GTS
Sound Card
Asus Xonar D2X/**Xonar D1
Monitor(s) Displays
Acer X233H, Dell E152FPc /**LG M237-WD
Screen Resolution
1920x1080 & 1024x768/**1980x1080
Hard Drives
WDC 2TB, 1.5TB, 1TB, 500GB,Seagate 500GB , Maxtor 80GB /**500GB Seagate & WDC 1TB Black
PSU
CM RS600 w/ APC BX1000G/**Antec 500 TP w/ APC BX1000
Case
HAF922/**Antec 1040IIB
Cooling
3x200mm, 1x140 and 1x120mm/**5x80mm fans
Keyboard
Logitech Media USB/**Saitek Eclipse
Mouse
Cordless Trackman Wheel/**Ditto
Internet Speed
3.3Mbps
Other Info
SB 560 5.1 w/ Sennheiser RS140/**Creative T20 speakers, Dvico FusionHDTV7 Gold RT, Cisco E3000, HP 5510V AIO, Linksys E3000, Belkin F5U237 hub and **F5D8055 adapter
(** = 2nd rig)
I wasn't suggesting that the programmers themselves did it on purpose, but it's possible that they unknowingly have an infected build machine OR it may be that by pure accident this compile triggers the signature detection.

In both cases there may be something they can do to fix it. Like I said, it happened to me at an old company and we were notified and we fixed the problem and issued an update. (Though I admit that I seem to work for the only companies in the universe that actually care when someone calls in with a problem).
 

My Computer

Computer Manufacturer/Model Number
Scratch built
OS
Windows 7 x64 Ultimate
CPU
i7 960
Motherboard
Asus P6X58D
Memory
12 Gig Corsair Dominator
Graphics Card(s)
Nvidia 480
Sound Card
Maudio Delta 44 + breakout box
Monitor(s) Displays
Dell UltraSharp U2410 24in and Samsung 21 dual monitors
Screen Resolution
1920x1200 and 1280x1024
Hard Drives
Primary: Intel X-25M G2 160G SSD
Secondary: Segate baracuda 1.0 TB
HDs in AHCI mode.
PSU
Corasair TX850
Case
Cooler Master HAF
Cooling
Corsair H50
Keyboard
Logitech G15 + N52 game pad
Mouse
Logitech MX518
Internet Speed
15kbs down 4.5kbps up
Other Info
WEI 7.6
CPU & RAM 7.6
Graphics 7.9
Hard disk 7.7
Kharma or kismet?
 

My Computer

Computer Manufacturer/Model Number
DIY
OS
W7x64 Pro, SuSe 12.1/** W7 x64 Pro, XP MCE
CPU
Phenom II 1090T w/Noctua NH-D14 /**4400+ X2 w/CM Hyper TX 3
Motherboard
ASRock 890FX Deluxe 4/**A8N-SLI
Memory
2 x 2GB Patriot PGS34g1600LLKA/**4x1GB Corsair VS
Graphics Card(s)
EVGA GTX460 SC/**EVGA 8800GTS
Sound Card
Asus Xonar D2X/**Xonar D1
Monitor(s) Displays
Acer X233H, Dell E152FPc /**LG M237-WD
Screen Resolution
1920x1080 & 1024x768/**1980x1080
Hard Drives
WDC 2TB, 1.5TB, 1TB, 500GB,Seagate 500GB , Maxtor 80GB /**500GB Seagate & WDC 1TB Black
PSU
CM RS600 w/ APC BX1000G/**Antec 500 TP w/ APC BX1000
Case
HAF922/**Antec 1040IIB
Cooling
3x200mm, 1x140 and 1x120mm/**5x80mm fans
Keyboard
Logitech Media USB/**Saitek Eclipse
Mouse
Cordless Trackman Wheel/**Ditto
Internet Speed
3.3Mbps
Other Info
SB 560 5.1 w/ Sennheiser RS140/**Creative T20 speakers, Dvico FusionHDTV7 Gold RT, Cisco E3000, HP 5510V AIO, Linksys E3000, Belkin F5U237 hub and **F5D8055 adapter
(** = 2nd rig)
Back
Top