PDA

View Full Version : False positive


Chris12923
October 25th, 2005, 02:26 PM
How long does Eset usually take to fix a false positive? I sent them a file that I think is almost 24 ago and it is still showing up. Just curious.

Thanks,

Chris

Marcos
October 25th, 2005, 02:28 PM
It depends on the complexity of the file. Did you actually send it to samples[at]eset.com or sample[at]eset.com ?

Chris12923
October 25th, 2005, 02:32 PM
Dang your fast Marcos. I sent it using NOD wherever that goes. I am beta testing some software and it came up as probably unknown NewHeur_PE virus. The developer says maybe it's triggering because what the file does trying to access the hard drive info.

Thanks,

Chris

Marcos
October 25th, 2005, 04:07 PM
Hi Chris,
please submit it by email to samples@eset.com as it might easily get lost among thousands of files submitted daily via ThreatSense.

Chris12923
October 25th, 2005, 04:10 PM
I will send it right now as I will not trust the file till it is no longer a flase positive :)

Thanks,

Chris

COSMO26
October 26th, 2005, 07:51 AM
Marcos, do you mean that the "Submit for Analysis" button in Quarantine is "mixed" with all of the Threat Sense data? He said he sent it via "NOD" and that button in "Quarantine" is the only way I've found to "submit from NOD". Pls clarify if emailing to samples@eset is the only sure way to send and that the Submit for Analysis button should NOT be used. Thanks!

Chris12923
October 26th, 2005, 07:57 AM
Ok now it has been almsot 16 hours since sent to samples at and almost 2 days since I sent with NOD .... and still no fix or email back. As I said I am beta testing software with a deadline. Anyway to speed this up Marcos. I know you can do magic :) Only NOD and VBA32 with paranoid hueristics picked this up at jottis.

Thanks,

Chris