PDA

View Full Version : False Positive? - Kaspersky wouldn't let me update SB10.



NewsArchive
01-12-2017, 10:39 AM
Jeff Slarve
www.jssoftware.com
Twitter free since Jan 11, 2016
I'll search help files & Google for you.

Grammar troll's, are the worse.

NewsArchive
01-12-2017, 10:39 AM
https://www.virustotal.com/en/url/7a80664bd50fbd9282d5d31b69d9ca2b4afcea9bd46ce8591f 8b33da34935137/analysis/1484238156/

Jeff Slarve
www.jssoftware.com
Twitter free since Jan 11, 2016
I'll search help files & Google for you.

Grammar troll's, are the worse.

NewsArchive
01-12-2017, 10:40 AM
So the URL of the .exe shows LinderSoftware as a "malware site", but
the file is ok.

https://www.virustotal.com/en/file/a0f4bdb216ccd677e0e7260a3fad50a7dc056db1fee3837fab 920237306e802c/analysis/1483548616/

Jeff Slarve
www.jssoftware.com
Twitter free since Jan 11, 2016
I'll search help files & Google for you.

Grammar troll's, are the worse.

NewsArchive
01-12-2017, 11:33 AM
Jeff,

Thank you for the report.

Try to report this to Kaspersky or Yandex -- it is absolutely impossible.
They simply do not care.

Kaspersky sent this automated email:

> Thank you for sending a file for analysis to the Anti-Virus Lab.
>
> Kaspersky Anti-Virus has scanned files.
>
> No malware detected in files:
> wud_sb100_5368_cla.exe

Case closed. Of course, it is malware free. But I asked them to remove our
"Malware site" status - and without attaching a file the email bounces back.

I also reported our site as "clean" here:
http://newvirus.kaspersky.com/

Yandex does not even have an email address to report false-positives. Argh!
Sent an email to their virus-samples address. I am sure this will not "fix"
anything.

I think it's time to do something simpler and less depressing. Farming or
sheep herding. All these weird protection vendors are a waste of time and
resources. They are the devil and 666 is their number.

Friedrich

NewsArchive
01-12-2017, 11:58 AM
Sheep are susceptible to all kinds of viruses. You'll never be virus
free! <g>

Maybe you and Lee could take turns in the rocking chair holding the 12
gauge on the porch of your chicken ranch. :)

>
>I think it's time to do something simpler and less depressing. Farming or
>sheep herding. All these weird protection vendors are a waste of time and
>resources. They are the devil and 666 is their number.

Jeff Slarve
www.jssoftware.com
Twitter free since Jan 11, 2016
I'll search help files & Google for you.

Grammar troll's, are the worse.

NewsArchive
01-12-2017, 11:58 AM
> Sheep are susceptible to all kinds of viruses. You'll never be virus
> free! <g>
>
> Maybe you and Lee could take turns in the rocking chair holding the 12
> gauge on the porch of your chicken ranch. :)

<VBG> :-)

Friedrich

NewsArchive
01-12-2017, 11:59 AM
One person clicked "Vote as malicious". What? Who on earth did this <g>.
I bet it was one of our competitors.

https://www.virustotal.com/en/url/45ac9e120090532e8c878faed27fb0d01c7bede2567b0ff679 3787583f85326e/analysis/1484246283/

Well, or a company specialized in "Website Malware Removal".

Quttera
https://quttera.com/sitescan/www.lindersoft.com

Sucuri
https://sitecheck.sucuri.net/results/www.lindersoft.com

No problem, I will send them the requested $199.99 per year. Why not? <bg>.

Friedrich

NewsArchive
01-13-2017, 05:32 AM
Kaspersky came back to us:

> Sorry, it was a false detection. It will be fixed.
> Thank you for your help.
>
> Best Regards, NewVirus
>
> 39A/3 Leningradskoe Shosse, Moscow, 125212, Russia

Friedrich

NewsArchive
01-13-2017, 05:33 AM
Probably a 12 year old kid<g>

>One person clicked "Vote as malicious". What? Who on earth did this <g>.
>I bet it was one of our competitors.

Jeff Slarve
www.jssoftware.com
Twitter free since Jan 11, 2016
I'll search help files & Google for you.

Grammar troll's, are the worse.

NewsArchive
01-13-2017, 05:33 AM
>
> Probably a 12 year old kid<g>
>

<G>

Friedrich

NewsArchive
01-13-2017, 05:34 AM
> I think it's time to do something simpler and less depressing.
Farming or
> sheep herding. All these weird protection vendors are a waste of
time and
> resources. They are the devil and 666 is their number.

LOL

Indeed. The farming we always think of is goat farming - they seem to
require very little attention and are quite jolly all the time.

Andre Labuschagne

NewsArchive
01-13-2017, 05:34 AM
ROFL!

Andre Labuschagne

NewsArchive
01-13-2017, 05:35 AM
Why not? Just be done with it and pay it - if they get the "job" done.

Andre Labuschagne

NewsArchive
01-13-2017, 05:36 AM
A fat boy sitting on a bed somewhere :-)

Andre Labuschagne

NewsArchive
01-14-2017, 07:54 AM
FWIW, it still blocks that file when I attempt to update.

Jeff Slarve
www.jssoftware.com
Twitter free since Jan 11, 2016
I'll search help files & Google for you.

Grammar troll's, are the worse.

NewsArchive
01-16-2017, 03:53 AM
Hi Jeff,

>
> FWIW, it still blocks that file when I attempt to update.
>

Thank you for the update! I have contacted Kaspersky again. But according
to VirusTotal, Kaspersky is cool with our site now.

https://www.virustotal.com/en/url/7a80664bd50fbd9282d5d31b69d9ca2b4afcea9bd46ce8591f 8b33da34935137/analysis/1484559579/

Could you please try it again? And if it still blocks it, can you post a
new screenshot so I can forward it.

