1 2 3 Previous Next 21 Replies Latest reply on Apr 19, 2016 12:36 PM by Peter M

    BehavesLike.Win32.XXX, False positives

    anchorfree

      Hello,

       

      All our software (~400-500 binaries) seem to still being flagged by McAfee-GW-Edition, I believe this is Web Gateway product? This has been the case since few months now, but now there are more new detection names. and we're not getting any feedback after submitting files for review as instructed.

       

      Some samples:

      BehavesLike.Win32.Expiro.rc

      https://www.virustotal.com/en/file/37de93816c38a065027c817833bc9f92d1e42df58ebac 5f53f1caa667a1811d0/analysis/1458689133/

       

      BehavesLike.Win32.Suspicious.rc

      https://www.virustotal.com/en/file/646a2b2ea0748f11ad3fbf6f42b73246af6283ba36216 009dabbb456ea7afbe2/analysis/1458689134/

       

      BehavesLike.Win32.BadFile.rc

      https://www.virustotal.com/en/file/31f0a9813bc279ccde2284b1192f281d77e354b834337 66e74519bbba5437f3b/analysis/1458689249/

       

      Can someone shed some light on how to resolve this false positive, and possibly apply for the whitelisting program to avoid getting software blocked?

        1 2 3 Previous Next