View Full Version : Virus Bulletin April 2007 - Linux Server
FRug
April 2nd, 2007, 02:05 PM
Only quickresults publicly available (requires free registration) at
http://www.virusbtn.com/vb100/archive/2007/04
Alwil Status: PASS
Avira Status: PASS
CA eTrust Status: FAIL
CAT QuickHeal Status: PASS
Doctor Web Status: FAIL
Eset Status: FAIL
FRISK Status: FAIL
F-Secure Status: PASS
Grisoft Status: PASS
Kaspersky Status: PASS
McAfee Status: PASS
MicroWorld Status: FAIL
Norman Status: PASS
Sophos Status: PASS
Symantec Status: PASS
VirusBuster Status: PASS
lodore
April 2nd, 2007, 02:11 PM
that looks like normal results but im surprised that eset failed.
anyone know why?
lodore
HiTech_boy
April 2nd, 2007, 02:21 PM
{QUOTE-> that looks like normal results but im surprised that eset failed.
anyone know why? <-QUOTE}
Two possible reason :
either a false positive or missed a virus
IBK
April 2nd, 2007, 02:31 PM
1 false alarm due improved DOS heuristic (flagged as "probably ...").
pykko
April 2nd, 2007, 02:34 PM
{QUOTE-> 1 false alarm due improved DOS heuristic (flagged as "probably ..."). <-QUOTE}
not so bad. :)
Inspector Clouseau
April 2nd, 2007, 02:42 PM
{QUOTE-> 1 false alarm due improved DOS heuristic (flagged as "probably ..."). <-QUOTE}
Not fully correct. 32 missed DOS Samples as well. (32 Replicated Samples)
Edit: Just to clarify: That's the printed reason, however the heuristic f/p is the reason for denied award
lucas1985
April 2nd, 2007, 03:10 PM
So, ESET missed 32 DOS viruses (replicated from a unique variant or 32 variants?) and had a FP generated by heuristics?
What about FRISK?
JimIT
April 2nd, 2007, 03:44 PM
http://ryanduff.net/images/wordpress/chickenlittle.jpg
Firecat
April 2nd, 2007, 03:53 PM
So, Eset's record of VB100 is finally broken :D
Lets see what Eset comes up with this time....Anyway, strange thing is...MicroWorld fails and Kaspersky passes? ???
RejZoR
April 2nd, 2007, 04:20 PM
In case of MicroWorld, i'd say false positives...
Firecat
April 2nd, 2007, 04:24 PM
{QUOTE-> In case of MicroWorld, i'd say false positives... <-QUOTE}
From where? It uses KAV engine, the only place FPs would come from is their own MWAV tool, which also uses their custom spyware detection engine. However, the on-access and on-demand scans in the commercial version of eScan do not use this engine, as far as I know...
AMRX
April 3rd, 2007, 05:25 AM
I don't like MicroWorld, its buggy as hell. But yeah the result surprised me. Eset didn't surprise me. Frankly speaking it had to come one day. Quickheal is doing good in VB but they should really fix their f/p problem with packers. I guess they are taking one step at a time.
One question to the experts, how much threat does those DOS bugs pose now? I mean do you really get such incidence in real world?
HiTech_boy
April 3rd, 2007, 05:31 AM
{QUOTE-> Eset didn't surprise me. Frankly speaking it had to come one day <-QUOTE}
Hey , nothing so bad has happened . This is not the first time since 1998 when ESET misses VB100% award . This is the 4th time NOD32 misses VB100% award since 1998 . But it still remains the one that have more VB100% awards than any other product
HiTech_boy
April 3rd, 2007, 03:27 PM
I am very disappointed . As long as I rememer myself , I have always been able to download the VirusBulletin report to see how vendors perform . However , now I can't because they want me pay them 175 USD .
RejZoR
April 3rd, 2007, 07:01 PM
{QUOTE-> From where? It uses KAV engine, the only place FPs would come from is their own MWAV tool, which also uses their custom spyware detection engine. However, the on-access and on-demand scans in the commercial version of eScan do not use this engine, as far as I know... <-QUOTE}
Obviously you don't understand it. Though i'd expect you would...
Base engine might be KAV's, but they use their own heuristics, be it based on KAV engine or their own. Still it produces large amounts of false positives.
Firecat
April 3rd, 2007, 09:30 PM
{QUOTE-> Obviously you don't understand it. Though i'd expect you would...
Base engine might be KAV's, but they use their own heuristics, be it based on KAV engine or their own. Still it produces large amounts of false positives. <-QUOTE}
Their own heuristics? Now this is new to me. No wonder I do not understand. :)
In the time I used it, they were using KAV's own heuristic only...though there were a bunch of "suspicious" detections logged which would not be reported on the main GUI itself during scanning (you'd have to see the log to get this), but I never figured this.
Durad
April 3rd, 2007, 10:22 PM
eSafe has many FP's. I used their on-demand scanner that wes FREE durin last 2-3 months.
IBK
May 4th, 2007, 01:54 PM
http://www.virusbtn.com/news/vb_news/2007/05_04.xml?rss=
HiTech_boy
May 4th, 2007, 01:57 PM
Flawless perfection , as always ;) Congratulations , ESET !
vBulletin® Copyright ©2000-2008, Jelsoft Enterprises Ltd.