View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
0000153 | NoteFly | bug | public | 2012-03-18 19:31 | 2019-10-26 10:41 |
Reporter | D9ping | Assigned To | |||
Priority | high | Severity | minor | Reproducibility | N/A |
Status | resolved | Resolution | no change required | ||
Summary | 0000153: NoteFly setup reported as Suspicious.Emit. (false positive) | ||||
Description | NoteFly is reported as Suspicious.Emit by Symantec Anti-virus. This is a false positive. | ||||
Additional Information | NSIS installer is causing a lot of false postives. For more information see http://nsis.sourceforge.net/NSIS_False_Positives | ||||
Tags | No tags attached. | ||||
|
Reported NoteFly 3.0.0 for whitelisting. |
|
Also reported NoteFly 3.0.1 for whitelisting. To address NoteFly being again reported as false positive virus in the future, i'm going to stop using LZMA compression on the NSIS installer. |
|
NoteFly 3.0.0 and NoteFly 3.0.1 are added to whitelist. |
|
Bug report reopened, Setup version 3.0.3 again reported as Suspicious.Emit by Symantec and HeurEngine.ZeroDayThreat by PCtools. Applied for white listing. |
|
NoteFly 3.0.3 setup added to whitelist. |
|
NoteFly 3.0.4 causing false positives. Reference https://www.virustotal.com/en/file/26747d48b7080a0bdacc42668b4ef5e9ae1dd2181f979fcf5336f6c1800c2906/analysis/1368369327/ <pre> AV: False positive: <del>PCTools HeurEngine.ZeroDayThreat</del> Symantec Suspicious.Emit <del>TrendMicro-HouseCall TROJ_GEN.F47V0515</del> <del>VBA32 suspected of Crafted.Win32File.OLS</del> <del>Emsisoft Trojan.Generic.10008038 (B) </del> McAfee-GW-Edition BehavesLike.Win32.Tool.dc </pre> |
|
NoteFly 3.0.5 causing false positives. Reference https://www.virustotal.com/nl/file/2bc5402c1ee3c38a64a1116247d267df170e4527f89865a0bef4153e89a7f740/analysis/ <pre> AV: False positive: <del>PCTools HeurEngine.ZeroDayThreat</del> <del>Symantec Suspicious.Emit</del> <del>TrendMicro-HouseCall TROJ_GEN.F47V0515</del> <del>VBA32 suspected of Crafted.Win32File.OLS</del> </pre> |
|
I'm going to try to get a code signing certificate so false positives are less likely. |
|
NoteFly 3.0.7 causing false positives. Reference https://www.virustotal.com/en/file/62cb5efaf646445ba5103686f4aff3f83d8af0a585f2193d17e259e85ffce60b/analysis/ <pre> AV: False positive: Trapmine Suspicious.low.ml.score <del>PCTools HeurEngine.ZeroDayThreat</del> <del>Symantec Suspicious.Emit</del> <del>TrendMicro-HouseCall TROJ_GEN.R047H01G913</del> </pre> |