NOD32's latest update, virus signature database 5432, is now reporting RemoteDesktopManager as a trojan.
Please see attached file.
Honestly, I'm somewhat disappointed with ESET as of late.
edited by cthrockmorton on 9/7/2010
NOD32.JPG
Wow,
I can assure you that there is no trojan in the application. What version do you have? what is ESET?
David Hervieux
Hi David,
ESET is the company that makes NOD32. Don't worry, I beleive you 100%.
I've got the latest version of NOD32 installed, v4.2.64.12 (or at least it's close to the latest version if they've put an update out). However, it's the virus definition update, 5432, that's the problem.
A recent update from NOD32 caused servers and workstations to crash at our customers sites all over the country, so I'm not happy with ESET to begin with right now. Now this.
I'm just letting you know that ESET's virus definition update is currently giving a false positive on RemoteDesktopManager. Hope this helps someone else using Remote Destop Manager.
Best regards,
ct
Just wanted to pass along that I just ran into the same thing with 5432 update. ESET is an antimalware suite. http://www.eset.com/
Thx!
Bryan
greenshot_2010-09-07_10-49-01.png
greenshot_2010-09-07_10-28-28.png
Same here.
Here is what we did to solve the problem:
First, restore the executable:
Next, add the RemoteDesktopManager executable to the exclusions:
Hope that helps.
Cheers!
Benoit
Hi,
Can you verify if you get the error with this internal build:
http://remotedesktopmanager.com/download/Setup.RemoteDesktopManager.5.8.3.0.exe
David Hervieux
Devolutions inc.
edited by dhervieux on 9/8/2010
David Hervieux
Yes, I do.
NOD32[1].JPG
You get the error even in the setup ? Wow, I will install nod32 and see what might be the problem
edited by dhervieux on 9/7/2010
David Hervieux
Hi David,
Not even running the setup. Simply trying to download it. NOD32 scans the files that are coming into the sytem.
You might want to get in touch with NOD32 support. They may resolve the issue in their next virus definition update.
Best regards,
ct
David,
I think the most important thing to do is insure that your customers are aware of the false positive from ESET and know how to resolve the issue.
Benoit's post is quite good at giving details on how to resovle the issue.
Best regards,
ct
Hi,
I will do some test in the next few hours, I think NOD32 does not like my assembly compression.
David Hervieux
Hi,
I removed the compression and keep the obfuscation and NOD32 seems to work fine. The result for you is only a bigger executable. I also notified the company about this problem and I hope to get a response soon. Thank you all for you support and again sorry about that:
http://remotedesktopmanager.com/download/Setup.RemoteDesktopManager.5.8.2.6.exe
David Hervieux
Hi David,
That works perfectly! When you get the resolved with ESET, I'm certainly willing to try the compressed EXE version for you.
Best regards,
ct
Hi,
Thank you very much. I got a very hard day, you post give me some hope :)
David Hervieux
Hi,
I got an answer from ESET:
Dear Devolutions inc.,
Thank you for your submission.
It is a false positive of our scanner and this issue will be fixed in our next signature update.
Regards,
Tomasz Smolarek
Virus Researcher
ESET spol. s r.o.
David Hervieux
Hi,
Here is a new version with some small fixed:
http://remotedesktopmanager.com/download/Setup.RemoteDesktopManager.5.8.3.0.exe
David Hervieux