View Full Version : a squared detects NOD32 setup exe
Ocky
September 29th, 2007, 06:26 AM
Another false positive from a2. Scan detects this:-
ndntenst.exe/advheur.nup detected: Heuristic.ArchiveBomb.
Thought I'd mention it in case someone gets the wrong impression. :P
(Not yet posted in a2 forum - am not a member).
Kosak
September 29th, 2007, 08:24 AM
Hi,
write to tech support of a-squared, please.:thumb:
ctrlaltdelete
September 29th, 2007, 03:56 PM
I did contact a-squared support a month ago about the detection of some *.nup files in several NOD32 setups.
Answer;
"Heuristic.ArchiveBomb means that is probably a file with a unpacking ratio
1:10000. You can add this file to the whitelist in the scannermodul to skip
the detection."
Maybe someone from Eset knows the unpacking ratio of the files....?
Kosak
September 29th, 2007, 04:25 PM
Are you using two AV products with switched on realtime protection?
GES/POR
September 29th, 2007, 06:29 PM
ive seen tons of those kind of detection wich are all bull and offcourse they wont fix m or else whats the point is usin a2 in a layered setup if it doesnt supposedly benefit.
Ocky
October 2nd, 2007, 03:53 AM
Have received the following reply from emsisoft regarding detection
of the NOD32 installer when scanning with a2. (viz: Heuristic.ArchiveBomb):-
{QUOTE-> the file is detected as Heuristic.Archivebomb, please read the description on
http://www.emsisoft.com/en/malware/?heuristic.archivebomb .
To skip the detection please add the file to the whitelist in the scanner.
<-QUOTE}
A bit complicated.
Marcos
October 2nd, 2007, 05:20 AM
{QUOTE-> Have received the following reply from emsisoft regarding detection
of the NOD32 installer when scanning with a2. (viz: Heuristic.ArchiveBomb):-
<-QUOTE}
It seems that our attorney will need to hunt them a bit if they insist on that approach and refuse to fix it ;)
GES/POR
October 2nd, 2007, 11:18 AM
For a change: Go go Marcos.:thumb:
deckie49
October 3rd, 2007, 04:04 PM
the good folks at a2 have known about this for some time. if you left click and add to whitelist, you will get the following:
Name: Heuristic.ArchiveBomb
Description:
Archive Bombs are not really Malware, but can crash Malware scanners.
The idea behind is simple: A Malware writer creates an archive file such as zip that is very small, but contains very large files. If a file is filled with the same characters, a 1 GB file can be compressed down to a few bytes. A Malware scan engine that supports scanning of archive files would try to unpack the content to the harddisk to scan, but fill up the disk with unpacked data until the system crashes.
Other archive bombs are manipulated archive files, that let the scanner unpack and scan in an endless loop.
The a-squared scan engine detects such archive bombs with a heuristic scan module. In some rare cases, regular archives are flagges as archive bombs if the content looks very similar to archive bombs.
interestingly enough, this is right below a nice advertisement to purchase the anti-malware program.
i_kenefick
October 3rd, 2007, 05:23 PM
Well, no serious company would allow a heuristic false positive being declared on a competing product not to be fixed. You can be sure that you weren't the only person to submit this file and you can also be sure that this researcher who replied wasn't the only one to receive it. They will fix this alright but how long it takes them depends on how much they value their customers. People generally get pissed off about security software breaking legitimate applications.
SamSpade
October 3rd, 2007, 06:46 PM
I ran A2 today and it came back w three false positives, including three different nod32 files plus a ccleaner file. A2 is wound a bit tight right now, it seems.
Denny
October 16th, 2007, 06:39 AM
{QUOTE-> I ran A2 today and it came back w three false positives, including three different nod32 files plus a ccleaner file. A2 is wound a bit tight right now, it seems. <-QUOTE}
NOD32 found AWPR.exe in the a2archive temp update files today and said it is probably a variant of the Win32/Genetk trojan. Quarantined/Deleted
I suspect this to be a FP as this is the update archive of a-squared.
If I was the cynical type, it would have crossed my mind that NOD32 is poking them in the eye.
D
Kosak
October 16th, 2007, 09:32 AM
Hi,
send this file to ESET tech support, please => http://www.eset.com/support/contact.php
:thumb:
ASpace
October 16th, 2007, 09:44 AM
{QUOTE-> Hi,
send this file to ESET tech support, please => http://www.eset.com/support/contact.php
:thumb: <-QUOTE}
You mean this one:
http://www.eset.com/threat-center/up/submit.htm
because with the above there is no way to send attachment
Kosak
October 16th, 2007, 09:46 AM
Thanks;)
ChicknDip
October 16th, 2007, 11:16 AM
Forget about a2, it ain't a malware scanner, it's a FP-generator on the fly.
vBulletin® Copyright ©2000-2009, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2009, Wilders Security Forums