Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

AV - Confirming a False Positive.

Status
Not open for further replies.

Ed2020

Programmer
Nov 12, 2001
1,899
GB
Hi,

If you suspected your anti-virus software was giving you a false positive report of an infection how can you verify that the report is indeed a false positive? So far I have come up with:

• Confirmation from the AV vendor that there is a known problem with the AV software producing false positive reports for the specific executable where the infection has been found.
• A comparison between the alleged infected executable and a known clean version.
• A reverse engineer and detailed analysis of the executable’s Assembly code by a competent person.

Are there any other methods? The obvious one seems to be to scan with a different AV product, however I am not sure this really confirms a false positive in the original product - it could mean that your alternative AV is missing the infection.

Ed Metcalfe.

Please do not feed the trolls.....
 
I think you've got your bases covered with your original three suggestions.

If a known clean version displays the same problem, then you can be sure it's a FP; assuming it's the same version of the file.

You can then move on to notify the AV vendor.

Carlsberg don't run I.T departments, but if they did they'd probably be more fun.
 
Thanks Grenage.

Please do not feed the trolls.....
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top