<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Fenomen(al) False Positives</title>
	<atom:link href="http://research.pandasecurity.com/fenomenal-false-positives/feed/" rel="self" type="application/rss+xml" />
	<link>http://research.pandasecurity.com/fenomenal-false-positives/</link>
	<description>Leading the way in proactive malware detection</description>
	<lastBuildDate>Fri, 29 Jul 2011 08:21:04 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.4</generator>
	<item>
		<title>By: Pedro Bustamante</title>
		<link>http://research.pandasecurity.com/fenomenal-false-positives/comment-page-1/#comment-991</link>
		<dc:creator>Pedro Bustamante</dc:creator>
		<pubDate>Tue, 02 Sep 2008 14:36:11 +0000</pubDate>
		<guid isPermaLink="false">/archive/Fenomen_2800_al_2900_-False-Positives.aspx#comment-991</guid>
		<description>It seems that SwishMax2 is using multiple layers of run-time packing and/or a packer that is used by known malware.

We can add this to the exclusion list on the signature, but you might want to tell the SwishMax2 developers to not use malicious runtime packers. I see that other AV engines also detect this as malicious because of the same reason.</description>
		<content:encoded><![CDATA[<p>It seems that SwishMax2 is using multiple layers of run-time packing and/or a packer that is used by known malware.</p>
<p>We can add this to the exclusion list on the signature, but you might want to tell the SwishMax2 developers to not use malicious runtime packers. I see that other AV engines also detect this as malicious because of the same reason.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pedro Bustamante</title>
		<link>http://research.pandasecurity.com/fenomenal-false-positives/comment-page-1/#comment-990</link>
		<dc:creator>Pedro Bustamante</dc:creator>
		<pubDate>Mon, 01 Sep 2008 12:01:56 +0000</pubDate>
		<guid isPermaLink="false">/archive/Fenomen_2800_al_2900_-False-Positives.aspx#comment-990</guid>
		<description>Nobody at Panda answered me since 1 year when I ask about SwishMax2, a very nice flash web designer program I can&#039;t use anymore. 
Why?
Simply! Panda IS 2008 always says me that it is Malicious Paker inside!
CRAZY!
In the while I&#039;m losing money with my clients dued to Panda stupid interpretation of this paker...
No way to say Panda IS to avoid file analisys of this folder and/or file.exe of swishmax.
Look at various forums are talking of that!
</description>
		<content:encoded><![CDATA[<p>Nobody at Panda answered me since 1 year when I ask about SwishMax2, a very nice flash web designer program I can&#8217;t use anymore.<br />
Why?<br />
Simply! Panda IS 2008 always says me that it is Malicious Paker inside!<br />
CRAZY!<br />
In the while I&#8217;m losing money with my clients dued to Panda stupid interpretation of this paker&#8230;<br />
No way to say Panda IS to avoid file analisys of this folder and/or file.exe of swishmax.<br />
Look at various forums are talking of that!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pedro Bustamante</title>
		<link>http://research.pandasecurity.com/fenomenal-false-positives/comment-page-1/#comment-989</link>
		<dc:creator>Pedro Bustamante</dc:creator>
		<pubDate>Thu, 31 Jul 2008 07:47:34 +0000</pubDate>
		<guid isPermaLink="false">/archive/Fenomen_2800_al_2900_-False-Positives.aspx#comment-989</guid>
		<description>Thanks for the heads-up Norberto. We&#039;ll take a look at it and fix it.</description>
		<content:encoded><![CDATA[<p>Thanks for the heads-up Norberto. We&#8217;ll take a look at it and fix it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pedro Bustamante</title>
		<link>http://research.pandasecurity.com/fenomenal-false-positives/comment-page-1/#comment-988</link>
		<dc:creator>Pedro Bustamante</dc:creator>
		<pubDate>Wed, 30 Jul 2008 06:11:06 +0000</pubDate>
		<guid isPermaLink="false">/archive/Fenomen_2800_al_2900_-False-Positives.aspx#comment-988</guid>
		<description>Hi, My last Panda actualization deletes my Swish flash editor [www.swishzone.com] by a false positive error, same issue happened with Norton AV on May as you can see on Swish forums at http://forums.swishzone.com/index.php?showtopic=58210&amp;hl= , fortunately it was solved inmediately by Symantec.

I wrote to local Panda support and Panda support staf tells me I need to contact program vendor (Prodigy -a internet provider-). So I called Prodigy support, and Ms Beatriz Contreras simply tells me &quot;disable antivirus&quot;. What kind of support is this?

I want to known if this problem will be solved soon or if I need to get a new antivirus software.

