False positive with 5757: math.dll from NSIS (Nullsoft Scriptable Install System)

J

Jason McKinnon

Hi again,

Once again, math.dll (one of the standard NSIS standard plugins) has
reappeared on the false positive charts.

The full path of the file (in its default installation location) is
"c:\program files\nsis\plugins\math.dll".
It is being detected as "Begin2Search (Browser Plug-in)", which is
classified as a "High" threat level, with a default action of "Remove".

Is there anything that can be done to prevent the same file that has been
repeatedly declared non-spyware from falling prey to yet another faulty
signature? This is the third signature set that has incorrectly identified
math.dll as a spyware component (5709 and 5711 were the previous ones to
target this particular component).

Incidentally, I have also just filed a report on the false positive
reporting page at
http://www.microsoft.com/athome/security/spyware/software/isv/fpform.aspx

Thanks,
Jason
 
B

Bill Sanderson

Sorry to hear this--thanks for the report.

You've reported it in the right places, but I'll make an additional report
myself, using your message.
 
J

Jason McKinnon

This email is just to confirm that the problem below in 5757 has now been
corrected in 5761.

Thanks again,
Jason
 
B

Bill Sanderson

Glad they are keeping the responsiveness pretty high--'course, not having it
come up in the first place'd be nicer, I'm sure.
--
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top