PDA

View Full Version : Win Defender false positive for FileAlyzer


pgroot
2006-11-24, 00:46
Windows Defender (both beta 2 and release version) detects FileAlyzer's uninstaller with definition version 1.14.1841.7 created 11/21/2006.
It was labeled (falsely) as WinSoftware.WinAntiSpyware .
I sent it to the Windows Defender False Positive reporting site.
http://www.microsoft.com/athome/security/spyware/software/isv/fpform.aspx
But it should be sent officially by Safer Networking.

This file and associated registry keys are from Safer Networking (makers of Spybot Search & Destroy).

regkey: HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\FileAlyzer_is1

uninstall: HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\FileAlyzer_is1

file: C:\Program Files\Safer Networking\FileAlyzer\unins000.exe

PepiMK
2006-11-24, 09:15
I've seen it here as well:
http://www.microsoft.com/athome/security/support/newsgroups/default.mspx?cat=&lang=&cr=&guid=&sloc=en-us&dg=microsoft.public.security.homeusers&tid=a64a773e-0092-41d2-8798-34c511831ef3&mid=a64a773e-0092-41d2-8798-34c511831ef3&rmid=a64a773e-0092-41d2-8798-34c511831ef3&helpful=1&p=1&stgxml=http%3a%2f%2fwww.microsoft.com%2fathome%2fsecurity%2fsupport%2fnewsgroups%2fsettings.xml

Seems to affect all installers/uninstallers created with InnoSetup, at least with those of a special version (otherwise it would complain about Spybot-S&D itself as well).

Report submitted and trying another channel as well.

pgroot
2006-11-24, 11:49
Win Defender definitions 1.14.1843.4 dated 11/23 fixed the false positive.