Thanks</description>
		<content:encoded><![CDATA[<p>Hi, My last Panda actualization deletes my Swish flash editor [www.swishzone.com] by a false positive error, same issue happened with Norton AV on May as you can see on Swish forums at <a href="http://forums.swishzone.com/index.php?showtopic=58210&#038;hl=" rel="nofollow">http://forums.swishzone.com/index.php?showtopic=58210&#038;hl=</a> , fortunately it was solved inmediately by Symantec.</p>
<p>I wrote to local Panda support and Panda support staf tells me I need to contact program vendor (Prodigy -a internet provider-). So I called Prodigy support, and Ms Beatriz Contreras simply tells me &#8220;disable antivirus&#8221;. What kind of support is this?</p>
<p>I want to known if this problem will be solved soon or if I need to get a new antivirus software.</p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pedro Bustamante</title>
		<link>http://research.pandasecurity.com/fenomenal-false-positives/comment-page-1/#comment-987</link>
		<dc:creator>Pedro Bustamante</dc:creator>
		<pubDate>Fri, 04 Jul 2008 10:56:09 +0000</pubDate>
		<guid isPermaLink="false">/archive/Fenomen_2800_al_2900_-False-Positives.aspx#comment-987</guid>
		<description>Yes of course quding, FPs happen to every vendor. That&#039;s why its extremely important to invest in resources to control these FPs on a daily basis, more so with more automation involved in adding signatures.</description>
		<content:encoded><![CDATA[<p>Yes of course quding, FPs happen to every vendor. That&#8217;s why its extremely important to invest in resources to control these FPs on a daily basis, more so with more automation involved in adding signatures.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pedro Bustamante</title>
		<link>http://research.pandasecurity.com/fenomenal-false-positives/comment-page-1/#comment-986</link>
		<dc:creator>Pedro Bustamante</dc:creator>
		<pubDate>Mon, 30 Jun 2008 13:48:31 +0000</pubDate>
		<guid isPermaLink="false">/archive/Fenomen_2800_al_2900_-False-Positives.aspx#comment-986</guid>
		<description>Hi, I&#039;m using IS08, and very please with the performance. Regarding the FPs problems, i&#039;m just setting in firewall. The smartest brain is human&#039;s brain not computer&#039;s brain.</description>
		<content:encoded><![CDATA[<p>Hi, I&#8217;m using IS08, and very please with the performance. Regarding the FPs problems, i&#8217;m just setting in firewall. The smartest brain is human&#8217;s brain not computer&#8217;s brain.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pedro Bustamante</title>
		<link>http://research.pandasecurity.com/fenomenal-false-positives/comment-page-1/#comment-985</link>
		<dc:creator>Pedro Bustamante</dc:creator>
		<pubDate>Mon, 30 Jun 2008 12:43:50 +0000</pubDate>
		<guid isPermaLink="false">/archive/Fenomen_2800_al_2900_-False-Positives.aspx#comment-985</guid>
		<description>And what&#039;s more,&quot;Fenomen(al)&quot; is titled here,you constructed with a suffix &quot;al&quot;,does it mean to be an adjective word?
I mean,you predicated of yhe word that it is a class but not only a sigle one,didn&#039;t it?
In other words,in conclusion,not only Panda but also other vendors&#039; automation will appear such type of FPs?</description>
		<content:encoded><![CDATA[<p>And what&#8217;s more,&#8221;Fenomen(al)&#8221; is titled here,you constructed with a suffix &#8220;al&#8221;,does it mean to be an adjective word?<br />
I mean,you predicated of yhe word that it is a class but not only a sigle one,didn&#8217;t it?<br />
In other words,in conclusion,not only Panda but also other vendors&#8217; automation will appear such type of FPs?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pedro Bustamante</title>
		<link>http://research.pandasecurity.com/fenomenal-false-positives/comment-page-1/#comment-984</link>
		<dc:creator>Pedro Bustamante</dc:creator>
		<pubDate>Thu, 26 Jun 2008 10:09:33 +0000</pubDate>
		<guid isPermaLink="false">/archive/Fenomen_2800_al_2900_-False-Positives.aspx#comment-984</guid>
		<description>Yes quding there are other reasons that cause FPs other than automated systems. But I believe these FPs that are generated automatically can have a significant effect as the volume of FPs can grow very rapidly and affect users negatively unless more controls are added to these automated systems.</description>
		<content:encoded><![CDATA[<p>Yes quding there are other reasons that cause FPs other than automated systems. But I believe these FPs that are generated automatically can have a significant effect as the volume of FPs can grow very rapidly and affect users negatively unless more controls are added to these automated systems.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pedro Bustamante</title>
		<link>http://research.pandasecurity.com/fenomenal-false-positives/comment-page-1/#comment-983</link>
		<dc:creator>Pedro Bustamante</dc:creator>
		<pubDate>Mon, 23 Jun 2008 14:50:44 +0000</pubDate>
		<guid isPermaLink="false">/archive/Fenomen_2800_al_2900_-False-Positives.aspx#comment-983</guid>
		<description>OK,I agreed with what you said.
It makes sense to an extent.
If it is possible,i wanna communicate with you further about this issue.

Traditionally,How many reasons can cause FPs happen?
Currently,Are there any new reasons?besides &quot;automated&quot; here?

</description>
		<content:encoded><![CDATA[<p>OK,I agreed with what you said.<br />
It makes sense to an extent.<br />
If it is possible,i wanna communicate with you further about this issue.</p>
<p>Traditionally,How many reasons can cause FPs happen?<br />
Currently,Are there any new reasons?besides &#8220;automated&#8221; here?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pedro Bustamante</title>
		<link>http://research.pandasecurity.com/fenomenal-false-positives/comment-page-1/#comment-982</link>
		<dc:creator>Pedro Bustamante</dc:creator>
		<pubDate>Thu, 05 Jun 2008 17:29:27 +0000</pubDate>
		<guid isPermaLink="false">/archive/Fenomen_2800_al_2900_-False-Positives.aspx#comment-982</guid>
		<description>FPs have traditionally happened for other reasons (too generic signatures, poor QA, etc.). What I suggest on this post is a more recent method by which FPs appear because of &quot;automated&quot; signature generation systems.</description>
		<content:encoded><![CDATA[<p>FPs have traditionally happened for other reasons (too generic signatures, poor QA, etc.). What I suggest on this post is a more recent method by which FPs appear because of &#8220;automated&#8221; signature generation systems.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

