View Full Version : Possible False Positive from AntiVir
pilotart
June 3rd, 2007, 07:49 AM
Just saw this informative post (http://www.wilderssecurity.com/showpost.php?p=1017879&postcount=224) from Stefan Kurtzhals AV Expert from AVIRA,
but did not want to add more off-topic to the AV-Comparatives Thread.
In seventeen months with AntiVir Classic's detection settings at maximum,
have had eight detections, four False Positive and four True Positive,
I am very pleased with this performance.
The scenerio described below *may* be the fifth FP for me.;D
I had visited and enjoyed the D5 video coverage (http://d5.allthingsd.com/20070530/video-steve-jobs-and-bill-gates-prologue/) of the complete Steve Jobs and Bill Gates interview
at the Wall Street Journal Executive Conference.
The Prologue and all seven parts were presented inside a Thumbnail sized Flash Player
(on my WUXGA 1920x1200 LCD).
Then I navigated (on same site) to the Video Presentations from D4 (http://d.wsj.com/images/d4/index.html) and now it said:
-{ Quote: "...and the videos are hosted courtesy of RealNetworks. To view the video clips, you’ll need the latest version of RealPlayer (http://www.real.com/player/?lang=en&btn=en/dwnld_88x31)." }-
Went through that link and downloaded RealPlayer and on install attempt,
got a HUER/Malware warning from the AntiVir's Guard and Quarantined the same, that ended the install.
That File and that URL have been sent to Suspicious Files (http://www.avira.com/en/support/submit_suspicious_files.html) at the AVIRA Support site.
Years ago, before AdWare/Spyware problems, I had installed RealPlayer, it wasn't MalWare, but it sure was AnnoyWare.
It installed on StartUp SysTray and would constantly (without asking) want to download and play for me,
content that It thought I should see.
Have also seen SpyBot flag something from RealPlayer (and it had never previously been on this system),
so perhaps that detection is not False Positive after all.
Londonbeat
June 3rd, 2007, 07:58 AM
I think I recall reading somewhere by Stefan that "HEUR/..." possible false positives may be fixed quicker if you send them to heuristik2[at]avira.com, I guess that address doesn't get the huge volume of samples that the main email address gets and that the email will go straight to those that are responsible for the heuristic, but saying that they're still quick if you mail the normal address IME
Mele20
June 3rd, 2007, 08:27 AM
I've had Real Player on my computers many times. Don't have it currently but I really like Rhapsody and that requires Real Player. I've never had a virus from installing Real Player. Years ago, it was very invasive though privacy wise. Then they changed the Privacy Policy after much criticism and actually had a very good privacy policy finally. Sadly though, the damage had been done and most wouldn't read the new policy and still thought Real Player was crap. It's ok. I prefer it to WMP, but I am not crazy about it (I basically use just Winamp unless I get a craving for Rhapsody and want to subscribe again for awhile). Real can be tamed so that it doesn't constantly want to run your life for you.
I read Stefan's post too and also didn't want to add more OT stuff to the AV Comparatives thread than I already had.
I downloaded Real Player just now but since I don't have Avira Guard installed all I could do was right click scan the installer which was ok. I didn't really want to install Real and then scan because I don't need the Player currently. If you do install it, watch it because it likes to steal your file associations and the last time I uninstalled it, it didn't uninstall very cleanly.
Mele20
June 3rd, 2007, 08:28 AM
-{ Quote: "I think I recall reading somewhere by Stefan that "HEUR/..." possible false positives may be fixed quicker if you send them to heuristik2[at]avira.com, I guess that address doesn't get the huge volume of samples that the main email address gets and that the email will go straight to those that are responsible for the heuristic, but saying that they're still quick if you mail the normal address IME" }-
Yes, Stefan said that and if you send them there they go directly to Stefan and you will hear back from him usually quickly.
pilotart
June 3rd, 2007, 09:01 AM
Thank You Mele20-{ Quote: "Years ago, it was very invasive though privacy wise. Then they changed the Privacy Policy after much criticism and actually had a very good privacy policy finally. Sadly though, the damage had been done and most wouldn't read the new policy and still thought Real Player was crap. It's ok. I prefer it to WMP" }-That was exactly the information I was hoping to get :)
I now have 'StartUp Monitor' (just have to remember to turn it off for Most Installs), but will leave it on if I install RealPlayer.
