Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET NOD32 Antivirus Forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old February 5th, 2008, 11:10 PM
Hermescomputers's Avatar
Hermescomputers Hermescomputers is offline
Frequent Poster
 
Join Date: Jan 2006
Location: Toronto, Ontario, Canada, eh?
Posts: 926
Default NOD 32 False Positive New Prevx CSI

Hello all... here's a sure FP...
I downloaded the Executable as well as performed an built in update and both detected and killed by NOD32 3.0

A scan at virus total came up clean:
[ file data ]
* name: PREVXCSIFREE.EXE
* size: 621624
* md5.: 5b3f4f9e32eafe0a975bafc596baed9d
* sha1: 48a2770a41849ed7a9a42d0c3d00ef8ed89d293d

Sorry, I already had it posted in the "other malware Thread"....
http://www.wilderssecurity.com/showp...15&postcount=1
__________________
--
Live Technical Support Help Desk
We Provides Online Computer Help 24/7. Our technical Support Staff Can Fix Computer Problems, Clean Viruses, Speed up your Computer, Remove Spyware, and Eliminate Computer Crashes.
www.hermes-computers.ca

  #2  
Old February 5th, 2008, 11:37 PM
proactivelover's Avatar
proactivelover proactivelover is offline
Frequent Poster
 
Join Date: Apr 2006
Location: Near Wilders Forums
Posts: 786
Default Re: NOD 32 False Positive New Prevx CSI

make sure you have letest update of eav v3 (2851)
i download the file no any warning
Attached Images
 
  #3  
Old February 6th, 2008, 03:11 AM
ctrlaltdelete ctrlaltdelete is offline
Frequent Poster
 
Join Date: Oct 2005
Location: Netherlands
Posts: 223
Default Re: NOD 32 False Positive New Prevx CSI

I did send an e-mail about the FP to ESET support on monday.

The download is clean on virustotal, it's prevxcsi.exe in a temp directory that triggers the heuristics.
Or the same file if the program is installed.

"probably a variant of Win32/Genetik trojan"

Also detected by another AV as Generic9.AYPR and some suspicious AV's think it's Suspicious

prevxcsi.exe
File size: 89600 bytes
MD5: 2e1dc859748231b6485c27d594a9331c
SHA1: 1dec79c42237c443e93f71383ea8dbe332e3739e
  #4  
Old February 6th, 2008, 04:07 AM
Stijnson's Avatar
Stijnson Stijnson is offline
Frequent Poster
 
Join Date: Nov 2007
Location: Paranoia Heaven
Posts: 532
Default Re: NOD 32 False Positive New Prevx CSI

Strangely enough I don't get the FP with NOD2.7.
  #5  
Old February 6th, 2008, 05:27 AM
ctrlaltdelete ctrlaltdelete is offline
Frequent Poster
 
Join Date: Oct 2005
Location: Netherlands
Posts: 223
Default Re: NOD 32 False Positive New Prevx CSI

Quote:
Originally Posted by Stijnson
Strangely enough I don't get the FP with NOD2.7.

Did you install the latest release (v1.2.103.196 or higher)?
And are NOD32's heuristics enabled?
  #6  
Old February 6th, 2008, 05:42 AM
Stijnson's Avatar
Stijnson Stijnson is offline
Frequent Poster
 
Join Date: Nov 2007
Location: Paranoia Heaven
Posts: 532
Default Re: NOD 32 False Positive New Prevx CSI

Quote:
Originally Posted by ctrlaltdelete
Did you install the latest release (v1.2.103.196 or higher)?
And are NOD32's heuristics enabled?

The answer to both questions is Yes.
On another machine AVG Free also 'detects' it as a threat (Trojan horse Generic9.AXPJ).
  #7  
Old February 6th, 2008, 05:58 AM
ctrlaltdelete ctrlaltdelete is offline
Frequent Poster
 
Join Date: Oct 2005
Location: Netherlands
Posts: 223
Default Re: NOD 32 False Positive New Prevx CSI

I guess version 2.7 is using another heuristics module.

Did try to run the file on another machine with NOD32 v 3 def. 2852 and it got busted again.
  #8  
Old February 6th, 2008, 06:09 AM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,383
Default Re: NOD 32 False Positive New Prevx CSI

Quote:
Originally Posted by Hermescomputers
Hello all... here's a sure FP...
I downloaded the Executable as well as performed an built in update and both detected and killed by NOD32 3.0

A scan at virus total came up clean:
[ file data ]
* name: PREVXCSIFREE.EXE
* size: 621624
* md5.: 5b3f4f9e32eafe0a975bafc596baed9d
* sha1: 48a2770a41849ed7a9a42d0c3d00ef8ed89d293d

Sorry, I already had it posted in the "other malware Thread"....
http://www.wilderssecurity.com/showp...15&postcount=1

Since this issue is/has been handled in the thread mentioned above, please hop over there.

This thread is closed.

regards,

paul
 

Wilders Security Forums > Official ESET Support Forum > ESET NOD32 Antivirus Forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 12:59 AM.


Powered by vBulletin® Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2009, Wilders Security Forums