Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-virus software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 31st, 2007, 05:26 AM
Arin's Avatar
Arin Arin is offline
Frequent Poster
 
Join Date: May 2004
Location: India
Posts: 997
Default trend micro heuristic?

Pattern Version: 4.381.00
Release Type: New Malware Threat
Notes: WORM_WOMBLE.AB

March 30, 2007, 13:03:07 (GMT - 08:00)

---------------------
New Virus Detected:
---------------------
There are [426] new virus detected by the pattern file.
All detailed virus names please refer to the list below.

BKDR_AGENT.LQX
BKDR_AGENT.LZL
BKDR_AGENT.MBP
BKDR_AGENT.MID
BKDR_BIFROSE.VR
BKDR_BIFROSE.VU
BKDR_BIFROSE.WE
BKDR_DELF.EHF
BKDR_GRAYBIRD.RS
BKDR_HEURISTI.AL
BKDR_HEURISTI.AM

BKDR_HUPIGON.CWH
BKDR_HUPIGON.CXP

This is a part from the page which gets updated with every virus pattern file update. Now the virus information page says nothing much about this bug. So is it their new heuristics or just some fancy bug named heuristik and its variants? If its heuristics then why they don't bother letting the users know about the feature?

Yeah yeah I know about the av-comparatives result but its a simple question so product bashers stay out.
__________________
If it was so, it might be; and if it were so, it would be; but as it isn't, it ain't. That's logic. ~ Twiddledee
  #2  
Old March 31st, 2007, 07:04 AM
Sjoeii's Avatar
Sjoeii Sjoeii is offline
Very Frequent Poster
 
Join Date: Aug 2006
Location: 52°18'51.59"N + 4°56'32.13"O
Posts: 1,240
Default Re: trend micro heuristic?

The new heuristic engine is being tested as we speak. It is being tested by a few named testers all over the world. I have to say it works great .
  #3  
Old March 31st, 2007, 07:45 AM
Sputnik's Avatar
Sputnik Sputnik is offline
Very Frequent Poster
 
Join Date: Feb 2005
Location: Москва
Posts: 1,198
Default Re: trend micro heuristic?

Quote:
Originally Posted by Sjoeii
The new heuristic engine is being tested as we speak. It is being tested by a few named testers all over the world. I have to say it works great .
Agreed here, also I'm one of the testers. Especially the false positives rate is very low, and I see more and more heuristic detections.
__________________
"Proud openSUSE user."
  #4  
Old March 31st, 2007, 09:06 AM
Arin's Avatar
Arin Arin is offline
Frequent Poster
 
Join Date: May 2004
Location: India
Posts: 997
Default Re: trend micro heuristic?

Thats excellent news! Well now I remember IBK saying this longtime ago about Trend Micro's heuristics based detection. I simply forgot it. Now I looked carefully and found some heuristic detection for trojans, dialers, packed malwares and password protected malwares. So its in the current engine version 8.320.1004. What is the version you guys are testing? Whats new in that?
__________________
If it was so, it might be; and if it were so, it would be; but as it isn't, it ain't. That's logic. ~ Twiddledee
  #5  
Old March 31st, 2007, 12:16 PM
Sputnik's Avatar
Sputnik Sputnik is offline
Very Frequent Poster
 
Join Date: Feb 2005
Location: Москва
Posts: 1,198
Default Re: trend micro heuristic?

We (currently) use the same engine, though we use custom signatures.
__________________
"Proud openSUSE user."
  #6  
Old March 31st, 2007, 12:34 PM
mrhero mrhero is offline
Frequent Poster
 
Join Date: Jul 2005
Location: Ankara , Turkey
Posts: 297
Default Re: trend micro heuristic?

Hi sputnik, In my system new heuristics flags packed crack files as malware. But I know they aren't malware only keygens, cracks, etc. This type of behavior likes Sophos, Quickheal and Fortinet and not a good behavior IMO.
  #7  
Old March 31st, 2007, 02:22 PM
Sputnik's Avatar
Sputnik Sputnik is offline
Very Frequent Poster
 
Join Date: Feb 2005
Location: Москва
Posts: 1,198
Default Re: trend micro heuristic?

@mrhero
True, on some more "exotic" packers it will cause false positives. Please notice that most of these packers are used on cracks, keygens, hacktools and stuff like that. So it shouldn't be any problem for most Trend Micro users.

Though I'm in touch with the beta team regarding exe-packers for some months now, and they are working on it.
__________________
"Proud openSUSE user."
 

Wilders Security Forums > Security Products > other anti-virus software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 11:57 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums