LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 11-14-2019, 02:20 PM   #1
Gregg Bell
Senior Member
 
Registered: Mar 2014
Location: Illinois
Distribution: Xubuntu
Posts: 2,034

Rep: Reputation: 176Reputation: 176
How to determine if something is a false positive in a scan?


On my VirusTotal scans of files I keep running into one scanner finding something. I want to get this writing software yWriter http://www.spacejock.com/yWriter6.htmland I've run the Linux zip file, the .exe file from the Linux zip file and the Windows .exe and VT has returned these three things respectively:

  1. Suspicious.low.ml.score
  2. Malicious.high.ml.score
  3. W32.HfsIemusi.


I read somewhere to drop the .exe file onto hybridanalysis.com but is it safe? https://www.hybrid-analysis.com/

A lot of writers use yWriter6, should I just ignore all the warnings?

And what's the best way to determine if something is a false positive or malware?

Thanks.
 
Old 11-14-2019, 07:36 PM   #2
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,311
Blog Entries: 28

Rep: Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137
You could try submitting them to another scanner for comparison, such as Symantic or Trendmicro:

https://www.symantec.com/security-ce...-virus-samples

https://success.trendmicro.com/solut...g-threat-query
 
1 members found this post helpful.
Old 11-14-2019, 09:03 PM   #3
Gregg Bell
Senior Member
 
Registered: Mar 2014
Location: Illinois
Distribution: Xubuntu
Posts: 2,034

Original Poster
Rep: Reputation: 176Reputation: 176
Quote:
Originally Posted by frankbell View Post
You could try submitting them to another scanner for comparison, such as Symantic or Trendmicro:

https://www.symantec.com/security-ce...-virus-samples

https://success.trendmicro.com/solut...g-threat-query
Thanks a lot, Frank. I bookmarked the sites. (The Trend Micro looks a little more user friendly.) Good to know about these places. Thanks for passing them along.
 
Old 11-14-2019, 09:18 PM   #4
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,311
Blog Entries: 28

Rep: Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137
You are most welcome.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
apache / mod_security: fixing false positive 950013 fryzer Linux - Server 5 05-06-2008 10:30 AM
Is this a false positive....A/V question cbjhawks Linux - Security 4 02-21-2006 06:50 AM
Snort: Block False Positive from Dlink Wireless Router omICron Linux - Security 1 01-01-2005 01:41 AM
'Chkrootkit 0.43' false positive? Mr. Gone Linux - Security 2 03-09-2004 09:16 AM
'Chkrootkit 0.43' false positive? Mr. Gone Linux - Security 0 03-08-2004 08:06 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 01:08 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration