PDA

View Full Version : Buggy advanced heuristics


Megachip
October 5th, 2007, 10:17 AM
Hello Eset, hello community ...

As seen in this (http://www.wilderssecurity.com/showthread.php?p=1071562) and many other threads, nod seems to get trouble with his previously excellent heuristics...

Seems it have problems with bigger textfiles... (aprox 20 MB).

Can someone confirm this?
Can ESET try to find the bug... (IMHO in former times nod didn't had so much false positives)

Here some new false positives (sorry, at the moment i did have the files to send them to eset)

-{ Quote: "
Log Details
F:\nc2006\iCH-MET-ECMWF-IFS-A+2006_239_06_0055.txt - probably a variant of BAT/CopyToAll.H virus - quarantined - deleted
Log Details
F:\nc2006\iCH-MET-ECMWF-IFS-A+2006_212_00_0005.txt - probably a variant of VBS/Pajamas.X trojan - quarantined - deleted
Log Details
F:\nc2006\iCH-MET-ECMWF-IFS-A+2006_134_06_0055.txt - BAT/FormatAll.D trojan - quarantined - deleted
Log Details
F:\nc2006\iCH-MET-ECMWF-IFS-A+2006_115_18_5555.txt - BAT/Kia.A virus - quarantined - deleted
Log Details
F:\nc2006\iCH-MET-ECMWF-IFS-A+2006_113_06_0055.txt - HTML/Citifraud.AC trojan - quarantined - deleted
Log Details
F:\nc2006\iCH-MET-ECMWF-IFS-A+2006_090_12_0555.txt - probably a variant of BAT/Haltwin.K trojan - quarantined - deleted
Log Details
F:\nc2006\iCH-MET-ECMWF-IFS-A+2006_090_06_0055.txt - probably a variant of IRC/Smev.A trojan - quarantined - deleted
Log Details
F:\nc2006\iCH-MET-ECMWF-IFS-A+2006_069_00_0005.txt - probably a variant of BAT/Codered.A virus - quarantined - deleted
Log Details
F:\nc2006\iCH-MET-ECMWF-IFS-A+2006_056_06_0055.txt - probably a variant of Unix/Exploit.Generic.B trojan - quarantined - deleted
" }-

4 some of our employees its very hard to work, if they even get an virus alert and didn't know what they have done false... (nothing because false positive)

I hope the problem will be fixed soon...

Regards Meg

Marcos
October 5th, 2007, 01:07 PM
This is not heuristic detection, it's signature based. Could you please compress the files with RAR/ZIP and upload it to our ftp as you did last time? Let me know when done.

Megachip
October 12th, 2007, 12:56 PM
Seems that all FP's are fixed... THX to Marcos, THX to eset...

but why nod use 99% of cpu when checking big (aprox 12 mb) compressed files?

Regards

Marcos
October 12th, 2007, 04:30 PM
-{ Quote: "Seems that all FP's are fixed... THX to Marcos, THX to eset...
" }-

You're welcome ;)

-{ Quote: "
but why nod use 99% of cpu when checking big (aprox 12 mb) compressed files?
" }-

In my opinion, this has probably something to do with parsing large logs. This could be probably fixed by parsing only a couple of the first lines of a text file, but on the other hand this might open a potential security hole. I'll ask our developers about this.

Megachip
October 25th, 2007, 08:32 AM
Upped again 2 FPs... hopefully this help to identify the problem...


Regards :(