False Positive


[ Follow Ups ] [ Post Followup ] [ Signature.net Forum ]

Posted by jim guerber on January 22, 2010 at 09:10:19:

In Reply to: Re: cometanywhere infected? posted by Marc Shevick on January 21, 2010 at 15:16:43:

We take any suspicion of a virus or any sort of malware in our programs very seriously.

I scanned the current release of cosp.exe and the 2007 build 388 version with

http://virscan.org

The current version showed no virus detected. The old one,built 2 years ago, when passed through the CA anti-virus checker, showed the trojan horse twizzor. COSP builds file names for print files (PDF and HTML) from elements from your program, etc. This behavior may have been detected as a trojan horse behavior by CA.

Here is a copy of the report. As you can see, only CA is suspicious of this file.

Scanner results
Scanner results :   3% Scanner(s) (1/37) found malware!
Time :   2010/01/22 07:06:01 (HST)
Scanner Engine Ver Sig Ver Sig Date Scan result Time
a-squared 4.5.0.8 20100122204231 2010-01-22
-
7.660
AhnLab V3 2010.01.22.03 2010.01.22 2010-01-22
-
2.071
AntiVir 8.2.1.146 7.10.3.43 2010-01-22
-
0.180
Antiy 2.0.18 20100122.3738848 2010-01-22
-
0.124
Arcavir 2009 201001211452 2010-01-21
-
0.079
Authentium 5.1.1 201001220552 2010-01-22
-
5.319
AVAST! 4.7.4 100122-0 2010-01-22
-
0.047
AVG 8.5.720 271.1.1/2638 2010-01-22
-
0.308
BitDefender 7.81008.4894620 7.30001 2010-01-22
-
4.308
CA (VET) 35.1.0 7251 2010-01-21
Win32/Swizzor.A!generic(suspicious)
5.854
ClamAV 0.95.2 10324 2010-01-22
-
0.194
Comodo 3.13.579 3409 2010-01-22
-
1.067
CP Secure 1.3.0.5 2010.01.22 2010-01-22
-
0.105
Dr.Web 4.44.0.9170 0004.00.00 0004-00-00
-
9.119
F-Prot 4.4.4.56 20100121 2010-01-21
-
3.472
F-Secure 7.02.73807 2010.01.22.09 2010-01-22
-
9.834
Fortinet 11.405- 11.405 2010-01-22
-
0.384
GData 19.10081/19.693 20100122 2010-01-22
-
6.909
ViRobot 20100122 2010.01.22 2010-01-22
-
0.440
Ikarus T3.1.01.80 2010.01.22.75018 2010-01-22
-
5.466
JiangMin 13.0.900 2010.01.22 2010-01-22
-
10.218
Kaspersky 5.5.10 2010.01.22 2010-01-22
-
0.186
KingSoft 2009.2.5.15 2010.1.22.22 2010-01-22
-
1.212
McAfee 5.3.00 5868 2010-01-21
-
3.739
Microsoft 1.5302 2010.01.21 2010-01-21
-
7.307
Norman 6.01.09 6.01.00 2010-01-16
-
4.008
Panda 9.05.01 2010.01.21 2010-01-21
-
0.596
Trend Micro 9.120-1004 6.796.04 2010-01-22
-
0.045
Quick Heal 10.00 2010.01.21 2010-01-21
-
1.524
Rising 20.0 22.31.04.04 2010-01-22
-
1.086
Sophos 3.03.0 4.49 2010-01-22
-
3.255
Sunbelt 3.9.2392.2 5631 2010-01-21
-
4.631
Symantec 1.3.0.24 20100112.005 2010-01-12
-
0.004
nProtect 20100122.01 6971919 2010-01-22
-
4.641
The Hacker 6.5.0.9 v00159 2010-01-22
-
0.777
VBA32 3.12.12.1 20100121.1001 2010-01-21
-
2.870
VirusBuster 4.5.11.10 10.119.16/1987150 2010-01-22
-
2.850



Follow Ups:



Post a Followup

Name:
E-Mail:

Subject:

What is the name of the main Signature System's Product?  

Comments:

Optional Link URL:
Link Title:
Optional Image URL:

You may attach up to 5 files to your followup (see below):





Each file can be a maximum of 1MB in length Uploaded files will be purged from the server on a regular basis.


[ Follow Ups ] [ Post Followup ] [ Signature.net Forum ]