False Positive Virus Detection On Confused Assemblies

Dec 29, 2011 at 9:54 PM

Greetings,

On attempting to run confused assemblies using the Maximum preset, Avira Personal (guard) returns the following:

Guard: Malware found. A virus or unwanted program 'TR/ATRAPS.Gen' was found in... [assemblies].

This happens with a program I have written, with a process viewer, and with a simple tab control demo--three completely unrelated assemblies.

The warning occurs only if the assemblies have been confused with the Maximum preset. Normal or Aggressive presets do not elicit this warning.

Manual scans of the confused assemblies with Avira or Malwarebytes do not throw a warning. This only happens on trying to run the assembly with Avira AntiVir Guard enabled, and typical Avira settings.

This warning occurs with or without the Memory Optimizer plugin, with or without Strong Name Key.

It would appear this is related to either Anti-Tampering Confusion, Reduce Metadata Confusion or Invalid Metadata Confusion, (though I may be mistaken).

I realize this is more a problem with Avira, but I plan to release some programs--preferably with Maximum confusion--and would like to fix this: I really don't want my programs flagged as viruses, even by mistake.

Any thoughts?

Coordinator
Dec 31, 2011 at 3:06 PM

Hi,

I do not have Avira installed, so would you please attach a screenshot and a sample program before and after confuser processed.

Dec 31, 2011 at 6:46 PM
Greetings,

Thanks for your reply.

Attached is a screenshot of Avira's detection warning, along with a normal exe, a Confuser processed exe, and the source code.

Let me reiterate that the problem occurs on any assembly confused only with the Maximum preset, (I have have tried four completely different assemblies, so far). None of the other presets trigger a malware warning.

This appears to trigger Avira's Generic detection algorithm, so I presume Avira sees a specific pattern of bytes, perhaps indicating a compression technique, or simply a "signature" of the malware in question.

Please let me know what else I may do for you.

Thank you very much,

Talion



On 12/31/2011 8:06 AM, yck1509 wrote:

From: yck1509

Hi,

I do not have Avira installed, so would you please attach a screenshot and a sample program before and after confuser processed.