heuristic and signature based detection

Discussion in 'other anti-virus software' started by shek, Apr 12, 2005.

Thread Status:
Not open for further replies.
  1. shek

    shek Registered Member

    Joined:
    Mar 27, 2005
    Posts:
    342
    Location:
    SE CHINA/NYC USA
    Hello everyone,

    one month ago, i started to use antivir pe and it got a false positive warning, Heuristic/Trojan.Downloader. Then I sent the file to antivir. next day antivir updated its VDF(virus definition file) and the problem solved. It is not the end of the story. Today, i update the VDF as usual and antivir again got another false positive warning to the same file, Heuristic/Trojan.Downloader.

    How could it be? since the Heuristic dection doesn't rely on the virus definition, why could the false positive disappear and show up again by changing the VDF? Any comments or ideas?

    shek
     
  2. BlueZannetti

    BlueZannetti Registered Member

    Joined:
    Oct 19, 2003
    Posts:
    6,590
    shek,

    The program could be responding to a distinctly different segment of code or a result of a follow-up refinement of their module. In either case, I'd resend the file in question.

    Blue
     
  3. shek

    shek Registered Member

    Joined:
    Mar 27, 2005
    Posts:
    342
    Location:
    SE CHINA/NYC USA
    i did resend the file. my question is why with the update of VDF, the false positive detected by heuristic, not by signature, shows up again. I assume the heuristic code analyzer should be modified at the first time i sent the file and the VDF has nothing to do with the heuristic code.
     
  4. RejZoR

    RejZoR Lurker

    Joined:
    May 31, 2004
    Posts:
    6,426
    Exclusions are signature driven,thats why. They probably just mixed up some files probably. Got the same problem while ago with ArcaVir. They fixed FP,but it was back after 1 month. Human error factor ;)
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.