I've had a few CA-Vet alerts for Win32/Puloagem.B recently, with pretty sparse information on what Puloagem actually is. If you're being plagued with this, then it's worth knowing that this is basically just a variant of Zlob and it's a variety of fake anti-virus software. In our case, the executable was named winrar.exe.
VirusTotal has a good list of aliases, so if you're struggling with it then you can use some of the other names as references.
Showing posts with label Vet. Show all posts
Showing posts with label Vet. Show all posts
Tuesday, 14 October 2008
Monday, 31 December 2007
Js/snz.a - likely false positive in eTrust / Vet Anti-Virus
It appears that CA's eTrust Anti-Virus product (also known as Vet Anti-Virus, often bundled with other security applications such as ZoneAlarm) is coming up with a false positive for js/snz.a for several complex javascript applications.
As far as I can tell, the javascript uses complex encoding but is not malware. These javascript elements are widely used on the web. As far as I can tell, they are not harmful in any way and this is a mis-identification by eTrust / Vet.
The signature that has the problem is 31.3.5417 dated 31/12/07
Some of the Javascript files that seem to trigger an alert are named:
If you're running Internet Explorer, then you may see an alert for an individual .js file as above, in a Mozilla-based browser (such as Seamonkey or Firefox) you may get a virus alert for a file named something similar to C:\Documents and Settings\USERNAME\Application Data\Mozilla\Profiles\Default\xxxxxxxx.SLT\CACHE\xxxxxxxxxxx
Usually, these false positives are fixed by CA pretty quickly. For most people this should just be a temporary nuisance that will be fixed with the latest virus update.
You can submit suspect files to CA here for analysis, that may well help them to fix the problem.
Follow up: this problem has now been fixed. It turns out that the javascript had been compressed using this packer tool which itself is harmless, but it does appear that the packer has been used for malicious javascript applications in the past as well as legitimate ones. Perhaps the lesson is.. don't pack or obfuscate your javascript!
As far as I can tell, the javascript uses complex encoding but is not malware. These javascript elements are widely used on the web. As far as I can tell, they are not harmful in any way and this is a mis-identification by eTrust / Vet.
The signature that has the problem is 31.3.5417 dated 31/12/07
Some of the Javascript files that seem to trigger an alert are named:
- jquery.js
- mootools.js
- ifx.js
- show_ads.js
- relevancead.js
- submodal.js
- iutil.js
- ifxslide.js
If you're running Internet Explorer, then you may see an alert for an individual .js file as above, in a Mozilla-based browser (such as Seamonkey or Firefox) you may get a virus alert for a file named something similar to C:\Documents and Settings\USERNAME\Application Data\Mozilla\Profiles\Default\xxxxxxxx.SLT\CACHE\xxxxxxxxxxx
Usually, these false positives are fixed by CA pretty quickly. For most people this should just be a temporary nuisance that will be fixed with the latest virus update.
You can submit suspect files to CA here for analysis, that may well help them to fix the problem.
Follow up: this problem has now been fixed. It turns out that the javascript had been compressed using this packer tool which itself is harmless, but it does appear that the packer has been used for malicious javascript applications in the past as well as legitimate ones. Perhaps the lesson is.. don't pack or obfuscate your javascript!
Labels:
eTrust,
False Positive,
Vet,
Viruses
Subscribe to:
Posts (Atom)