Solved Eset v5 keeps quarantining gotd programs?

Status
Not open for further replies.

clyde

Level 1
Thread author
Verified
Nov 14, 2012
138
Can someone tell me why EAV is doing this.It has been doing this for a while now :huh:
 

Exterminator

Community Manager
Verified
Staff Member
Well-known
Oct 23, 2012
12,527
I am assuming gotd is Giveaway of the day programs? does this happen on install?
Eset Antivirus and Smart Security both quarantine suspicious programs automatically. They could very well be a false positives but if you know them to be safe you can restore them and also make an exclusion in both real time protection and scan or one or the other.See the links below on how to remove from quarantine and add to exclusion list.

How do I restore a quarantined file in my ESET security product? (5.x)

How do I exclude certain files or folders from Real-time scanning? (5.x)

It's not a good idea to exclude a program or file unless your are sure it is safe.Certain programs come with toolbars ect. packed into their installers which most would not even realize these are ticked and will install with the program.This could be the reason for EAV quarantining the programs.
 
Upvote 0

clyde

Level 1
Thread author
Verified
Nov 14, 2012
138
When it tries to contact gotd when installing it freezes and Eset quarantines it.I'm assuming that gotd's are safe.I wanted todays giveaway.
 
Upvote 0
D

Deleted member 178

They are flagged as suspicious because each gotd softwares are packed in a different installer (including the time-limit) than the original one.
 
Upvote 0

clyde

Level 1
Thread author
Verified
Nov 14, 2012
138
Do you think I should just leave the antivirus settings as they are?Can I bypass the program from doing this?
 
Upvote 0
D

Deleted member 178

i dont think you can make a rule for that, just disable the AV during the installation, but be sure it is safe so check the file first in Virus Total in case of.
 
Upvote 0

gone

Level 1
Jul 10, 2012
43
Faced the same problem while installing yesterdays gotd.
setup detected as a variant of Win32/Kryptik.ELS trojan :(
 
Upvote 0
P

Plexx

clyde said:
Do you think I should just leave the antivirus settings as they are?Can I bypass the program from doing this?

Only way to bypass is to change the default settings to never clean and it will prompt you for what action you want to do.

another way is exclude it from scanning options.

They are modified installers that is why is being detected (most by PUP module).
 
Upvote 0
P

Plexx

Themida detection in NOD goes back to 2007 or 2008, if I remember correctly.

Like it has been said in this thread, it is detected as PUP due to installers being modified to its needs (no upgrades possible, no trial mode for shareware etc).
 
Upvote 0

miragez

New Member
Dec 5, 2012
13
The only way for this to be solve is at Themida side, their implementation is definitely good for developer to wrap their product but at the same time they are blocking certain headers from antivirus scanning it such as ESET. Such behavior will only make the whatever is pack within gotd as suspicious.
 
Upvote 0
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top