PDA

View Full Version : This must be a FP


m00nbl00d
January 4th, 2009, 11:32 AM
I downloaded DefenseWall HIPS 2.46 from here http://gladiator-antivirus.com/forum/index.php?showtopic=81884 and the AV detected malware on it.

Sorry, I don't recall the name of the FP malware. But, perhaps you guys could check it out.

Best regards

djohn
January 4th, 2009, 12:04 PM
I checked it for you Nod32 4 picksup as probably a win/32 genetik trojan.I upload to Virustotal and panda detects as a suspicious file.Its probably a falsepositive and I summitted it to eset.

Marcos
January 5th, 2009, 04:12 AM
The file DefenseWall_HIPS_v2_46.exe is reported clean here. Do you have the latest database signatre version 3737 installed? If so, please send that file in a ZIP/RAR archive protected with the password "infected" to samples[at]eset.com with "False positive" and a link to this thread in the subject.

funkydude
January 5th, 2009, 12:13 PM
{QUOTE-> The file DefenseWall_HIPS_v2_46.exe is reported clean here. Do you have the latest database signatre version 3737 installed? If so, please send that file in a ZIP/RAR archive protected with the password "infected" to samples[at]eset.com with "False positive" and a link to this thread in the subject. <-QUOTE}

3739 detected by the internet heuristics. I won't send since djohn did.

ASpace
January 5th, 2009, 12:37 PM
{QUOTE-> The file DefenseWall_HIPS_v2_46.exe is reported clean here <-QUOTE}

http://www.softsphere.com/files/DefenseWall_HIPS_v2_46.exe

MasterTB
January 5th, 2009, 01:30 PM
Tried the link (http://www.softsphere.com/files/DefenseWall_HIPS_v2_46.exe) posted by HiTech_boy here and the result was an ESS warning, see the pic.

Running ESS v4 Beta, Updated, all modules active, no other security software.

CivilTaz
January 5th, 2009, 03:09 PM
{QUOTE-> The file DefenseWall_HIPS_v2_46.exe is reported clean here. <-QUOTE}

Hey Marcos, wich settings do you use to test the files? It's not the first time that someone reports a file that is detected by nod32 and you say that is clean, when, as u can see here, is not true. I wonder if that's why nod32 is not detecting a lot of things and there are more cases of false positives lately; because maybe something is wrong with the settings you and your team are using to do the testing.