Team OS : Your Only Destination To Custom OS !!

Welcome to TeamOS Community, Register or Login to the Community to Download Torrents, Get Access to Shoutbox, Post Replies, Use Search Engine and many more features. Register Today!

Tips & Tricks VirusTotal false positive - How to know?

juanamm

Uploader
Uploader
Power User
✅ Verified Member
Member
Downloaded
5.7 GB
Uploaded
448.6 GB
Ratio
78.11
Seedbonus
134,973
Upload Count
217 (223)
Member for 5 years
VirusTotal false positive - How to know?



I am going to share some tips to help you know if a VirusTotal detection may or may not be a false positive.

Obviously this is not 100% certain as there are many virus writers who leave their Trojans or other malware undetectable, but it can be a good start when in doubt.

Always before the slightest doubt, install the program detected as malware in a VM or Windows Sandbox and monitor its behavior.

Here are the tips:
1)
You got it from the offical site, it's not impossible but unlikely to be bad

2) The antivirus that detects it is not one of the well-known ones, and it's the only one

3) Combine low detection rate with the age of the file (First Submission Time in the Details tab in VirusTotal): If it's a few months old, it's most likely clean. Old malware doesn't stay on low detection rates for that long.

4) Check the hash values of our download, we can go to the website of the developer of the program for which we have the installer and look for the MD5, SHA-1, SHA-256 code, etc. of its original installer. Once we have the two codes available, that of our downloaded file and that of the installer or software from the developer's official website, we can compare both and see if they match and our file is reliable or not.

5) Check if the file is signed and if that sign is valid. You also see that in the VirusTotal Details tab. Things like adware and unwanted programs can also be signed. But if you trust the company or organization that signed it, the file is most likely clean.


Example of a false positive:
vt_false_positive.png


vt_false_positive1.png


vt_false_positive2.png



How do I know that this detection is a false positive?


I have followed the advice shared above and I can assure you with high probability of certainty that it is a false positive because:

1) I am a beta tester for this company and have downloaded the file from a secure developer site.

2) AV that detects an adware is an unknown antivirus and it's the only one, does anyone know Jiangmin? The truth is the first time I see that AV.

3) The detection date and the file is new because it is a file that is in development, in this case the date is not useful.

4) I have compared the hashing algorithms of the downloaded file and they match those published by the developer on their website.

5) The file is signed, the signatures are valid and one of the signatures corresponds to that of the developer for which I am sure it is a legitimate file.



— Ok, this works when I download something from the official website of the author / developer / company, but what happens with the false positives of downloads from this forum?

— To know that, look at @Cyler's contribution below, it will be very helpful.
 
Last edited:

vdogeek

🤴 Super Admin
Uploader
Downloaded
93.5 GB
Uploaded
56.4 TB
Ratio
618.35
Seedbonus
8,558,674
Upload Count
1199 (1205)
Member for 9 years
Very well Put... Thank you @juanamm
 

Cyler

🤴 Super Admin
⚡OS Master
Downloaded
510.5 GB
Uploaded
24.5 TB
Ratio
49.16
Seedbonus
27,587
Upload Count
1 (1)
Member for 6 years
Very good info Juanamm, Just want to add that 2 more signs that a shown detection is a false positive which may apply more to our kind of software that we download from here.

1. The name itself. Often we will see a mix of the words, Something-Generic-something, Gen-something, PUA (Possible Unwanted, Application), Hacktool-xxx, Malicious-xxxx, Gen_Trojan, RiskTool, and in general not a specific virus name. The above can also be seen in variations like PUS (software) or PUF (file). The reason those names often pop is because of either the heuristic function, which essentially tries to guess if a part of code inside a program is a virus, based on some known code patterns or because after some time the medicine that is included along with programs get detected as a virus by the AV to scare/warn people.

2. We won't see the same virus name repeat on several antivirus engines concurrently and consistently. Some a/v will show one name, and, some others will show a different. If it was indeed a known virus, most AV will show the same name or the same sub variation.

