 |
 | Heuristic.Trojan.SusPacket. TMS FOUND - False Positive? |  |
fidel
Joined: 25 Jan 2010 |
Posts: 0 |
|
|
 |
Posted: Mon Nov 15, 2010 9:13 am |
|
 |
 |
 |
 |
Hi,
i do scan my WSUS-Box (Windows 2003 SBS) from time to time using ClamWin and realizing several (in my eyes) false positives.
Quote: |
C:\WSUS\WsusContent\09\B3D0350CEF4D26F1B4B91CBC530EE5E83F211609.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\21\48DC1DB8ED61511E26127F1A3C85CCE637C92D21.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\29\F2BB7E7930F99A44FBA706E4B61254E162C5F529.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\2B\50CBE42219D6EA154B63429FF9E3F70028597F2B.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\3E\98DA0FA38299CBB991F41CCDC28D3C9E551AD03E.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\4A\75F1521962EE5B2AA732BAD74ACBBA577B62D14A.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\52\5A319F0B89E92D067898E19FEC2883A2F8B80752.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\5B\8FAECB92E7D083FF5C7AB42453A91559A524065B.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\61\33C97458662338E9B7C58EB2BF59269FF76B4361.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\65\B94113F61ACF2D00A8B6E19739E18858FDDC0165.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\6A\0AFBC6E0997236EF00CFDEDE5FFCBBAFD8BAD86A.cab: W32.Virut.Gen.D-163 FOUND
C:\WSUS\WsusContent\6E\4DD731657832205F83B29F8C32102824A56A456E.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\7A\ADC32AC3A9BB93A60520FE51477FCE5FF1565E7A.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\85\6C88D5DDBE155582D6A8151448149F43A913FF85.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\86\348F3DCFB27D15603269CC951D2B68D762461686.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\94\3C89F177C3FD83A9A452221661AE663510DC2D94.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\94\CBD74C97519F132AF0062576F244BB7C9892D094.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\A3\79E369A4B54D0EA70F15F180F122F777B95006A3.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\B9\7A857F4A099B4191C3615E1AC06B28D4BB06ADB9.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\C9\BCFBD6EE62D220E554AF7ACDDC0451DB6A14BFC9.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\D3\3DEBF3917CC79C04A5E542EB5EB1D293C99ED7D3.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\DC\ED5DF2D7145476A09339A3778B26F978B41AC2DC.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\F0\A77F6716E1888AE8CA8BFAF69654D553A0E1E9F0.exe: Heuristic.Trojan.SusPacked.TMS FOUND
C:\WSUS\WsusContent\F1\EAA5394E08AA4D61D7BCABFDD6CA2144CDAE19F1.exe: Heuristic.Trojan.SusPacked.TMS FOUND
|
I did check those files on another testbox using Avira without a single hit/alarm.
Using the VirusTotal Onlinecheck doesn’t work - as the files are all around 47MB in size - which causes the upload to fail.
Clamwin: 0.96.2.1 & latest Definitions.
Questions:
Is that a known false-positive?
How to make sure the files arent reported over and over again?
Best Regards
fidel
|
|
 |
 | |  |
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Mon Nov 15, 2010 1:56 pm |
|
 |
 |
 |
 |
Heuristics are always subject to false positives, but they do catch a lot of viruses. The problem is that "evil" files can use the same tools/coding as the good files. The only way to cure a false positive is to visit the Clam AV submisstion page, starting at https://www.clamav.net/lang/en/sendvirus/ on the web. This is a welcome page. When you get to the actual submission page, upload the file to them, designate it as a false positive, and tell them the name of the falsely-detected virus in the comments section. Clam AV furnishes the scanning engine and signature database for ClamWin, and they will corrrect their signature within 2 or 3 days.
In the meantine, you can exclude the filename.extension (like that) in ClamWin's filters tab--on the left side of the page.
Regards,
|
|
 |
 | |  |
fidel
Joined: 25 Jan 2010 |
Posts: 0 |
|
|
 |
Posted: Tue Nov 16, 2010 8:34 am |
|
 |
 |
 |
 |
Hi GuitarBob,
i am already in contact with the clam-devs - gonna add the results later to this post.
Thanks for your hints.
