Heur.Packed.Unknown - few FP

CIS version: 3.9.95478.509
DB version: 1164

I’ve just scanned my PC with heuristic set to High and CIS found few files as Heur.Packed.Unknown which are FP.

Edit: Since all of FPs have been fixed with DB 1174 I removed unnecessary links which made this post huge.

Heur.Packed.Unknown RADVideo\radana.exe
Heur.Packed.Unknown VSD Software\GoOff!\gooff.exe
Heur.Packed.Unknown WapSter AQQ\System\DelZip179.dll
Heur.Packed.Unknown WinRAR\Default.SFX
Heur.Packed.Unknown WinRAR\WinCon.SFX
Heur.Packed.Unknown WinRAR\Zip.SFX
Heur.Packed.Unknown DPT.exe
Heur.Packed.Unknown HD_Speed 1.5.2\HD_Speed_ENG.zip|hd_speed.exe
Heur.Packed.Unknown wyklad_6_-_przyklady.exe

Hi fOrTy_7,

Thankyou for reporting the false positive. We shall get back to you after investigation.

Regards,
Sriram.P

CIS version: 3.9.95478.509
DB: 1168
Windows XP SP3 French
Heuristic set to high

same false positive on:

/windows/system32/adortl70.bpl
/windows/system32/inet70.bpl

verified on virustotal

edit: seems fixed now

hi llama,

We will have a look at it, We will get back to you after investigation

Regards,
-Chandra Mohan

I removed from the list the FP which have been fixed with virus database 1172 from my previous post. Two new FP have been introduced.

[tr]
[td]Malware name[/td]
[td]Filename[/td]
[td]Status(virustotal.com)[/td]
[/tr]
[tr]
[td]Heur.Packed.Unknown[/td]
[td]bass_ape.dll[/td]
[td]Scan results[/td]
[/tr]
[tr]
[td]Heur.Packed.Unknown[/td]
[td]bass_cda.dll[/td]
[td]Scan results[/td]
[/tr]

These two DLLs and the other files which haven’t been fixed yet are attached to this post as a zip archive.

[attachment deleted by admin]

Hi fOrTy_7,

Thanks for FP reporting
We will get back to you when it will be fixed.

Regards,
-Chandra Mohan

After database update to version 1174, only BASS DLLs have left. All other FP have been fixed. Thanks guys for your hard work. :-TU

CIS version: 3.9.95478.509
DB version: 1174

[tr]
[td]Malware name[/td]
[td]Filename[/td]
[td]Status(virustotal.com)[/td]
[/tr]
[tr]
[td]Heur.Packed.Unknown[/td]
[td]p.exe[/td]
[td]Scan results[/td]
[/tr]

[attachment deleted by admin]

HI
i use Miranda IM Client and my CIS (3.8.64263.468)
false scan alert by ‘Heur.Packed.Unknown’
but VT show 0\34 result. =
what does it mean ??
Thx…

Hi fOrTy_7,

The reported FP is under our consideration,
We will get back to you after investigation,
Thanks for reporting.

-Chandra Mohan

Hi vector.x86,

Please update your Product as well as database.
Check the detection and let us know.

The latest is as on May-20-2009
Product version : 3.9
Database version: 1176

Regards,
-Chandra Mohan

Hi llama,

Thanks for confirming.

Regards,
-Chandra Mohan

Hi fOrTy_7,

Thanks for confirming with DB 1174.
FP regarding BASS DLLs will be fixed in few updates.

Regards,
-Chandra Mohan

Hi fOrTy_7,

Mentioned FP is fixed DB 1177.
Please verify.

Regards,
-Chandra Mohan

Yes, p.exe FP has been fixed. Thanks.

Hi fOrTy_7,

Mentioned FP has been fixed in DB v1179
Please update your database and confirm.

Regards,
-Chandra Mohan

Yes, those have been fixed in DB 1179. Thank you.