As an example, look at the screen below and you will see exactly what I described above. Generic names (hacktool, Generic, malicious, etc) and each engine give its own name. You can understand how fake some programs and results are just by looking at the name. W32.AIDetectVM... AI as in Artificial Intelligence which is simply a catchphrase used from marketing to impress.

chrome_2020-11-24_14-49-36.jpg


Needless to say, no matter what, attention to detail and caution must be exercised always. Remember to scan the "medicine" as well as the main app. Dont be afraid to ask if you are not sure but don't wear the tinfoil hats either.
 
Last edited:

brugo

Member
Downloaded
26.4 GB
Uploaded
291.8 GB
Ratio
11.05
Seedbonus
58,521
Upload Count
0 (0)
Member for 4 years
Thank You for the post & Heads up Juanamm. I'd need to try a little harder when detecting Viruses, it ain't what i don't know that causes a fuss, it is the things i think i know for sure that causes the bother in the fist place.
 

juanamm

Uploader
Uploader
Power User
✅ Verified Member
Member
Downloaded
5.7 GB
Uploaded
448.6 GB
Ratio
78.11
Seedbonus
134,973
Upload Count
217 (223)
Member for 5 years
Thank You for the post & Heads up Juanamm. I'd need to try a little harder when detecting Viruses, it ain't what i don't know that causes a fuss, it is the things i think i know for sure that causes the bother in the fist place.
Security is very important to everyone, at the slightest doubt run the suspicious program in a VM or otherwise discard it outright.

Merry Christmas :)
 

2go2ozz

Member
Downloaded
733.8 MB
Uploaded
4.9 GB
Ratio
6.91
Seedbonus
0
Upload Count
0 (0)
Member for 4 years
This is the best info ever, bookmarking this as well as making a pdf file to keep
I appreciate the very valuable info everyone needs to learn
 

PsyTom

Power User
✅ Verified Member
Member
Downloaded
1.4 TB
Uploaded
502.1 TB
Ratio
367.69
Seedbonus
1,662,990
Upload Count
0 (0)
Member for 3 years
thank you for sharing this information, very useful.
 

whoanjo

Member
Downloaded
26.9 GB
Uploaded
591.2 GB
Ratio
21.99
Seedbonus
170
Upload Count
0 (0)
Member for 3 years
Thank you for sharing this information.
 

mjdaved1

Member
Downloaded
15.4 GB
Uploaded
25.5 GB
Ratio
1.65
Seedbonus
944
Upload Count
0 (0)
Member for 6 years
I have a question: what if the file is not signed? What does that mean?

One more thing the Virus Tool website said:
"24 security vendors and no sandboxes flagged this file as malicious."

I'm new to that IT stuff, so I'm not sure.
 

basel202020

Member
Downloaded
0 bytes
Uploaded
5 GB
Ratio
-
Seedbonus
0
Upload Count
0 (0)
Member for 5 years
Very good info
Thank you
 

Toxined

✅ Verified Member
Member
Downloaded
20 GB
Uploaded
101.5 GB
Ratio
5.08
Seedbonus
53,335
Upload Count
0 (0)
Member for 7 years
Well informed. Thank you @juanamm and @Cyler... Everyone needs to take a peek in this. Time to time we'll get some questions. But overall this is something we could look before we sound the alarm and get panicked.:h:
 

RedDove

⭐ VIP
Power User
✅ Verified Member
Member
Downloaded
118.2 GB
Uploaded
41.6 TB
Ratio
360.67
Seedbonus
1,842,673
Upload Count
0 (0)
Member for 9 years
:) Thank you, @juanamm and @Cyler.
Very educational and helpful info.
Everyone who has concerns should read this.
 

mysignature

Member
Downloaded
41.4 GB
Uploaded
38.2 GB
Ratio
0.92
Seedbonus
1,482
Upload Count
0 (0)
Member for 5 months
Thank you so much for this very educational and helpful information.
 
Top