360TS found lots of safe files as malwares!!!

Status
Not open for further replies.

phyniks

Level 7
Thread author
Verified
Well-known
Nov 17, 2013
300
I m trying 360TS...default engines + Avira

everything is well except it detects some safe files as malwares

First it quarantined IDM setup file

Then it detects a musical note MHTML ...

Today it quarantined Avast Free setup file!!!!
 

peymi

Level 1
Verified
Aug 28, 2014
37
Hi,
Qihoo Has False Positives,
Try Avast Free Antivirus, It's Better Than Qihoo
 
  • Like
Reactions: phyniks

jackuars

Level 28
Verified
Top Poster
Well-known
Jul 2, 2014
1,717
First it quarantined IDM setup file

Then it detects a musical note MHTML ...

Today it quarantined Avast Free setup file!!!!

When you're downloading cracks/keygens [read IDM], you're bound to get hassled by antiviruses. :p

About Avast, where did you download it from? The official website?
 
  • Like
Reactions: phyniks

Oxygen

Level 44
Verified
Feb 23, 2014
3,323
I have been getting the same issue with Qihoo Products. I have uninstalled it because of this. Use another antivirus.
 
  • Like
Reactions: phyniks

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Try to consult for uploading the file from virustotal and sometimes the hashes from file came from known and unknown source may be different.
 

phyniks

Level 7
Thread author
Verified
Well-known
Nov 17, 2013
300
When you're downloading cracks/keygens [read IDM], you're bound to get hassled by antiviruses. :p

About Avast, where did you download it from? The official website?

Yes...the official
I have the screenshot....But uploading is not active in this thread (and I dont know how to activate it)
 

phyniks

Level 7
Thread author
Verified
Well-known
Nov 17, 2013
300
Yes...QVM06.1 Malware gen
 
Last edited:

xinjing545853507

Level 1
Verified
Nov 4, 2014
39
QVM misstatement is a bit high haha I still like to use kaspersky in China might now kappa in viral response and collect less than 360o_O
 

AtlBo

Level 28
Verified
Top Poster
Content Creator
Well-known
Dec 29, 2014
1,716
Disadvantages of High Detection rates ;)
Please check the FP detection names? All must be "QVM/HEUR.XXX" etc. This is how Qihoo works :D

Yes, thanks for this comment.

Awhile back I downloaded a compiler, working on learning C#, and the first program is in the tutorial is called "Hello World". So I created my first program and happily named it "Hello World" as instructed. What do you know, avast went crazy. Talk about ironic...my first program was a known virus. I am still loling about this. Everything I have ever installed has flagged it, including 360 TS. This is because there was (I am sure) a virus/malware called the "Hello World" virus at one time where the file name "Hello World" was used. Look at the names of the files that get flagged incorrectly, and you will find the source of each false positive, but, if you think about it, you will realize that, if you had the malware version of the file on your PC but didn't put it there, you would be glad it was flagged. It's 360's way of keeping old viruses in quarantine in the big picture I guess.

360 TS is old school high activity and high detection. Reminds me of the days back in the early 2000s when some of the a-vs were very active and returned alot of FPs. Even with the FPs, modern a-vs are quite a bit better than those early ones in so many ways, though.

To each his own I think on a-v. You don't like the false positives, you got your reasons for sure. Probably another one is for you. With 360 TS I think the focus should be auto shopping mode, auto gaming mode, anti-keylogging, anti-webcam capture, avira defs, and BitDefender defs, oh, and free. Yes higher FPs, too, but they aren't phony...

Hello World virus:
 
Last edited:

xinjing545853507

Level 1
Verified
Nov 4, 2014
39
I also do not think Qihoo is spying!Because I am a Chinese!I am now in with kaspersky, I could be the kaspersky is a spy?The fact is not!
 

Kate_L

in memoriam
Verified
Top Poster
Well-known
Jun 21, 2014
1,044
This is the downside of this software, has amazing detection but it has some fp. You can always use Avira Free or Avast.
 
  • Like
Reactions: yigido

jackuars

Level 28
Verified
Top Poster
Well-known
Jul 2, 2014
1,717
I have to ask for an apology

I thought the official setup files were quarantined....I restored them and saw they are from an Iranian site which puts his adddress on any setup files

But the MHTML musical note is safe according to Avira and Lavasoft Analysis

https://www.virustotal.com/en/file/...05f60edfd4e9ad6d1d7d5240/analysis/1420222600/
It's a clicker agent, doesn't need to be detected by all antiviruses. Whether you want to keep it or not is your wish. What it does, I don't know.
 
  • Like
Reactions: phyniks

jackuars

Level 28
Verified
Top Poster
Well-known
Jul 2, 2014
1,717
Yes, thanks for this comment.

Awhile back I downloaded a compiler, working on learning C#, and the first program is in the tutorial is called "Hello World". So I created my first program and happily named it "Hello World" as instructed. What do you know, avast went crazy. Talk about ironic...my first program was a known virus. I am still loling about this. Everything I have ever installed has flagged it, including 360 TS. This is because there was (I am sure) a virus/malware called the "Hello World" virus at one time where the file name "Hello World" was used. Look at the names of the files that get flagged incorrectly, and you will find the source of each false positive, but, if you think about it, you will realize that, if you had the malware version of the file on your PC but didn't put it there, you would be glad it was flagged. It's 360's way of keeping old viruses in quarantine in the big picture I guess.

360 TS is old school high activity and high detection. Reminds me of the days back in the early 2000s when some of the a-vs were very active and returned alot of FPs. Even with the FPs, modern a-vs are quite a bit better than those early ones in so many ways, though.

To each his own I think on a-v. You don't like the false positives, you got your reasons for sure. Probably another one is for you. With 360 TS I think the focus should be auto shopping mode, auto gaming mode, anti-keylogging, anti-webcam capture, avira defs, and BitDefender defs, oh, and free. Yes higher FPs, too, but they aren't phony...

Hello World virus:

It's not just the helloworld. It even detected my C++ files as suspicious. Things can go nasty with these codes. But it doesn't quarantine them. It asks us for what to do. So no harm done at all.

I have to ask for an apology

I thought the official setup files were quarantined....I restored them and saw they are from an Iranian site which puts his adddress on any setup files
There is your answer :D
 

phyniks

Level 7
Thread author
Verified
Well-known
Nov 17, 2013
300
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top