View Full Version : This must be a FP
m00nbl00d
January 4th, 2009, 11:32 AM
I downloaded DefenseWall HIPS 2.46 from here http://gladiator-antivirus.com/forum/index.php?showtopic=81884 and the AV detected malware on it.
Sorry, I don't recall the name of the FP malware. But, perhaps you guys could check it out.
Best regards
djohn
January 4th, 2009, 12:04 PM
I checked it for you Nod32 4 picksup as probably a win/32 genetik trojan.I upload to Virustotal and panda detects as a suspicious file.Its probably a falsepositive and I summitted it to eset.
Marcos
January 5th, 2009, 04:12 AM
The file DefenseWall_HIPS_v2_46.exe is reported clean here. Do you have the latest database signatre version 3737 installed? If so, please send that file in a ZIP/RAR archive protected with the password "infected" to samples[at]eset.com with "False positive" and a link to this thread in the subject.
funkydude
January 5th, 2009, 12:13 PM
{QUOTE-> The file DefenseWall_HIPS_v2_46.exe is reported clean here. Do you have the latest database signatre version 3737 installed? If so, please send that file in a ZIP/RAR archive protected with the password "infected" to samples[at]eset.com with "False positive" and a link to this thread in the subject. <-QUOTE}
3739 detected by the internet heuristics. I won't send since djohn did.
ASpace
January 5th, 2009, 12:37 PM
{QUOTE-> The file DefenseWall_HIPS_v2_46.exe is reported clean here <-QUOTE}
http://www.softsphere.com/files/DefenseWall_HIPS_v2_46.exe
MasterTB
January 5th, 2009, 01:30 PM
Tried the link (http://www.softsphere.com/files/DefenseWall_HIPS_v2_46.exe) posted by HiTech_boy here and the result was an ESS warning, see the pic.
Running ESS v4 Beta, Updated, all modules active, no other security software.
CivilTaz
January 5th, 2009, 03:09 PM
{QUOTE-> The file DefenseWall_HIPS_v2_46.exe is reported clean here. <-QUOTE}
Hey Marcos, wich settings do you use to test the files? It's not the first time that someone reports a file that is detected by nod32 and you say that is clean, when, as u can see here, is not true. I wonder if that's why nod32 is not detecting a lot of things and there are more cases of false positives lately; because maybe something is wrong with the settings you and your team are using to do the testing.
vBulletin® Copyright ©2000-2009, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2009, Wilders Security Forums