# False Positive Report - itzOpti.exe - Elastic

**URL:** <https://discuss.elastic.co/t/false-positive-report-itzopti-exe-elastic/385949>\
**Category:** Endpoint Security\
**Created:** [April 20, 2026, 5:35am UTC](https://discuss.elastic.co/t/false-positive-report-itzopti-exe-elastic/385949 "2026-04-20T05:35:43Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Luca1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca1/32/147371_2.png) [@Luca1](https://discuss.elastic.co/u/Luca1)\
**Post date:** [April 20, 2026, 5:35am UTC](https://discuss.elastic.co/t/false-positive-report-itzopti-exe-elastic/385949/1 "2026-04-20T05:35:43Z")

</div>

Hello,

I am reporting a false positive detection for my file.

Vendor: Elastic  
Detection name: Malicious (high Confidence)  
SHA256: 6ed1f7c0565b84201b7f9b7ed47eee7f73fddad453ae9e4ce7914369b9ad1311  
VirusTotal: [VirusTotal](https://www.virustotal.com/gui/file/6ed1f7c0565b84201b7f9b7ed47eee7f73fddad453ae9e4ce7914369b9ad1311/detection)

File: itzOpti.exe  
Type: Windows optimization utility compiled from PowerShell source using PS2EXE

Why this is a false positive:

- I created this tool myself; it is not malware
- It performs PC optimization (disable unused services, clean temp files, registry tweaks for gaming/performance)
- The detection is heuristic/ML-based triggered by PS2EXE packaging and system-level operations
- The original .ps1 source code is available for verification on request

Requested action: please review and whitelist/remove this false positive.

Thank you.

---

<div class="post-metadata">

**Author:** ![lesio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lesio/32/89323_2.png) [@lesio](https://discuss.elastic.co/u/lesio)\
**Post date:** [April 29, 2026, 9:40pm UTC](https://discuss.elastic.co/t/false-positive-report-itzopti-exe-elastic/385949/2 "2026-04-29T21:40:26Z")

</div>

There's an official channel for that

> [@Submitting False Positives](https://discuss.elastic.co/t/submitting-false-positives/232322):
>
> We welcome your False Positive (FP) report for Elastic’s malware detection engine. These FP reports help us improve our security products. Please note that as of June 5, 2024 we have updated our False Positive review process. Due to a high volume of spam and/or submissions not adhering to our guidelines, we will no longer accept email submissions. Please submit your False Positives via the [Elastic False Positive Submission Form](https://forms.gle/LSYYPu9iS4Ex5R8p8). Submissions received after June 5, 2024 via email will no longer …

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 27, 2026, 9:40pm UTC](https://discuss.elastic.co/t/false-positive-report-itzopti-exe-elastic/385949/3 "2026-05-27T21:40:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