The Windows Media Player 11 does a great job for other Video, but guess it's that "hosted courtesy of RealNetworks..." that makes it unusable for those videos.
My desire to install it quickly vanished with the warning, may try it later and monitor carefully what is installed. :D
pilotart
June 5th, 2007, 05:06 PM
Received Tuesday morning from AVIRA Lab:::) -{ Quote: "We received the following archive files:
File ID Filename Size (Byte) Result
598358 469a1b17.qua 24.37 KB OK
A listing of files contained inside archives alongside their results can be found below:
File ID Filename Size (Byte) Result
598359 469a1b17.vir 24 KB CLEAN
Please find a detailed report concerning each individual sample below:
Filename Result
469a1b17.vir CLEAN
The file '469a1b17.vir' has been determined to be 'CLEAN'.
Overview" }-
A ReScan also now shows 'Clean' so it had already been corrected in today's Search Engine:)
Still doubt that i want to install that RealPlayer:dry:
Mele20
June 5th, 2007, 05:59 PM
-{ Quote: "Received Tuesday morning from AVIRA Lab:::)
A ReScan also now shows 'Clean' so it had already been corrected in today's Search Engine:)
Still doubt that i want to install that RealPlayer:dry:" }-
Good to see Avira fixed it so fast. My main beef with Real Player (since they did change the privacy policy a couple of years ago and I was so surprised that it actually was a good privacy policy when it had been very bad) is the support. I love Rhapsody. There is no other source that is so rich for music (at least the types of music I enjoy). But Rhapsody, over the years, has had problems and when I would try to get support from Real...what a nightmare! It is the worst support I have ever encountered. It never improves either. The horrible support is the reason I don't currently have Real Player. Eventually, I will again really want Rhapsody and may install Real again in the hopes that by now Rhapsody is trouble free so I won't ever need tech support or that if I do that support has been improved. I seriously doubt either has occured though.
Macstorm
June 5th, 2007, 08:49 PM
-{ Quote: "Good to see Avira fixed it so fast. My main beef with Real Player (since they did change the privacy policy a couple of years ago and I was so surprised that it actually was a good privacy policy when it had been very bad) is the support. I love Rhapsody. There is no other source that is so rich for music (at least the types of music I enjoy). But Rhapsody, over the years, has had problems and when I would try to get support from Real...what a nightmare! It is the worst support I have ever encountered. It never improves either. The horrible support is the reason I don't currently have Real Player. Eventually, I will again really want Rhapsody and may install Real again in the hopes that by now Rhapsody is trouble free so I won't ever need tech support or that if I do that support has been improved. I seriously doubt either has occured though." }-
When that time comes, you might want the lightweight RealPlayer Enterprise version (instead of annoying playerplus) http://forms.real.com/rnforms/products/tools/red/index.html
Mele20
June 5th, 2007, 09:47 PM
-{ Quote: "When that time comes, you might want the lightweight RealPlayer Enterprise version (instead of annoying playerplus) http://forms.real.com/rnforms/products/tools/red/index.html" }-
I don't know if that would work if you need Real for Rhapsody which is a player within Real Player. But if it would that would be nice. It would not solve the support problem though. Rhapsody player has problems (or has when I have used it) and support is so horrible, so frustrating that I have yanked Rhapsody and Real off my computer and sworn I would never use them again....but then time goes by and I miss Rhapsody and I think it has probably improved as a player (the sound and music have always been great) so I install it again and then have problems requiring tech support which is still abysmal.
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums