PDA

View Full Version : Nod32 V4 too sensitive?


softtouch
March 29th, 2009, 05:35 AM
I am a programmer, and write a lot of projects where I have to access/gather system information, like info about screen, memory etc., and NOD32 V4 popup all the time that it detected "probably unknown NewHeur_PE virus", that is just plain stupid!
V3 and V2.7 did not popup anything, just the today installed V4!
This happen with a lot of my programs now, they are all written in Delphi, if that matter.
I then tried to send the file to eset, but all I get after filling up the comment "unable to send file".

Marcos
March 29th, 2009, 05:54 AM
That's what heuristics as well as behavior blockers are supposed to do - to detect suspicious behavior and let the user decide what action to take. If you release your software to the public, email the file in a password protected archive to samples[at]eset.com with "False positive" in the subject and as much information about the software as possible (e.g. its purpose, the url people can download it from, version number, etc.).
Since advanced heuristics is same for all versions, I assume you must have enabled a new option introduced in v4, such as advanced heuristics on file access or execution.

softtouch
April 2nd, 2009, 12:56 AM
Where can I submit the file manually, because its a FP!

I wrote it, I know its not a virus or does any dangerous things, and all scanner report no virus, except NOD32 V4 (V2.7 did not report it).

Virustotal:
Result: 1/40 (2.5%)

and the 1 of 40 was NOD32, which tells me always
"systemsnap.dll probably unknown NewHeur_PE virus"

funkydude
April 2nd, 2009, 06:56 AM
Make sure you're updated, if you are: http://kb.eset.com/esetkb/index?page=content&id=SOLN141

softtouch
April 2nd, 2009, 07:25 AM
{QUOTE-> Make sure you're updated, if you are: http://kb.eset.com/esetkb/index?page=content&id=SOLN141 <-QUOTE}

Thanks, submitted it already.