False positive doodling.org.uk

Discussion in 'NOD32 version 2 Forum' started by Nick, Dec 5, 2006.

Thread Status:
Not open for further replies.
  1. Nick

    Nick Registered Member

    Joined:
    May 14, 2002
    Posts:
    187
    Location:
    California
    A few people have posted over at Castle Cops about this site generating an alert from NOD 32, hXXp://www.doodling.org.uk/startups/bad_startupsall.htm.

    You can see the talk at Castle Cops here. There's a link to a screen shot of the alert a few posts into the topic.

    I've submitted the file to Eset using the internal submit for analysis in NOD 32. The alert is listed as a BAT/generic trojan, which sounds like a heuristic detection.

    Thanks for looking into this.
     
    Last edited by a moderator: Dec 5, 2006
  2. Blackspear

    Blackspear Global Moderator

    Joined:
    Dec 2, 2002
    Posts:
    15,115
    Location:
    Gold Coast, Queensland, Australia
    Here is a screenshot.

    Please also send a email to support @ eset.com with a link to this thread.

    Cheers :D
     

    Attached Files:

  3. Bubba

    Bubba Updates Team

    Joined:
    Apr 15, 2002
    Posts:
    11,271
    To narrow it down further....if one goes to the Index of /startups page....the only alpha\numeric on this end that burps with that same Nod alert is http://www.doodling.org.uk/startups/bad_startups_c.htm

    It appears it does not like the description of the chart.vbs I-Worm.Gigger worm contained in the bad_startups_c.htm file.
     

    Attached Files:

    Last edited: Dec 5, 2006
  4. kjempen

    kjempen Registered Member

    Joined:
    May 6, 2004
    Posts:
    379
    Is it really considered a "false positive" when they put parts of the source code of a malicious script in a malware description?
     
  5. pykko

    pykko Registered Member

    Joined:
    Apr 27, 2005
    Posts:
    2,236
    Location:
    Romania...and walking to heaven
    well, I think not quite. As IC suggested once, it is usefull to post that code as a picture not text and so it will result in no FP. :D
     
Thread Status:
Not open for further replies.