PDA

View Full Version : False Positive?


fingers
September 3rd, 2003, 10:11 PM
Hi all,
dont know if this has been covered or is the correct place to post but....
I have been getting a false (i think/know) positive identification of a virus when i manual scan hdd in the file kix32.exe and any zip files that contain it. --- from kix2001 421

This does not register when scanned with nod32v1
Anyone else noted this before?

here is the log entry from the scan..
probably unknown NewHeur_PE virus

anders
September 4th, 2003, 02:55 AM
Send a copy of the file to Jan. (or some other eset-adress)

Best regards,
Anders

fingers
September 4th, 2003, 03:48 AM
Thanx,
but if i knew who to send it to i would are there any adddress' available to send the exe file too?
dave

martindijk
September 4th, 2003, 04:45 AM
Hi Fingers,

Please send a copy to support@eset.com, if you can Zip the file first, please do.

rgds,
Martin

Paul Wilders
September 4th, 2003, 05:11 AM
fingers,

{QUOTE-> here is the log entry from the scan..
probably unknown NewHeur_PE virus <-QUOTE}

FYI: this isn't a positive identification: as stated its' a "propably unknown..." - due to the use from strong heuristics.

Submitting it to Eset is indeed the safest way to go.

regards.

paul

fingers
September 4th, 2003, 06:32 AM
thanx all
i have sent a copy to the above address -

i dont believe that it is a biggie but the kix script file is distributed widely on many networks and if a scheduled - delete file hdd scan is enabled on a server then the file would be deleted or at least placed in quarantine, and users would get login errors or no script running at all
dave

fingers
October 1st, 2003, 07:08 AM
The false positive has been rectified.
Thanx to those involved
dave