in

eEye Digital Security

The endpoint to vulnerability starts here.

 

Legit Detections or False Positives?

Last post 06-15-2009 1:11 PM by Blue1978. 3 replies.
Page 1 of 1 (4 items)
Sort Posts: Previous Next
  • 06-12-2009 4:08 PM

    Legit Detections or False Positives?

    After Norman did it's scan it found several things that it quarantined fine according to my settings, but I'm pretty sure they are all False Positives or detections of txt versions of scripts I had hanging around from a backup I forgot to delete.  Is there a place to send these quarantined files for assessment?  I did submit to virustotal, and they confirmed that Norman was the only catcher on them.  Some I'm pretty sure are not malware.

     

     

    JRF
  • 06-14-2009 1:57 PM In reply to

    Re: Legit Detections or False Positives?

    I would recommend making a copy of the files that you think are false-positives, zip them with the password infected.  Be sure to include a link to your post here so someone can respond if need be.  Email this to malware@eeye.com.  eEye will have to send them to Norman so they can be corrected for you.

  • 06-15-2009 9:23 AM In reply to

    Re: Legit Detections or False Positives?

    I noticed the quarantine files are packed and they look like a known packer from a quick look, Would these do?  Or should I still pack these up as suggested?

    JRF
  • 06-15-2009 1:11 PM In reply to

    Re: Legit Detections or False Positives?

     You can use what is in the quarantine folder if you want.  Just zip them all up with the password "infected" on your zipped archive.  I think Norman has an upload limit of no more than 10 files, within one zip archive file and is not to exceed 10mb in size (if I remember correctly).  Make note in your email that you think they are false-positives.

Page 1 of 1 (4 items)
© 1995 - 2009 eEye Incorporated