CIS version: 3.9.95478.509
DB version: 1164
I’ve just scanned my PC with heuristic set to High and CIS found few files as Heur.Packed.Unknown which are FP.
Edit: Since all of FPs have been fixed with DB 1174 I removed unnecessary links which made this post huge.
Heur.Packed.Unknown RADVideo\radana.exe
Heur.Packed.Unknown VSD Software\GoOff!\gooff.exe
Heur.Packed.Unknown WapSter AQQ\System\DelZip179.dll
Heur.Packed.Unknown WinRAR\Default.SFX
Heur.Packed.Unknown WinRAR\WinCon.SFX
Heur.Packed.Unknown WinRAR\Zip.SFX
Heur.Packed.Unknown DPT.exe
Heur.Packed.Unknown HD_Speed 1.5.2\HD_Speed_ENG.zip|hd_speed.exe
Heur.Packed.Unknown wyklad_6_-_przyklady.exe
Hi fOrTy_7,
Thankyou for reporting the false positive. We shall get back to you after investigation.
Regards,
Sriram.P
llama
#3
CIS version: 3.9.95478.509
DB: 1168
Windows XP SP3 French
Heuristic set to high
same false positive on:
/windows/system32/adortl70.bpl
/windows/system32/inet70.bpl
verified on virustotal
edit: seems fixed now
gmohan
#4
hi llama,
We will have a look at it, We will get back to you after investigation
Regards,
-Chandra Mohan
I removed from the list the FP which have been fixed with virus database 1172 from my previous post. Two new FP have been introduced.
[tr]
[td]Malware name[/td]
[td]Filename[/td]
[td]Status(virustotal.com)[/td]
[/tr]
[tr]
[td]Heur.Packed.Unknown[/td]
[td]bass_ape.dll[/td]
[td]Scan results[/td]
[/tr]
[tr]
[td]Heur.Packed.Unknown[/td]
[td]bass_cda.dll[/td]
[td]Scan results[/td]
[/tr]
These two DLLs and the other files which haven’t been fixed yet are attached to this post as a zip archive.
[attachment deleted by admin]
gmohan
#6
Hi fOrTy_7,
Thanks for FP reporting
We will get back to you when it will be fixed.
Regards,
-Chandra Mohan
After database update to version 1174, only BASS DLLs have left. All other FP have been fixed. Thanks guys for your hard work. :-TU
CIS version: 3.9.95478.509
DB version: 1174
[tr]
[td]Malware name[/td]
[td]Filename[/td]
[td]Status(virustotal.com)[/td]
[/tr]
[tr]
[td]Heur.Packed.Unknown[/td]
[td]p.exe[/td]
[td]Scan results[/td]
[/tr]
[attachment deleted by admin]
HI
i use Miranda IM Client and my CIS (3.8.64263.468)
false scan alert by ‘Heur.Packed.Unknown’
but VT show 0\34 result. =
what does it mean ??
Thx…
gmohan
#10
Hi fOrTy_7,
The reported FP is under our consideration,
We will get back to you after investigation,
Thanks for reporting.
-Chandra Mohan
gmohan
#11
Hi vector.x86,
Please update your Product as well as database.
Check the detection and let us know.
The latest is as on May-20-2009
Product version : 3.9
Database version: 1176
Regards,
-Chandra Mohan
gmohan
#13
Hi fOrTy_7,
Thanks for confirming with DB 1174.
FP regarding BASS DLLs will be fixed in few updates.
Regards,
-Chandra Mohan
gmohan
#14
Hi fOrTy_7,
Mentioned FP is fixed DB 1177.
Please verify.
Regards,
-Chandra Mohan
Yes, p.exe FP has been fixed. Thanks.
gmohan
#16
Hi fOrTy_7,
Mentioned FP has been fixed in DB v1179
Please update your database and confirm.
Regards,
-Chandra Mohan
Yes, those have been fixed in DB 1179. Thank you.