Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET Smart Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old February 26th, 2009, 11:10 PM
3nigma 3nigma is offline
Infrequent Poster
 
Join Date: Feb 2009
Posts: 5
Exclamation False Positive

Ok, my virus definitions have just been updated about 30mins ago and one of my programs has been quarantined by Eset. I have used this program for months, i am 100% positive it's not a virus Eset claims it to be.

The program in question is called Universal Extractor.

http://www.portablefreeware.com/?id=641

Can anyone inform Eset of this mistake and send out new virus definitions as soon as possible. This isnt the first time this has happened, a while back Eset started sending all the uninstallers of Innosetup files to quarantine. Thankfully, it wasnt set to delete them.
  #2  
Old February 26th, 2009, 11:47 PM
agoretsky's Avatar
agoretsky agoretsky is offline
Eset Moderator
 
Join Date: Apr 2006
Location: California
Posts: 3,897
Default Re: False Positive

Hello,

The download seems to be unavailable right now.

What was the exact threat detected by ESET's software and which version of ESET's virus signature are you using?

Knowing that will help ESET investigate the issue.

You can also send a copy of the file to ESET at samples@eset.sk inside a .ZIP or .RAR file protected with a password of "infected", a Subject: of "possible false positive" and a link to this message thread for examination by ESET's virus lab.

Regards,

Aryeh Goretsky
__________________
Resources: ESET · blog · documentation · FAQs · knowledge base · news · RSS · signature updates · support · Threat Center · @ESETNA (Twitter) · YouTube: ESETKnowledgebase · VirusRadar
Fun Stuff: Facebook (global) · Facebook (US) · @ESET (Twitter) · YouTube: esetusa
  #3  
Old February 27th, 2009, 03:11 AM
proactivelover's Avatar
proactivelover proactivelover is offline
Frequent Poster
 
Join Date: Apr 2006
Location: Near Wilders Forums
Posts: 832
Default Re: False Positive

i email eset about this FP
link for Universal Extractor v1.6
http://www.filehippo.com/download_universal_extractor/
  #4  
Old February 27th, 2009, 06:53 AM
3nigma 3nigma is offline
Infrequent Poster
 
Join Date: Feb 2009
Posts: 5
Default Re: False Positive

Thanks for the quick response. This is the name of the threat that Eset detects
when i attempt to use Universal Extractor.

Quote:
Win32/Sohanad.NCB worm
Version of Virus Signature Database. 3893 (20090226)

Quote:
You can also send a copy of the file to ESET at samples@eset.sk inside a .ZIP or .RAR file protected with a password of "infected", a Subject: of "possible false positive" and a link to this message thread for examination by ESET's virus lab.

Ah,, thank you. I'll send them an email as soon as possible. Thanks for your assistance.
  #5  
Old February 27th, 2009, 03:52 PM
proactivelover's Avatar
proactivelover proactivelover is offline
Frequent Poster
 
Join Date: Apr 2006
Location: Near Wilders Forums
Posts: 832
Default Re: False Positive

3894 fixes this FP
  #6  
Old March 1st, 2009, 09:04 AM
3nigma 3nigma is offline
Infrequent Poster
 
Join Date: Feb 2009
Posts: 5
Default Re: False Positive

Yep, i restored the file from quarantine and scanned it with Eset. New definitions dont recognise it as a virus.

I have another False Positive to report. I use this program from time to time. Until yesterday i had it zipped on my external HDD, then when i unpacked it. Eset flagged it as a virus.

http://labs.idefense.com/software/malcode.php

Quote:
probably unknown NewHeur_PE virus

3895 (20090227)

  #7  
Old March 1st, 2009, 10:11 AM
funkydude's Avatar
funkydude funkydude is offline
Massive Poster
 
Join Date: Apr 2004
Posts: 5,986
Default Re: False Positive

http://kb.eset.com/esetkb/index?page=content&id=SOLN141
__________________
OpenDNS with DNSCrypt

SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs
HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere
  #8  
Old March 2nd, 2009, 12:32 PM
3nigma 3nigma is offline
Infrequent Poster
 
Join Date: Feb 2009
Posts: 5
Default Re: False Positive

Well, i sent them an email + Sample yesterday. No update as of yet unfortunately. Has anyone else downloaded this file and got the same result.
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET Smart Security « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:13 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums