Kaspkersky False Positive in gosearch.gif

Kaspersky is detecting gosearch.gif as Trojan.JS.ramif.a.
gosearch.gif is a standard magnifying glass icon used in Sharepoint as a search button.
I submitted this to Kaspersky and they concur its a false positive, so hopefully updated defs will be out shortly.

Related posts:

  1. Symantec False Positive
  2. McAfee False Positive part 2
  3. Kaspersky and csshover.htc Possible False Positive?
  4. Update: Kaspersky False Positive
  5. Symantec False Positive in DWRCS.exe

3 Comments

  1. hooks says:

    Just received an email from a user indicating the behavior and confirmed the same. Thanks for the heads up.

  2. Probably someone used same icon for some malware thats why it got detected.Since some Av’s like kaspersky in some cases use look for icons used in some malwares to detect them

  3. That is the reason. The file is added to the signature due to a previous update.

Leave a Reply