false positives a question of taste or is it?

Discussion in 'other anti-virus software' started by larryb52, Oct 20, 2008.

Thread Status:
Not open for further replies.
  1. Judge Dee

    Judge Dee Guest

    I've never admitted this to anyone, especially my wife. :oops: Several years ago I was using f-prot for dos with a switch that created extra strong heuristics. It flagged explorer.exe. as a trojan. Without thinking at all, I had f-prot delete it.
    Man was I upset at myself!o_O
    I learned the hard way to pay attention.

    PS. I still haven't told my wife.
     
  2. TonyW

    TonyW Registered Member

    Joined:
    Oct 12, 2005
    Posts:
    2,741
    Location:
    UK
    You should be able to submit a file if you think it's suspicious. I submitted a file to KL a few days ago as it had a double extension i.e. .doc.exe with a long space between the .doc and .exe. Scanning it at the highest settings yielded no alerts, but I was wary of that file so I sent it for analysis. It turned out to be malware and KL added detection for it to their database.
     
  3. lodore

    lodore Registered Member

    Joined:
    Jun 22, 2006
    Posts:
    9,065
    fp's should be minimized as much as possible since most users wont be able to tell and just follow the reccomendation of there AV.
     
  4. Zombini

    Zombini Registered Member

    Joined:
    Jul 11, 2006
    Posts:
    469
    Thats exactly what I was referring to. As soon as you get hit with a really bad FP, you then start questioning using any products that have lots of FPs.
     
  5. Zombini

    Zombini Registered Member

    Joined:
    Jul 11, 2006
    Posts:
    469
  6. Macstorm

    Macstorm Registered Member

    Joined:
    Mar 7, 2005
    Posts:
    2,642
    Location:
    Sneffels volcano
  7. larryb52

    larryb52 Registered Member

    Joined:
    Feb 16, 2006
    Posts:
    1,131
    I'm starting to change my mind here as I use Nod32v3 & of course extremely low FP's but my machines have been hit hard & clean up is timely. Granted FP's for the untrained eye is NOT good & those that are inexperience using 'say' kaspersky will not be 'techie' enough to know there exe's & processes & create a nightmare for their machines. I have become a convert to kaspersky but I'd like to think I know my stuff. NO I'm not all intelligent but I will say I respect the fact the kaspersky forum is there & answers come quickly. In these trying times of new malware you can't be too careful & I'm starting to see the value of a ounce of caution (FP) is worth a pound of cure (or time & effort)...
     
  8. gery

    gery Registered Member

    Joined:
    Mar 8, 2008
    Posts:
    2,175
    Avg gave me some hard time today so i finally ditched it . It finds Bitdefenders files as spyware (some installation files of BD free ) and i checked it then with some other Av and it was a false alarm. recently i had 6 false alarms. back to trend micro
     
  9. Dark Shadow

    Dark Shadow Registered Member

    Joined:
    Oct 11, 2007
    Posts:
    4,553
    Location:
    USA
    Yes absolutley agree,I am just refering to If one does not see a suspicious file or the antivirus does not see it either.
     
  10. Dark Shadow

    Dark Shadow Registered Member

    Joined:
    Oct 11, 2007
    Posts:
    4,553
    Location:
    USA
    Hey do not feel bad when first started computing,I went on a trigger happy deleting stuff that should not have been deleted.OPPS:blink: what a Mess.If we Do Not make mistakes then whats there to learn.Once my friend and I took a car engine apart to replace a cam shaft,the valves and lifters and some other things We put a 3/4 race cam and performanced the engine when we where done it started up:D but we had a few extra bolts we discoverd laying around:blink: Needles to say the car ran for yrs with out problems at least that we new about.
     
  11. TonyW

    TonyW Registered Member

    Joined:
    Oct 12, 2005
    Posts:
    2,741
    Location:
    UK
    My point was the AV didn't see it initially, but I was clued up enough to submit the file to be checked just in case.
     
  12. risl

    risl Registered Member

    Joined:
    Dec 8, 2006
    Posts:
    581
    As a more "experienced" user I like to have aggressive heuristics and then decide myself if a file is malicious or not. Therefore I have no problem using Dr.Web that is somewhat known to produce false positives. Had a few during my time with it and all were quickly fixed.
     
  13. Dark Shadow

    Dark Shadow Registered Member

    Joined:
    Oct 11, 2007
    Posts:
    4,553
    Location:
    USA
    I Understand what your saying but keep in mind that you have the knowledge to spot something of a suspicious nature or a file that may not look wright,even if your uncertain its infected you where aware of something but Not everyone does have this knowledge.
     
  14. Ed_H

    Ed_H Registered Member

    Joined:
    Nov 10, 2004
    Posts:
    662
    Location:
    Chicago, IL
    I had the same experience with NOD32 V3. Way too much time spent cleaning up or restoring images. My machines now either have Avira or Kaspersky and I get occasional FP's but no infections. So, I don't mind researching an alert once in a while. That's a good trade off to me.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.