False Positive

Reply
Highlighted
L1 Bithead

False Positive


Accepted Solutions
Highlighted
L7 Applicator

f46a162f52d93172da4ccfd208c7cb4b53b6f890a786630ba46b1435cfd02c3a verdict has been changed to grayware.

It will now show as 'clean' in VirusTotal.

The associated Antivirus signature (beginning with tomorrow's release) will be removed from the Palo Alto Networks Antivirus database.

View solution in original post


All Replies
Highlighted
L7 Applicator

Where can the original installer be downloaded from? Can you provide the download link?

Highlighted
L1 Bithead

Uploaded it to sendpsace: https://www.sendspace.com/file/531fhi

 

You'll probably have to click "Download" twice because there's ad.

Highlighted
L1 Bithead

Any news?... Still have a false positive...

Highlighted
L7 Applicator

The uTorrent installers available at https://www.utorrent.com/downloads/win are 2.6MB in size.

The file you provided is 6.2MB.

 

Can you explain the difference in file size?

Highlighted
L1 Bithead

Ehm... this is the first time I get a question like this from an AV support representative. Your AV claims that the file is generic whereas it's just a clean uTorrent installer. Check — approve — done, that's how it always worked with all the other AVs. And if you look at the official uTorrent installer, you can see it's a bundle with ads.

 

Anyway, the installer I uploaded — it's a repack. I removed all ads so it's just clean uTorrent without anything else. That's it.

Highlighted
L7 Applicator

The sample exhibits suspicious behaviors. I'll work with our malware research team to verify this sample.

 

Screen Shot 2018-06-07 at 3.11.53 PM.png

Highlighted
L7 Applicator

f46a162f52d93172da4ccfd208c7cb4b53b6f890a786630ba46b1435cfd02c3a has been submitted for verdict reconsideration.

Highlighted
L7 Applicator

f46a162f52d93172da4ccfd208c7cb4b53b6f890a786630ba46b1435cfd02c3a verdict has been changed to grayware.

It will now show as 'clean' in VirusTotal.

The associated Antivirus signature (beginning with tomorrow's release) will be removed from the Palo Alto Networks Antivirus database.

View solution in original post

Highlighted
L1 Bithead

Thanks!

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!