PDA

View Full Version : True Positive at Prevx database?


GabolaN
March 12th, 2009, 10:14 PM
Hi there

I found on Prevx database the folowwing file:



http://www.prevx.com/filenames/993880321557136888-0/MSNCLEANER2EEXE.html (http://www.prevx.com/filenames/993880321557136888-0/MSNCLEANER2EEXE.html)


If we are talking about the anti-malware tool, wich is in fact called MSNCleaner.exe, it´s surely a false positive. I run a EDGE scan today and the program didn´t found the MSNCLEANER.EXE, so I strongly recomend to up-to-date that file on the database.


Cheers


EDIT: Is "True positive" correct? How should it be? In spanish we know these phrases as "Falsos positivos" and "Falsos Negativos". Many thanks.-

PrevxHelp
March 12th, 2009, 10:21 PM
Hello,
Some infections use the same filename as legitimate programs - we have thousands of programs named "MSNCleaner.exe", the database just picks the best match which currently seems to be malicious.

If you do encounter a MSNCleaner.exe which is found by Edge or CSI that you think is clean, please let us know.

GabolaN
March 12th, 2009, 10:44 PM
Right. Many thanks, I passed EDGE on the true malware tool and didnt detected, so everithing was just OK. I´ll keep informing you if I find something wrong.

Have a nice day an many thanks


EDIT: Is "True positive" correct? How should it be? In spanish we know these phrases as "Falsos positivos" and "Falsos Negativos"

PrevxHelp
March 12th, 2009, 11:00 PM
If a program is really not malicious but is found as malicious, that is considered a false positive. If a program is malicious but is not found as malicious, that is considered a false negative.

Hope that helps ;D

GabolaN
March 12th, 2009, 11:08 PM
Really helpfull! Done, phrases added to my english dictionary xD