Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > Other ESET Home Products Beta
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old January 9th, 2010, 06:31 PM
fduranti fduranti is offline
Infrequent Poster
 
Join Date: Oct 2006
Posts: 11
Default Probable False positive on Still Life 2 game executable

This evening I've bought a game (in downloadable form) called Still Life 2. I've started the installation and at the end of the installation I got a popup from ESET Smart Security related to a trojan in the tmp file that will be copied to the installation folder of the game as SL2.exe (the executable of the game).

I've done some tests and NOD32 detect it only with the advanced heuristics settings turned on. Turning off advanced heuristics and leaving only heuristics checks on the file pass the check.

The file is discovered as a variant of Win2/Kryptik.AUQ trojan.

Doing a check online on the file on www.virustotal.com it discover a virus only with NOD32 and sophos
NOD32 4757 2010.01.09 a variant of Win32/Kryptik.AUQ
Sophos 4.49.0 2010.01.09 Sus/UnkPacker


Anyone can help? Should I consider the file not infected ?
What I have to do? Exclude the file from the scan or disable the advanced heuristic check (as it is by default in the real time filesystem scan?

I've bought the game directly from the developer site and it seems ok.

Any suggestion? Any way to submit it to eset for the file to be analyzed and reported as false positive or real virus?

I'm using 4.2.22.0 with those versions of the modules:
Virus signature database: 4757 (20100109)
Update module: 1031 (20091029)
Antivirus and antispyware scanner module: 1256 (2010010
Advanced heuristics module: 1099 (20091030)
Archive support module: 1107 (20100105)
Cleaner module: 1048 (20091123)
Anti-Stealth support module: 1014 (2009121
Personal firewall module: 1054 (20091015)
Antispam module: 1013 (20091104)
SysInspector module: 1213 (20090902)
Self-defense support module : 1011 (2009121


Thanks for any suggestions
  #2  
Old January 9th, 2010, 06:34 PM
JRViejo's Avatar
JRViejo JRViejo is offline
Global Moderator
 
Join Date: Jul 2008
Posts: 10,458
Default Re: Probable False positive on Still Life 2 game executable

Quote:
Originally Posted by fduranti
Any way to submit it to eset for the file to be analyzed and reported as false positive or real virus?
fduranti, here you go: How to submit virus or potential false positive samples to ESET's labs
  #3  
Old January 9th, 2010, 09:07 PM
fduranti fduranti is offline
Infrequent Poster
 
Join Date: Oct 2006
Posts: 11
Default Re: Probable False positive on Still Life 2 game executable

Thanks for the link. I've submitted the file now I'm waiting to have some news on it
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > Other ESET Home Products Beta « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 09:42 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums