ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
Heuristic.Trojan.SusPacket. TMS FOUND - False Positive?
fidel


Joined: 25 Jan 2010
Posts: 0
Reply with quote
Hi,

i do scan my WSUS-Box (Windows 2003 SBS) from time to time using ClamWin and realizing several (in my eyes) false positives.

Quote:

C:\WSUS\WsusContent\09\B3D0350CEF4D26F1B4B91CBC530EE5E83F211609.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\21\48DC1DB8ED61511E26127F1A3C85CCE637C92D21.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\29\F2BB7E7930F99A44FBA706E4B61254E162C5F529.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\2B\50CBE42219D6EA154B63429FF9E3F70028597F2B.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\3E\98DA0FA38299CBB991F41CCDC28D3C9E551AD03E.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\4A\75F1521962EE5B2AA732BAD74ACBBA577B62D14A.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\52\5A319F0B89E92D067898E19FEC2883A2F8B80752.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\5B\8FAECB92E7D083FF5C7AB42453A91559A524065B.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\61\33C97458662338E9B7C58EB2BF59269FF76B4361.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\65\B94113F61ACF2D00A8B6E19739E18858FDDC0165.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\6A\0AFBC6E0997236EF00CFDEDE5FFCBBAFD8BAD86A.cab: W32.Virut.Gen.D-163 FOUND
C:\WSUS\WsusContent\6E\4DD731657832205F83B29F8C32102824A56A456E.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\7A\ADC32AC3A9BB93A60520FE51477FCE5FF1565E7A.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\85\6C88D5DDBE155582D6A8151448149F43A913FF85.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\86\348F3DCFB27D15603269CC951D2B68D762461686.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\94\3C89F177C3FD83A9A452221661AE663510DC2D94.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\94\CBD74C97519F132AF0062576F244BB7C9892D094.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\A3\79E369A4B54D0EA70F15F180F122F777B95006A3.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\B9\7A857F4A099B4191C3615E1AC06B28D4BB06ADB9.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\C9\BCFBD6EE62D220E554AF7ACDDC0451DB6A14BFC9.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\D3\3DEBF3917CC79C04A5E542EB5EB1D293C99ED7D3.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\DC\ED5DF2D7145476A09339A3778B26F978B41AC2DC.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\F0\A77F6716E1888AE8CA8BFAF69654D553A0E1E9F0.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\F1\EAA5394E08AA4D61D7BCABFDD6CA2144CDAE19F1.exe: Heuristic.Trojan.SusPacked.TMS FOUND


I did check those files on another testbox using Avira without a single hit/alarm.
Using the VirusTotal Onlinecheck doesn’t work - as the files are all around 47MB in size - which causes the upload to fail.

Clamwin: 0.96.2.1 & latest Definitions.

Questions:
Is that a known false-positive?
How to make sure the files arent reported over and over again?


Best Regards
fidel
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
Heuristics are always subject to false positives, but they do catch a lot of viruses. The problem is that "evil" files can use the same tools/coding as the good files. The only way to cure a false positive is to visit the Clam AV submisstion page, starting at https://www.clamav.net/lang/en/sendvirus/ on the web. This is a welcome page. When you get to the actual submission page, upload the file to them, designate it as a false positive, and tell them the name of the falsely-detected virus in the comments section. Clam AV furnishes the scanning engine and signature database for ClamWin, and they will corrrect their signature within 2 or 3 days.

In the meantine, you can exclude the filename.extension (like that) in ClamWin's filters tab--on the left side of the page.

Regards,
View user's profileSend private message
fidel


Joined: 25 Jan 2010
Posts: 0
Reply with quote
Hi GuitarBob,

i am already in contact with the clam-devs - gonna add the results later to this post.
Thanks for your hints.


Best Regards
fidel
View user's profileSend private message
fidel


Joined: 25 Jan 2010
Posts: 0
Reply with quote
Nach Rücksprache mit einem Clam-Entwickler wurden die Signaturen angepasst bzgl einem Beispielfile angepasst. Nun scheint es einzig an der noch veralteten Clam-Engine im Falle ClamWin zu klemmen.

Quote:
Quote:
Das Problem liegt bei ClamWin, es wird eine veraltete Engine verwendet, mit unserer aktuellen Version wird die Datei nicht mehr gemeldet. Leider haben wir keinen Einfluss auf die Entwicklung von ClamWin und können in diesem Fall leider nicht weiterhelfen.



Gruß
fidel
View user's profileSend private message
clwin01


Joined: 18 Nov 2010
Posts: 0
Reply with quote
Hello,
with today clamwin updates, scan found a lot of file with message in thread title,
clamwin unloaded from memory all dll/programs with this (false positive) message and moved them to .quarantine.
It was a quite big disaster Evil or Very Mad

From now I'll set clamwin action to "Report Only"

bye
View user's profileSend private message
beeg_98


Joined: 18 Nov 2010
Posts: 0
Reply with quote
Code:
Clamuko: /home/bj/scripts/PsTools.zip: Heuristic.Trojan.SusPacked.TMS FOUND
Clamuko: /home/bj/.config/google-chrome/Default/Extensions/caehdcpeofiiigpdhbabniblemipncjj/1.6.3/plugins/npSwitchy.dll: Heuristic.Trojan.SusPacked.TMS FOUND


I don't believe either of these files are infected. The first: PsTools.zip I've had on my machine for a long time and downloaded from microsoft. The second is a google chrome add-in for switching proxies "Proxy Switchy!". I've scanned both of these files with Avira antivir, and they both return negative. It might be good to refine the definition that is catching these files a little more. Wink I understand that it is normal for Heuristics to have false positives, but it appears that one update caused this particular heuristic to have two false positives on my machine where it had none before. It seems I'm not the only one. clwin01 looks like he suffered more from this than I did.

