View Single Post
  #141  
Old March 18th, 2010, 08:42 AM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,846
Default Re: Heuristics in action

AntiVir ProActiv sounds very interesting, and with cloud based interactivity.

>

@pasha101

Good to know you like it, generally I hadn't seen that article before, so thanks for sharing

Don't pretend to understand the code eval.txt

Name:  eval.gif
Views: 343
Size:  1.5 KB

but i copied/pasted it into notepad and attempted to open it. Avira jumped right in

Name:  avev.gif
Views: 349
Size:  9.7 KB

Obviously it's perfectly safe to do this, as it's just a js test, of which there are many.

Avira isn't the only one to detect it

AntiVir 8.2.1.194 2010.03.17 HTML/Crypted.Gen

McAfee-GW-Edition 6.8.5 2010.03.18 Heuristic.Script.Crypted

As long as people understand that Heuristics is a clever way of recognising potential malware, and realise that sometimes FP will naturally occur. One vendors Heuristics isn't the same as anothers, some will be more keen which can lead to detects that look like malware due to the code. Better safe than sorry though i think.

I've sent the eval.txt to Avira as a FP with the link, but due to the above scan and Stefan Kurtzhals input in here, they should already be aware of it. Having said that, he didn't seem too concerned when he posted about it