False positive doodling.org.uk

Discussion in 'NOD32 version 2 Forum' started by Nick, Dec 5, 2006.

Thread Status:
Not open for further replies.
  1. Nick

    Nick Registered Member

    Joined:
    May 14, 2002
    Posts:
    187
    Location:
    California
    A few people have posted over at Castle Cops about this site generating an alert from NOD 32, hXXp://www.doodling.org.uk/startups/bad_startupsall.htm.

    You can see the talk at Castle Cops here. There's a link to a screen shot of the alert a few posts into the topic.

    I've submitted the file to Eset using the internal submit for analysis in NOD 32. The alert is listed as a BAT/generic trojan, which sounds like a heuristic detection.

    Thanks for looking into this.
     
    Last edited by a moderator: Dec 5, 2006
  2. Blackspear

    Blackspear Global Moderator

    Joined:
    Dec 2, 2002
    Posts:
    15,115
    Location:
    Gold Coast, Queensland, Australia
    Here is a screenshot.

    Please also send a email to support @ eset.com with a link to this thread.

    Cheers :D
     

    Attached Files:

  3. Bubba

    Bubba Updates Team

    Joined:
    Apr 15, 2002
    Posts:
    11,271
    To narrow it down further....if one goes to the Index of /startups page....the only alpha\numeric on this end that burps with that same Nod alert is http://www.doodling.org.uk/startups/bad_startups_c.htm

    It appears it does not like the description of the chart.vbs I-Worm.Gigger worm contained in the bad_startups_c.htm file.
     

    Attached Files:

    Last edited: Dec 5, 2006
  4. kjempen

    kjempen Registered Member

    Joined:
    May 6, 2004
    Posts:
    379
    Is it really considered a "false positive" when they put parts of the source code of a malicious script in a malware description?
     
  5. pykko

    pykko Registered Member

    Joined:
    Apr 27, 2005
    Posts:
    2,236
    Location:
    Romania...and walking to heaven
    well, I think not quite. As IC suggested once, it is usefull to post that code as a picture not text and so it will result in no FP. :D
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.