Wilders Security Forums  

Go Back   Wilders Security Forums > Official Returnil Support Forum > General Returnil discussions
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old February 20th, 2010, 01:35 AM
pdr pdr is offline
Infrequent Poster
 
Join Date: Aug 2006
Posts: 14
Default False Positives

Hi Returnil People:

If I the Virus Scan finds a file that it flags as suspicious, is there some way that I can check if that file is a false positive or not?

Thanks,

Peter
  #2  
Old February 20th, 2010, 09:27 AM
cyberdiva cyberdiva is offline
Regular Poster
 
Join Date: May 2007
Posts: 71
Default Re: False Positives

Hi, Peter. You can upload the suspect file to VirusTotal at http://www.virustotal.com/. It runs it by about 40 different antivirus programs, including most of the well-known ones, and reports what each of them finds.

I might add that I found Returnil's Anti-Virus very unreliable. It claimed that I had a number of viruses, trojans, and the like when all other security programs I use said the files were fine. I finally disabled Returnil's AV.
  #3  
Old February 22nd, 2010, 10:12 AM
pdr pdr is offline
Infrequent Poster
 
Join Date: Aug 2006
Posts: 14
Default Re: False Positives

Hello Cyberdiva:

I wonder if there are others who have similar experiences with the Virus Scan. I did, in fact, use the Virus Total web-site to verify the files in question. The results there made me wonder if the Returnil people are doing some checking for false positivies, as do many anti-virus programs.

Anyhow, I am glad that you pointed out the existence of the VirusTotal web-site. It can be used to check any file on your system that you might suspect or wish to verify.

Peter
  #4  
Old February 22nd, 2010, 11:35 AM
Coldmoon's Avatar
Coldmoon Coldmoon is offline
Returnil Moderator
 
Join Date: Sep 2006
Location: North Carolina USA
Posts: 2,743
Default Re: False Positives

Hi,
The new build we are testing now includes a feature where the alert messages can be exported to file. The file will be in XML format and can be sent with your false positive detection reports to our support address. Also, please check your VG sensitivity settings to see if the files are also detected using the standard definitions rather than the advanced analysis setting.

Are they detected at the lower setting?

Mike
__________________
Returnil: The Real Security!
Follow us on Facebook
  #5  
Old February 22nd, 2010, 11:54 AM
pdr pdr is offline
Infrequent Poster
 
Join Date: Aug 2006
Posts: 14
Default Re: False Positives

Quote:
Originally Posted by Coldmoon
Hi, ... please check your VG sensitivity settings to see if the files are also detected using the standard definitions rather than the advanced analysis setting.

Are they detected at the lower setting?

Mike


Hi Mike:

Thank you for replying to my questions.

The Virus Guard Preferences are set at (I believe) the default: in the Reat-time Advanced Malware Analysis mode:

The filled-in button is "Only proven detection rules (Recommended: This mode will identify only malicious programs)"

The button NOT filled in is: "Do not use advanced rules analysis."


In the section for Data Collection Policy, I have chosen: "Ask me for approval when parts of a malicious program are required for analysis".

Although I would have liked to know if the files identified are, in fact, maicious, I am do not recall being asked by the program to send any programs (files?) to Returnil for analysis. So I am still not sure if there is a process for verifying p[ossible False Positives.

Peter
  #6  
Old February 22nd, 2010, 01:27 PM
Coldmoon's Avatar
Coldmoon Coldmoon is offline
Returnil Moderator
 
Join Date: Sep 2006
Location: North Carolina USA
Posts: 2,743
Default Re: False Positives

Hi Peter,
The data collection works independently and is sending information about behaviors and/or files of interest for more research. It does not send the files detected as they are...detected.

The new build (check your PM) allows you to export your alert messages so you can send that information to us more easily in false positive detections scenarios. Try the new build and send us a copy of the detection alerts (new green button on the messages when opened) and the files detected (in a password protected ZIP or RAR archive) so our (and Frisk's) team can investigate the issue in more detail.

Thanks
Mike
__________________
Returnil: The Real Security!
Follow us on Facebook
  #7  
Old February 22nd, 2010, 04:18 PM
cyberdiva cyberdiva is offline
Regular Poster
 
Join Date: May 2007
Posts: 71
Default Re: False Positives

Quote:
Originally Posted by pdr
I wonder if there are others who have similar experiences with the Virus Scan.
Hi, Peter. As I recall, when I was having this problem, I encountered others on the forum who were also experiencing what they suspected were false positives. But even if I hadn't found other people, I'd have turned off Virus Guard. It produced more false positives in the few days that I had it active than all my other security software combined had produced in the 3 1/2 years I've used this computer. And I did not have Virus Guard set at a very high level.

I'm glad to hear that Returnil is going to take more active steps to monitor the false-positive problem. However, I have no plans to reinstate Virus Guard. I have very little patience for false positives--they waste my time and raise my anxiety level. And since I feel I have excellent protection from my other security software, I see no reason to use Virus Guard.
  #8  
Old February 22nd, 2010, 05:56 PM
Coldmoon's Avatar
Coldmoon Coldmoon is offline
Returnil Moderator
 
Join Date: Sep 2006
Location: North Carolina USA
Posts: 2,743
Default Re: False Positives

Quote:
Originally Posted by cyberdiva
Hi, Peter. As I recall, when I was having this problem, I encountered others on the forum who were also experiencing what they suspected were false positives. But even if I hadn't found other people, I'd have turned off Virus Guard. It produced more false positives in the few days that I had it active than all my other security software combined had produced in the 3 1/2 years I've used this computer. And I did not have Virus Guard set at a very high level.

I'm glad to hear that Returnil is going to take more active steps to monitor the false-positive problem. However, I have no plans to reinstate Virus Guard. I have very little patience for false positives--they waste my time and raise my anxiety level. And since I feel I have excellent protection from my other security software, I see no reason to use Virus Guard.

Hi,
Nor should you feel compelled to use it if it is not useful in your setup. It is there to do what it does, not because we require its use. Further, we have been investigating every FP report we get and will continue to do so...

Mike
__________________
Returnil: The Real Security!
Follow us on Facebook
  #9  
Old February 22nd, 2010, 07:48 PM
pdr pdr is offline
Infrequent Poster
 
Join Date: Aug 2006
Posts: 14
Default Re: False Positives

Hi Cyberdiva:

I understand the stress of having a lot of virus warnings, having had quite a few of them with the Returnil virus scans. However, it seems that Mike's offer will allow me to report some of them, for more direct study than that available via Virus Total or other general analysis.

So I will try that out. I hope that I will be able to get some feedback on the files that I do submit; then I will feel a bit more confident that the positives really are false. And hopefully, that will improve the virus scanning machine that Returnil is using.

But I have to admit that I really hate spendiing time on this sort of thing. I would wish all kinds of plagues to personally descend on those creeps that invent these insidious malware programs that cause so much distress to others. (End of rant.)

Peter
 

Wilders Security Forums > Official Returnil Support Forum > General Returnil discussions « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 04:46 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums