Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old September 5th, 2007, 03:50 PM
Anth-Unit Anth-Unit is offline
Regular Poster
 
Join Date: Oct 2006
Posts: 100
Default ESEA client false positive

NOD32 is detecting my ESEA client as: a variant of Win32/Packed.Themida application. I'm pretty sure that this is a false positive. The ESEA client is a counter-strike matchmaking service that finds different pugs for players to join. I've already submitted the file to eset via NOD32 and I'm wondering if I should also report the false positive to support[at]eset.com. The website for this service is: http://www.esportsea.com/

Edit:
@ replaced with [at] to prevent robots from harvesting our address

Last edited by Marcos : September 5th, 2007 at 05:18 PM.
  #2  
Old September 5th, 2007, 04:04 PM
ASpace
 
Posts: n/a
Default Re: ESEA client false positive

Win32/Packed.Themida application

Application - this sounds like not false positive but real potentially unwanted/unsafe software . In case you want to take the risk of using such applications , you must uncheck these cathegories in the AMON/IMON setup.

http://www.wilderssecurity.com/showp...80&postcount=2

  #3  
Old September 5th, 2007, 07:34 PM
Anth-Unit Anth-Unit is offline
Regular Poster
 
Join Date: Oct 2006
Posts: 100
Default Re: ESEA client false positive

Quote:
Originally Posted by HiTech_boy
Win32/Packed.Themida application

Application - this sounds like not false positive but real potentially unwanted/unsafe software . In case you want to take the risk of using such applications , you must uncheck these cathegories in the AMON/IMON setup.

http://www.wilderssecurity.com/showp...80&postcount=2


I don't think thats the case. When I turn off potentially unwanted/unsafe applications it still detects the file.

-edit-

Actually, you're probably right. I'm using the ESS beta right now and I cant seem to get the setting to stick. It seems to turn itself back on after I uncheck the option to detect unwanted/unsafe applications. I still don't understand why this is classified as an unwanted/unsafe application. It's a very popular service amongst online CS gamers and as far as I know it does not fall under any of the characteristics explained in that link you gave me (remote access tools, password-cracking applications, and keylogger). I assume if it was a keylogger, password-cracker etc. someone would have discovered it by now as its been around forever.

Is it ok for me to post a virus total result in this case? A few other scanners detect this file, most of them look like a heuristic detection.

Last edited by Anth-Unit : September 5th, 2007 at 08:24 PM.
  #4  
Old September 6th, 2007, 03:36 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,185
Default Re: ESEA client false positive

Disabling potentially unsafe applications makes the alert disappear, I have tested it and it actually works. We will analyse the file and remove detection if it's actually a legit application.
  #5  
Old September 6th, 2007, 03:26 PM
Anth-Unit Anth-Unit is offline
Regular Poster
 
Join Date: Oct 2006
Posts: 100
Default Re: ESEA client false positive

Quote:
Originally Posted by Marcos
Disabling potentially unsafe applications makes the alert disappear, I have tested it and it actually works. We will analyse the file and remove detection if it's actually a legit application.

Thanks for the fast response! It looks like it was fixed as NOD32 no longer detects the file.
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:18 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums