Author Topic: ===> False Positives <===  (Read 385031 times)

0 Members and 3 Guests are viewing this topic.

Reply #375July 16, 2019, 05:35:53 PM

Mops21

  • Jr. Member

  • Offline
  • **

  • 64
  • Reputation:
    0
    • View Profile
Re: ===> False Positives <===
« Reply #375 on: July 16, 2019, 05:35:53 PM »
Hi Mops21,

Thanks for your feedback.
Theses files are all false positives, currently detected by MalPE detection engine (still in beta).

Could you please make an archive containing a copy of all of them and attach it with your next reply ?
Analysing them, will help us improving the detection accuracy.

Regards.

Hi

Thank you very much for your Infos

I will send you the Files part via part to you

https://www.sendspace.com/file/ohf7av

With best Regards
Mops21

Reply #376July 17, 2019, 12:18:29 AM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: ===> False Positives <===
« Reply #376 on: July 17, 2019, 12:18:29 AM »
Hi Mops21,

Thank you very much.

Regards.

Reply #377July 19, 2019, 05:19:14 PM

Mops21

  • Jr. Member

  • Offline
  • **

  • 64
  • Reputation:
    0
    • View Profile
Re: ===> False Positives <===
« Reply #377 on: July 19, 2019, 05:19:14 PM »
Hi

Here are 2 more Samples for you

https://www.sendspace.com/file/eyfi17

Can you add a submitz Files Button into the Rogue Anti-Malware please
And you can add a function to pack all detected Files into a zip Folder please for send them via email or via forum

With best Regards
Mops21

Reply #378July 19, 2019, 11:55:52 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: ===> False Positives <===
« Reply #378 on: July 19, 2019, 11:55:52 PM »
Hi Mops21,

Thanks for your feedback.
We will add your suggestion to our roadmap.

Regards.

Reply #379July 20, 2019, 06:41:18 PM

Mops21

  • Jr. Member

  • Offline
  • **

  • 64
  • Reputation:
    0
    • View Profile
Re: ===> False Positives <===
« Reply #379 on: July 20, 2019, 06:41:18 PM »
Hi

Thank you very much for your Infos

Here is the Scanlog of the Files

And can you add this Option or function to Rogue Anti-Malware please

Can you add a go to the detected Filepath of the File please

With best Regards
Mops21

Reply #380July 20, 2019, 11:21:11 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: ===> False Positives <===
« Reply #380 on: July 20, 2019, 11:21:11 PM »
Hi Mops21,

You are welcome.
This will be added to the roadmap as well.

Regards.

Reply #381August 03, 2019, 11:31:56 AM

Lemonsfluffynoodles

  • Newbie

  • Offline
  • *

  • 4
  • Reputation:
    0
    • View Profile
Re: ===> False Positives <===
« Reply #381 on: August 03, 2019, 11:31:56 AM »
Hi I just had a detection with google chrome called MalPe.99 somehow I deleted the scan log, but thought I would post anyway, is this a false positive?

Reply #382August 03, 2019, 04:40:03 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: ===> False Positives <===
« Reply #382 on: August 03, 2019, 04:40:03 PM »
Hi Lemonsfluffynoodles,

Thanks for your feedback.
Without the scan log, it's not possible to tell, but there is a high probability that was a false positive.

Regards.

Reply #383August 07, 2019, 01:44:18 AM

Cdew112

  • Newbie

  • Offline
  • *

  • 2
  • Reputation:
    0
    • View Profile
Re: ===> False Positives <===
« Reply #383 on: August 07, 2019, 01:44:18 AM »
hey ran into this yesterday equilizer.apo  is from fileforge which is legit. MWB and HMP didnt pick this up so not sure if false-positive or not.

Reply #384August 07, 2019, 02:48:21 AM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: ===> False Positives <===
« Reply #384 on: August 07, 2019, 02:48:21 AM »
Hi Cdew112,

Welcome to Adlice.com Forum.
This is indeed a false positive. It will be whitelisted as soon as possible.

Regards.

Reply #385August 28, 2019, 02:24:12 PM

Lemonsfluffynoodles

  • Newbie

  • Offline
  • *

  • 4
  • Reputation:
    0
    • View Profile
Re: ===> False Positives <===
« Reply #385 on: August 28, 2019, 02:24:12 PM »
Hi Is this a false positive ?

Reply #386August 28, 2019, 08:55:50 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: ===> False Positives <===
« Reply #386 on: August 28, 2019, 08:55:50 PM »
Hi Lemonsfluffynoodles,

Yes, these are false positives.

Quote
%localappdata%\Temp\7zS9460.tmp\N2080_FW_Upgrade_Tool_V003\GPCIDrv64.sys
%localappdata%\Temp\7zS9460.tmp\N2080_FW_Upgrade_Tool_V003\GPCIDrv64.sys
RogueKiller automatically detects loaded modules located in temporary folders as [Suspicious.Path].

Quote
%localappdata%\SLR VR Application\SLR_Data\Managed\SteamVR_Actions.dll
%localappdata%\SLR VR Application\SLR_Data\Managed\SteamVR.dll
%localappdata%\SLR VR Application\SLR_Data\Managed\Assembly-CSharp.dll
​​You have enabled RogueKiller MalPE engine, which uses a predictive AI model. The engine is still is in beta state and prone to false positives detection, like in your case.
For the time being, it's advised not to use it unless you know what you are doing.

Could you please make an archive of the three files listed above and attach it with your reply ?
Analysing thoses files will help us improve the MalPE engine.

Regards.

Reply #387September 11, 2019, 07:42:18 PM

techknowledge

  • Newbie

  • Offline
  • *

  • 5
  • Reputation:
    0
    • View Profile
Re: ===> False Positives <===
« Reply #387 on: September 11, 2019, 07:42:18 PM »
%ProgramFiles%\Pulseway\*.ps1
All of my powershell scripts that are running get killed by roguekiller.

roguekillercmd arguments: -scan "-reportformat txt -reportpath $ThisApplicationLogFile -portable-license $roguekillerlicense" -autodelete -no_interact

Thank you for your time!
« Last Edit: September 11, 2019, 07:45:55 PM by techknowledge »

Reply #388September 11, 2019, 09:45:35 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: ===> False Positives <===
« Reply #388 on: September 11, 2019, 09:45:35 PM »
Hi techknowledge,

Welcome to Adlice.com Forum and thanks for your feedback.
Could you please attach a scan report with your next reply ?

Regards.

Reply #389September 27, 2019, 07:35:51 PM

eurekaa

  • Newbie

  • Offline
  • *

  • 3
  • Reputation:
    0
    • View Profile
Re: ===> False Positives <===
« Reply #389 on: September 27, 2019, 07:35:51 PM »
A false positive error, or in short a false positive, commonly called a "false alarm", is a result that indicates a given condition exists, when it does not.