Antivirus false positive

Any issues related to FORScan application
FORScan
Site Admin
Posts: 2970
Joined: Fri Jun 13, 2014 2:21 am

Antivirus false positive

Post by FORScan »

FORScan uses binary compression and encryption to reduce the binary size and protect the code. This technique is often used by virus/malware (and often using the same compression/protection system), so some antivirus may throw a false positive if signature matched. We have created this thread to provide information on this issue.

At this moment we have this problem with FORScan v2.3.29 - several anti-virus software throw alerts for it, including Microsoft WIndows Defender. We have submitted the false positive to Microsoft and Bitdefender. Microsoft have already updated their database, so false positive should gone in the next update. They recommend to clear Defnder cache this way:
We have removed the detection. Please follow the steps below to clear cached detection and obtain the latest malware definitions.

1. Open command prompt as administrator and change directory to c:\Program Files\Windows Defender
2. Run “MpCmdRun.exe -removedefinitions -dynamicsignatures”
3. Run "MpCmdRun.exe -SignatureUpdate"

Alternatively, the latest definition is available for download here: https://www.microsoft.com/en-us/wdsi/definitions
Bitdefender promised to check the file and update DB in next 72 hours.


Update 2025-12-17:
Windows Defender flags the latest FORScan release (v2.3.68) as a Potentially Unwanted Application (PUA:Win32/Packunwan) — whatever that means. We have already submitted a false positive report to Microsoft twice, with no luck. This is strange because it used to work fine. It now seems these reports are checked by an AI instead of a human engineer, which makes the process futile. It appears we will have to change the binary and license the 3rd-party protector we currently use, as it has been unsupported for years and we're unable to modify it.

Here is the instruction from the user fordsmax471 (original post):
fordsmax471 wrote: Tue Dec 01, 2020 5:37 pm :arrow: How to prevent Windows Defender from scanning FORScan program and files
1. Open Windows Defender Security Center.
2. Click Virus & threat protection.
3. Click the Virus & threat protection option.
4. Under "Exclusions," click the Add or remove exclusions option.
5. Click the Add an exclusion button.
6. Select the content you want to exclude from Windows Defender Antivirus, such as:
7. File — Excludes only one file per exclusion. C:\Program Files (x86)\FORScan\FORScan.exe
8. Process — Excludes background processes by name. C:\Program Files (x86)\FORScan\FORScan.exe

:arrow: Allow FORScan through defender firewall

1. Open Windows Security.
2. Click on Firewall & network protection.
3. Click the Allow an app through firewall link.
4. Click the Change settings button.
5. Click the Allow another app button to locate the application you want to allow. C:\Program Files (x86)\FORScan\FORScan.exe
6. Select the which type of networks an app can access the network:
7. Private — Allows the app access to the network at home or work.
8. Public — Allows the app access to the network at a public place, such as on a coffee shop.
9. Click the OK button.

Now FORScan works very stable ;)
JAS2006
Posts: 3
Joined: Mon Feb 03, 2020 9:08 pm
Vehicle: 2019 Ford F150 XLT 5.0L Supercrew

Re: Antivirus false positive

Post by JAS2006 »

Thanks for this update!
FORScan
Site Admin
Posts: 2970
Joined: Fri Jun 13, 2014 2:21 am

Re: Antivirus false positive

Post by FORScan »

Update:

Microsoft removed trojan false positive for v2.3.29 from Windows Defender, but now it finds "PUA:Win32/Presenoker" in it :o Other antivirus s/w like Bitdefender seem to simply ignore our request for EXE analysis.
Jbst
Posts: 2
Joined: Sat Feb 15, 2020 3:24 am
Vehicle: Explorer ST/v6 3.0 twin turbo/2020

Re: Antivirus false positive

Post by Jbst »

So what now? Did I just waste $40.00 on a obd connector? :roll:
foden
Posts: 2
Joined: Wed Oct 30, 2019 4:23 pm
Vehicle: mondeo mk4 2.0tdci 140bhp 2009

Re: Antivirus false positive

Post by foden »

Jbst wrote: Tue Feb 25, 2020 8:16 pm So what now? Did I just waste $40.00 on a obd connector? :roll:
No you should be able to add the forscan as an exception to the anti virus programs or at least allow it to run
as if the anti virus finds the false positives they should quarantine and from there you should be able to choose what you
want the anti virus to do about it i.e allow it to run
then try reinstalling forscan
hope this helps and may resolve your problem (not gauaranteed as there a lot of anti virus programs)
this worked though for me with the windows security program.
foden
Jbst
Posts: 2
Joined: Sat Feb 15, 2020 3:24 am
Vehicle: Explorer ST/v6 3.0 twin turbo/2020

Re: Antivirus false positive

Post by Jbst »

Ok thanks. I will try that. Windows defender is my only anti virus.
yyz2pvg
Posts: 6
Joined: Wed Mar 04, 2020 4:23 pm
Vehicle: Ford Flex, 3.5 TC, 2015

Re: Antivirus false positive

Post by yyz2pvg »

McAfee is also providing warnings/alerts for this download.
FORScan
Site Admin
Posts: 2970
Joined: Fri Jun 13, 2014 2:21 am

Re: Antivirus false positive

Post by FORScan »

We have released v2.3.30 yesterday and tested it on Virustotal to make sure there are no false alerts. Here is the report:
Attachments
1.jpg
1.jpg (277.82 KiB) Viewed 123414 times
Deejin
Posts: 3
Joined: Sun Jul 09, 2017 8:14 am
Vehicle: RangerT6-MC

Re: Antivirus false positive

Post by Deejin »

FORScan wrote: Sun Mar 08, 2020 12:59 am We have released v2.3.30 yesterday and tested it on Virustotal to make sure there are no false alerts. Here is the report:
Thank you very much for your great support, I would like to confirmed, forscan V2.3.30 is no problem about that. I can install and it's working fine from now.
Best Regards,
eaa53
Posts: 2
Joined: Thu Feb 13, 2020 4:35 pm
Vehicle: MX5 2.0ltr 2007

Re: Antivirus false positive

Post by eaa53 »

Adaware still deletes the .exe and the shortcut on the desktop.

Added it to scan exceptions but still deletes them both automatically.

I updated Adaware software but that did not cure it either.
Post Reply