BTW, Kaspersky support is very fast and professional.

Friedrich

NewsArchive
01-16-2017, 09:27 AM
With the latest definitions update, computer still says no.

Jeff Slarve
www.jssoftware.com
Twitter free since Jan 11, 2016
I'll search help files & Google for you.

Grammar troll's, are the worse.

NewsArchive
01-16-2017, 09:27 AM
>
> With the latest definitions update, computer still says no.
>

Thanks :-(

Friedrich

NewsArchive
01-18-2017, 11:43 AM
And still today.

I tried out that other issue that I emailed to you, and it still
exists, as well.

Jeff Slarve
www.jssoftware.com
Twitter free since Jan 11, 2016
I'll search help files & Google for you.

Grammar troll's, are the worse.

NewsArchive
01-19-2017, 02:07 AM
> And still today.
>
> I tried out that other issue that I emailed to you, and it still
> exists, as well.

:-(

No update from Kaspersky, I sent two more emails on Monday :-( Would it be
possible for you to report it to Kaspersky (because you are one of their
customers).

Kaspersky seems to be a candidate for the "Hall of Shame" :-(

Friedrich

NewsArchive
01-19-2017, 02:07 AM
I'm not sure how to get the file to them. Since I can't download it, I
can't upload it. Also, it needs an http password. I didn't see a place
to enter a URL to it.

I wonder why virustotal didn't give me a problem when I gave it the
URL to your update.

Jeff Slarve
www.jssoftware.com
Twitter free since Jan 11, 2016
I'll search help files & Google for you.

Grammar troll's, are the worse.

NewsArchive
01-19-2017, 04:04 AM
Hi Jeff,

> I'm not sure how to get the file to them. Since I can't download it, I
> can't upload it. Also, it needs an http password. I didn't see a place
> to enter a URL to it.
>
> I wonder why virustotal didn't give me a problem when I gave it the
> URL to your update.

Argh!

Does Kaspersky give you access to this file (wud_sb100_5368_dev.exe packaged
in a ZIP with the required Kaspersky password)?

http://www.lindersoft.com/downloads/wud_sb100_5368_dev.zip

> The sample is in a password protected zip file
>
> The password for the attachment is infected

Strange thing is that Kaspersky sent the following on Thursday, January 12,
2017 11:12 PM (that is seven days ago!)

> Subject: RE: [Malicious link]False Positive Submission [KLAN-5647262378]
>

> Hello,
>
> Sorry, it was a false detection. It will be fixed.
> Thank you for your help.
>
> Best Regards, NewVirus
>
> 39A/3 Leningradskoe Shosse, Moscow, 125212, Russia

Thank you for your help, Jeff.

Friedrich

NewsArchive
01-19-2017, 10:54 AM
Hi Friedrich -

It allowed me to download it. Thanks. I will try to find the
false-positive upload page this morning .

Jeff Slarve
www.jssoftware.com
Twitter free since Jan 11, 2016
I'll search help files & Google for you.

Grammar troll's, are the worse.

NewsArchive
01-29-2017, 10:49 AM
Hi Friedrich -

I had completely forgotten to submit your zipped version of the
update.

The attached image is a screenshot of the result. I clicked on the "I
disagree" thing and submitted it just now.

Maybe they'll let me update one of these days<g>.

Jeff Slarve
www.jssoftware.com
Twitter free since Jan 11, 2016
I'll search help files & Google for you.

Grammar troll's, are the worse.

NewsArchive
01-30-2017, 08:46 AM
Hi Jeff,

> I had completely forgotten to submit your zipped version of the
> update.
>
> The attached image is a screenshot of the result. I clicked on the "I
> disagree" thing and submitted it just now.
>
> Maybe they'll let me update one of these days<g>.

Thank you!!

By the way, it's the very same file I sent them on January 12, 2016 and they
told me:

>> Hello,
>>
>> Sorry, it was a false detection. It will be fixed.
>> Thank you for your help.
>>
>> Best Regards, NewVirus
>>
>> 39A/3 Leningradskoe Shosse, Moscow, 125212, Russia

Okay, they did not say *when* it will be fixed <g>.

Friedrich

NewsArchive
01-30-2017, 08:47 AM
And it still ain't.

>
>Okay, they did not say *when* it will be fixed <g>.

Jeff Slarve
www.jssoftware.com
Twitter free since Jan 11, 2016
I'll search help files & Google for you.

Grammar troll's, are the worse.

NewsArchive
01-30-2017, 01:15 PM
Jeff,

> And it still ain't.

See how much better AVG is?!<g>

--
Lee White

RPM Report Viewer.: http://www.cwaddons.com/products/rpm/
RPM Review........: http://archive.clarionmag.com/cmag/v11/v11n06rpm.html
Report Faxing.....: http://www.cwaddons.com/products/afe/
---Enroll Today---: http://CWaddons.com

Creative Reporting: http://www.CreativeReporting.com

Product Release & Update Notices
http://twitter.com/DeveloperPLUS

Windows 8 brings us "The Oval, Bumper Car, Roller Coaster of Wait!"
And, now, Windows 10 brings us "The Inch Worm, Bumper Car of Wait!"

NewsArchive
02-01-2017, 08:56 AM
SUCCESS! I updated SB today.

Jeff Slarve
www.jssoftware.com
Twitter free since Jan 11, 2016
I'll search help files & Google for you.

Grammar troll's, are the worse.

NewsArchive
02-01-2017, 08:56 AM
>
> SUCCESS! I updated SB today.
>

COOOOOOL!!!! Thanks for the very good news!!!!

Friedrich