Skip to content

Wallet Issues Windows AntiVirus

Pixxl edited this page Jun 28, 2018 · 1 revision

One-time Fix Option

πŸ’‘ The idea is to use an online scan tool to find false positive detections and white-list a new version of the file(s) before publishing.

High level process

  1. Scan the new file version with VirusTotal https://www.virustotal.com/en/
  2. For every detection submit a "false positive report" to the anti-virus vendor
  3. Update vendor info for future reference

❗ This process takes time and not all vendors have a good option for submitting

Detailed results for "Obsidan-Qt for Windows, v1.0.0.6"

Engine Scan Results Action Taken White-listed
AegisLab Troj.W32.Ircbot!c πŸ“§ support@aegislab.com ❌
AhnLab-V3 Malware/Gen.Generic.C2129630 πŸ“§ v3sos@ahnlab.com βœ…
CAT-QuickHeal Trojan.IRCbot πŸ“§ viruslab@quickheal.com ❌
eGambit malicious_confidence_93% πŸ”— False Positive Request ❌
Ikarus Trojan.Win32.IRCBot πŸ“§ probe@ikarus.at βœ…
Kaspersky Trojan.Win32.IRCbot.awlu πŸ”— Virus Desk βœ…
McAfee Artemis!85A1A0055D26 πŸ”— Artemis Discussion βœ…
McAfee-GW-Edition Artemis πŸ”— Artemis Discussion βœ…
Symantec WS.Reputation.1 πŸ”— Report False Positive βœ…
Tencent Win32.Trojan.Ircbot.Ebgr N/A ❌
TrendMicro-HouseCall Suspicious_GEN.F47V0903 πŸ”— Re-Classify Request βœ…
ZoneAlarm Trojan.Win32.IRCbot.awlu πŸ”— Virus Desk βœ…

Additional Resources

https://www.virustotal.com/en/about/credits/
https://www.techsupportalert.com/content/how-report-malware-or-false-positives-multiple-antivirus-vendors.htm
https://www.opswat.com/blog/what-do-i-do-if-engine-detects-my-safe-file-threat

Long Term Solution

  1. Obsidian Developers can register with major antivirus vendors to avoid false positive detections.

https://usa.kaspersky.com/partners/whitelist-program
https://www.avg.com/en-us/whitelist

  1. Request additional info about VirusTotal Monitor https://www.virustotal.com/en/about/contact/

VirusTotal does offer a premium file detection monitoring service (VirusTotal Monitor) that acts as an early warning system about false positives. Files submitted to your premium account are periodically scanned with antivirus' latest signature sets, informing you immediately whenever any product flags any of your files as malicious. Should you be interested in receiving more information on this service do not hesitate to contact us.

How the Community:rocket: can help

Many Antivirus vendors offer better false positive submission options to their customers.
If you have an account, please let the Obsidian Developers know! https://twitter.com/obsidiancrypto