Thanks.
View user's profileSend private message
cing


Joined: 18 Nov 2010
Posts: 0
Reply with quote
DISASTER like clwin01.

Advise setting to Report Only until it's fixed.

I had more than 40 files tagged as infected with Heuristic.Trojan.SusPacket. TMS FOUND all moved to quarantine. Clamwin flagged two of its own files - clamwin.exe and clamtray.exe - and moved them as well.

The virus scan report did not get written to file, so I have no way of knowing from where all of the files came. Probably will have to reinstall most of the affected programs.

Hard to believe a major problem like this got committed to the daily updates.
View user's profileSend private message
hubbabubba


Joined: 19 Aug 2010
Posts: 0
Location: Montreal, Quebec, Canada
Reply with quote
Hello!

Every morning, I upload Virus Database and do a Memory Scan. Today, I got Heuristic.Trojan.SusPacked.TMS FOUND dire messages all over the place. The program stopped after five files were identified in this manner. They were KERNEL32.DLL, GDI32.DLL, I81X329X.DLL, ADVAPI32.DLL, USER32.DLL. As you can see, all important files.

After rebooting, I went to https://virscan.org/ https://virscan.org/ and had them scan by the plethora of scanners on-line they have.

Not one suspicious file report on any of these five DLL!!! Normally, I expect at least one or two positives per files checked.

I did a scan of the entire SYSTEM folder and got the Heuristic.Trojan.SusPacked.TMS FOUND on 99% of the DLL.

Something goes very wrong...
View user's profileSend private message
brianecole


Joined: 18 Nov 2010
Posts: 0
Reply with quote
I concur with this. We scan our servers daily. Today Clam decided to quarantine THOUSANDS of files under c:\Windows that are part of the Windows Server 2008 R2 operating system this morning, so Windows no longer functions properly and we have to reinstall Windows on several servers. Not fun. It found so many false positives that it stopped quarantining them after about 3,000 files and simply reported the remainder. All of them with the same thing: Heuristic.Trojan.SusPacked.TMS.
View user's profileSend private message
Same here - Happens on Mac OS X v10.5.8
knockmonster


Joined: 18 Nov 2010
Posts: 0
Location: Minneapolis
Reply with quote
Eight of my Mac OS X machines found around 100 "viruses" this morning during the daily cron jobs. They were each quarantined. But these could not all possibly be Heuristic.Trojan.SusPacked.TMS. Many were found here:

/Library/Internet Plug-Ins/Silverlight.plugin/Contents/MacOS/

And here:

/System/Library/CoreServices/.diagnostics
/System/Library/Frameworks/Python.framework/Versions/

Then two odd files:

/System/Library/Java/Support/VisualVM.bundle/Contents/Home/platform11/lib/nbexec.dll
/System/Library/CoreServices/boot.efi

It's the same on all machines. I hope someone who develops these virus definitions reads this.

Matthew
View user's profileSend private message
jideel


Joined: 18 Nov 2010
Posts: 0
Reply with quote
Same here. Windows 2000, 2003, 2008, 2008 R2 servers, all affected.
Most files are reported as "Heuristic.Trojan.SusPacked.TMS", and it tries to unload all DLL from memory, including critical system/kernel ones, obviously crashing the system.
Crashed one of our server last night, but fortunately, as we don't use quarantine, a simple hardware reboot fixed the issue.
But we had to disable the antivirus on all of our servers to avoid such behavior !
Really annoying.
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
If you have reported a false positive to Clam, they will usually fix it within a couple of days. For a false positve that is not yet fixed, you can exclude the affected file from ClamWin scans via the Confiuration menu, Filters.

If you have more than one detection for the same virus, it is likely to be a false positive.

When using Report Only as the infected file option, you may also want to uncheck the General configuration option to Unload infected programs from memory.

Regards,
View user's profileSend private message
cing


Joined: 18 Nov 2010
Posts: 0
Reply with quote
Well, yes...but the large number and variety of false positives leads me to suspect an error in the virus definition that was just committed to the database. I've turned it off instead of spending time excluding core OS files.
View user's profileSend private message
False positives suddenly on November 18th
tony-jennings


Joined: 19 Nov 2010
Posts: 0
Location: Cambridge, England
Reply with quote
Of our 4 servers running clamav, the first one that scans for the day threw lots and lots of reports from files all over the server.
This included files of clamav itself as well as windows files.

This server is a 3 week old (Oct 26) install of windows server 2008 and clamav has been running since October 29th.
Everything has been quiet from this server until this evening - BANG! Sad

ALSO

If (as a test) I scan mysql-5.1.51-winx64.msi with clamav - it reports 'infected with Heuristic.Trojan.SusPacket. TMS FOUND'

However, if I run the file through the MD5 hash calculator, the checksum matches the published signature proving thhat it has not been
modified/infected.

Seems to me that this virus definition download is going to be causing a whole lot of grief!
Looks like the default clamav install is set to report only - phew!
View user's profileSend private message
alch
Site Admin

Joined: 27 Nov 2005
Posts: 0
Reply with quote
There was a bug in 0.96.2 release which is fixed in 0.96.4 released today. Please download and install the update:
https://sourceforge.net/projects/clamwin/files/clamwin/0.96.4/clamwin-0.96.4-setup-nodb.exe/download
View user's profileSend private message
Heuristic.Trojan.SusPacket. TMS FOUND - False Positive?
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 3  

  
  
 Reply to topic