Best Regards
fidel
|
|
fidel
Joined: 25 Jan 2010 |
Posts: 0 |
|
|
 |
Posted: Thu Nov 18, 2010 2:09 pm |
|
 |
 |
 |
 |
Nach Rücksprache mit einem Clam-Entwickler wurden die Signaturen angepasst bzgl einem Beispielfile angepasst. Nun scheint es einzig an der noch veralteten Clam-Engine im Falle ClamWin zu klemmen.
Quote:
Quote: |
Das Problem liegt bei ClamWin, es wird eine veraltete Engine verwendet, mit unserer aktuellen Version wird die Datei nicht mehr gemeldet. Leider haben wir keinen Einfluss auf die Entwicklung von ClamWin und können in diesem Fall leider nicht weiterhelfen. |
Gruß
fidel
|
|
clwin01
Joined: 18 Nov 2010 |
Posts: 0 |
|
|
 |
Posted: Thu Nov 18, 2010 3:05 pm |
|
 |
 |
 |
 |
Hello,
with today clamwin updates, scan found a lot of file with message in thread title,
clamwin unloaded from memory all dll/programs with this (false positive) message and moved them to .quarantine.
It was a quite big disaster
From now I'll set clamwin action to "Report Only"
bye
|
|
 |
 | |  |
beeg_98
Joined: 18 Nov 2010 |
Posts: 0 |
|
|
 |
Posted: Thu Nov 18, 2010 5:21 pm |
|
 |
 |
 |
 |
Clamuko: /home/bj/scripts/PsTools.zip: Heuristic.Trojan.SusPacked.TMS FOUND
Clamuko: /home/bj/.config/google-chrome/Default/Extensions/caehdcpeofiiigpdhbabniblemipncjj/1.6.3/plugins/npSwitchy.dll: Heuristic.Trojan.SusPacked.TMS FOUND |
I don't believe either of these files are infected. The first: PsTools.zip I've had on my machine for a long time and downloaded from microsoft. The second is a google chrome add-in for switching proxies "Proxy Switchy!". I've scanned both of these files with Avira antivir, and they both return negative. It might be good to refine the definition that is catching these files a little more.  I understand that it is normal for Heuristics to have false positives, but it appears that one update caused this particular heuristic to have two false positives on my machine where it had none before. It seems I'm not the only one. clwin01 looks like he suffered more from this than I did.
Thanks.
|
|
 |
 | |  |
cing
Joined: 18 Nov 2010 |
Posts: 0 |
|
|
 |
Posted: Thu Nov 18, 2010 5:35 pm |
|
 |
 |
 |
 |
DISASTER like clwin01.
Advise setting to Report Only until it's fixed.
I had more than 40 files tagged as infected with Heuristic.Trojan.SusPacket. TMS FOUND all moved to quarantine. Clamwin flagged two of its own files - clamwin.exe and clamtray.exe - and moved them as well.
The virus scan report did not get written to file, so I have no way of knowing from where all of the files came. Probably will have to reinstall most of the affected programs.
Hard to believe a major problem like this got committed to the daily updates.
|
|
 |
 | |  |
hubbabubba
Joined: 19 Aug 2010 |
Posts: 0 |
Location: Montreal, Quebec, Canada |
|
 |
Posted: Thu Nov 18, 2010 5:36 pm |
|
 |
 |
 |
 |
Hello!
Every morning, I upload Virus Database and do a Memory Scan. Today, I got Heuristic.Trojan.SusPacked.TMS FOUND dire messages all over the place. The program stopped after five files were identified in this manner. They were KERNEL32.DLL, GDI32.DLL, I81X329X.DLL, ADVAPI32.DLL, USER32.DLL. As you can see, all important files.
After rebooting, I went to https://virscan.org/ https://virscan.org/ and had them scan by the plethora of scanners on-line they have.
Not one suspicious file report on any of these five DLL!!! Normally, I expect at least one or two positives per files checked.
I did a scan of the entire SYSTEM folder and got the Heuristic.Trojan.SusPacked.TMS FOUND on 99% of the DLL.
