False virus alarm?

AntonK3 years ago

I keep backups of Traccar Client APK (exported with SD Maid) in my personal archive, which is hosted at Windows 10 PC machine.
Today built-in Windows antivirus has detected a virus in version 6.5 (a kind of Ransom:Win32/Eris).
I've submitted the file to VirusTotal and got the report where several AV engines detected different signatures.
Some of them look like Monitor:Android/Traca.00ba9b14 (Alibaba), A Variant Of Android/Monitor.Traca.F (ESET-NOD32), Android.Monitor.Traccar.B (BitDefenderFalx), so the AV engines are aware of Traccar.
The report for version 6.7 also mentions some viruses.
Is it a known issue?

Anton Tananaev3 years ago

That's pretty cool that they know Traccar. Other stuff is probably false positives.

Is there a reason you didn't test APK you can download from our website directly? That's definitely clean. Not sure what that SD Maid does to it.

For paranoid people, there's always an option to build from the source code directly to make sure there's nothing "extra" added.

AntonK3 years ago

This is the report for the Traccar Client, which is available for download from your site.
It is 19 days old, and the file was submitted for scan by someone else (probably by a search engine).
BTW the report for Traccar Manager mentions only one virus Trojan ( 0056395e1 ) (K7GW).
I believe, they are all false positive.
I guess, it makes sense to contact some of AV vendors (at least the largest ones) to notify them about false positives.

Anton Tananaev3 years ago

Feel free to contact them. Let us know if any success. Thanks