PDA

View Full Version : How to whitelist a threat / false positive


sammyc53
March 17th, 2008, 11:04 AM
I have a few false positives that I do not want detected anymore. How would I go about excluding this, or whitelisting these the scanners?

Eset 3.0 Business Edition

Marcos
March 17th, 2008, 11:07 AM
The best would be if you compress those files, protect the archive with the password "infected" and submit it to samples[at]eset.com with "False positive" in the subject.

sammyc53
March 17th, 2008, 11:14 AM
Cool, but what if it is actually a threat that should be kept in eSet's signature database, but I don't want to detect it?

Example, many admin recovery tools for password recovery will be in the definitions, as they should be. However, I will need them on my desktop.

Thanks.

techtype
March 17th, 2008, 11:57 AM
Turn off scanning of "Potentially unsafe applications". They fall into this category.

Eryan
March 17th, 2008, 12:02 PM
Hi, in that case you should exclude those files from real-time and on-demand scanning.

creating exclusions from real-time scanner:
http://training.eset.com/kb/index.php?option=com_kb&Itemid=29&page=articles&articleid=560


excluding from on-demand scanner:
http://training.eset.com/kb/index.php?option=com_kb&Itemid=29&page=articles&articleid=139


hope that helps.

sammyc53
March 19th, 2008, 07:37 PM
That's a path exclusion, but that will have to do.

In my experience, if a False Positive if every released in the Defs, you won't to be able to individually exclude the whole threat, independent on the path. Otherwise, it will disrupt your whole domain. This should be files as a feature request.