Something goes very wrong...
|
|
 |
 | |  |
brianecole
Joined: 18 Nov 2010 |
Posts: 0 |
|
|
 |
Posted: Thu Nov 18, 2010 7:22 pm |
|
 |
 |
 |
 |
I concur with this. We scan our servers daily. Today Clam decided to quarantine THOUSANDS of files under c:\Windows that are part of the Windows Server 2008 R2 operating system this morning, so Windows no longer functions properly and we have to reinstall Windows on several servers. Not fun. It found so many false positives that it stopped quarantining them after about 3,000 files and simply reported the remainder. All of them with the same thing: Heuristic.Trojan.SusPacked.TMS.
|
|
 | Same here - Happens on Mac OS X v10.5.8 |  |
knockmonster
Joined: 18 Nov 2010 |
Posts: 0 |
Location: Minneapolis |
|
 |
Posted: Thu Nov 18, 2010 8:37 pm |
|
 |
 |
 |
 |
Eight of my Mac OS X machines found around 100 "viruses" this morning during the daily cron jobs. They were each quarantined. But these could not all possibly be Heuristic.Trojan.SusPacked.TMS. Many were found here:
/Library/Internet Plug-Ins/Silverlight.plugin/Contents/MacOS/
And here:
/System/Library/CoreServices/.diagnostics
/System/Library/Frameworks/Python.framework/Versions/
Then two odd files:
/System/Library/Java/Support/VisualVM.bundle/Contents/Home/platform11/lib/nbexec.dll
/System/Library/CoreServices/boot.efi
It's the same on all machines. I hope someone who develops these virus definitions reads this.
Matthew
|
|
 |
 | |  |
jideel
Joined: 18 Nov 2010 |
Posts: 0 |
|
|
 |
Posted: Thu Nov 18, 2010 9:19 pm |
|
 |
 |
 |
 |
Same here. Windows 2000, 2003, 2008, 2008 R2 servers, all affected.
Most files are reported as "Heuristic.Trojan.SusPacked.TMS", and it tries to unload all DLL from memory, including critical system/kernel ones, obviously crashing the system.
Crashed one of our server last night, but fortunately, as we don't use quarantine, a simple hardware reboot fixed the issue.
But we had to disable the antivirus on all of our servers to avoid such behavior !
Really annoying.
|
|
 |
 | |  |
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Thu Nov 18, 2010 11:38 pm |
|
 |
 |
 |
 |
If you have reported a false positive to Clam, they will usually fix it within a couple of days. For a false positve that is not yet fixed, you can exclude the affected file from ClamWin scans via the Confiuration menu, Filters.
If you have more than one detection for the same virus, it is likely to be a false positive.
When using Report Only as the infected file option, you may also want to uncheck the General configuration option to Unload infected programs from memory.
Regards,
|
|
cing
Joined: 18 Nov 2010 |
Posts: 0 |
|
|
 |
Posted: Thu Nov 18, 2010 11:53 pm |
|
 |
 |
 |
 |
Well, yes...but the large number and variety of false positives leads me to suspect an error in the virus definition that was just committed to the database. I've turned it off instead of spending time excluding core OS files.
|
|
 | False positives suddenly on November 18th |  |
tony-jennings
Joined: 19 Nov 2010 |
Posts: 0 |
Location: Cambridge, England |
|
 |
Posted: Fri Nov 19, 2010 1:08 am |
|
 |
 |
 |
 |
Of our 4 servers running clamav, the first one that scans for the day threw lots and lots of reports from files all over the server.
This included files of clamav itself as well as windows files.
This server is a 3 week old (Oct 26) install of windows server 2008 and clamav has been running since October 29th.
Everything has been quiet from this server until this evening - BANG!
ALSO
If (as a test) I scan mysql-5.1.51-winx64.msi with clamav - it reports 'infected with Heuristic.Trojan.SusPacket. TMS FOUND'
However, if I run the file through the MD5 hash calculator, the checksum matches the published signature proving thhat it has not been
modified/infected.
Seems to me that this virus definition download is going to be causing a whole lot of grief!
Looks like the default clamav install is set to report only - phew!
|
|
 |
 | |  |
alch
Site Admin
Joined: 27 Nov 2005 |
Posts: 0 |
|
|
 |
Posted: Fri Nov 19, 2010 1:12 am |
|
 |
 |
 |
 |
There was a bug in 0.96.2 release which is fixed in 0.96.4 released today. Please download and install the update:
https://sourceforge.net/projects/clamwin/files/clamwin/0.96.4/clamwin-0.96.4-setup-nodb.exe/download
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 3
|
|
|
Powered by phpBB © phpBB Group
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.
|  |