PDA

View Full Version : False positive with Btnext.exe


Di0g08
September 5th, 2009, 08:04 PM
Hi

Eset Nod32 is the only av detecting btnext.exe with a win32/packed themida application.

I cant upload the file.


Help....

Fixer
September 6th, 2009, 06:01 AM
Hi!

Please, send this file to ESET.
How to submit virus or potential false positive samples to ESET's labs (http://kb.eset.com/esetkb/index?page=content&id=SOLN141&actp=search&viewlocale=en_US&searchid=1252143620291)

Marcos
September 6th, 2009, 06:10 AM
I'd suggest bringing this (http://www.avertlabs.com/research/blog/index.php/2009/05/28/who-digs-the-elephant-trap/) article to the author's attention.

Di0g08
September 6th, 2009, 01:46 PM
How much time is necessary to eset to fix them?

ASpace
September 6th, 2009, 02:00 PM
Nothing from ESET side to be fixed . However , you could either

1-> Use the Exclusions
http://kb.eset.com/esetkb/index?page=content&id=SOLN2153&actp=search&viewlocale=en_US&searchid=1252259916427


2-> (temporary) Disable detection of Potentially Unwanted Applications

http://kb.eset.com/esetkb/index?page=content&id=SOLN2198&actp=search&viewlocale=en_US&searchid=1252259916427

Takes less than 30 seconds - from your side

Marcos
September 6th, 2009, 03:38 PM
Maybe we'll whitelist it, but the author should really read the above mentioned article concerning protectors.