View Full Version : False positive with a brazilian plugin bank.
RenatoMejias
June 8th, 2008, 01:52 PM
Hi,
Few days ago NOD32 shows a false postive with a brazilian plugin bank known as G-Buster Browser Defense
A scan with VirusTotal show it:
~VirusTotal results removed per Policy. (http://www.wilderssecurity.com/showthread.php?t=180057) - Ron~
The path of file is: C:\WINDOWS\Downloaded Program Files\gbieh.dll.
Thanks
HiTech_boy
June 8th, 2008, 01:54 PM
Send this file as an attachment to ESET Threat Lab . In the subject include information that you send them a possible false positive
The mail addrress is samples@eset.sk
Regards!
RenatoMejias
June 8th, 2008, 02:02 PM
Ok,
I'm helping an user in a forum here, and I said to him to send the sample and the link to the topic there.
Thanks.
RenatoMejias
June 28th, 2008, 12:40 PM
Hi,
Sorry for this 'bump', but I sent a sample to ESET and I don't received any reply :(
The problem persist. Is very boring all the time receive a malware alert on the computer.
Fajo
June 28th, 2008, 02:37 PM
It can take 2 weeks from what I have seen. and heard so if you want you can try resending it again maybe it did not go Thur your ISP Virus scanner never know :D
Marcos
July 10th, 2008, 01:34 AM
We have eventually removed detection just because the tool was created by a bank. You can read more about its suspicious behavior here (http://insanebits.blogspot.com/2007/04/g-buster-browser-defense-analysis-and.html).
~ updated link to current address of web page - agoretsky ~
RenatoMejias
July 14th, 2008, 09:41 PM
Thanks for your feedback Marcos, it's really appreciate.
vBulletin® Copyright ©2000-2009, Jelsoft Enterprises Ltd.