Feeds

Reg reader trapped in McAfee Catch 22

Nimda spawns heuristic headache

  • alert
  • submit to reddit

Providing a secure and efficient Helpdesk

A Register reader ran into a Catch 22 situation when he tried to inform McAfee that its antivirus software was generating false warnings about the Nimda worm.

Alarm bells triggered when Russell Elliott tried to browse www.kingcomp.net, when McAfee's antivirus tools warned him that the site was infected with Nimda.

Kingcomp was able to tell him the site had been cleaned up but its "page not available" (404.html) file still had a reference to a text string used by the Nimda. This was still there even though the payload had been wiped off its servers.

Russell tried to advise McAfee it was catching some systems that had been actually been cleaned and wanted to quiz it on its technology.

But since his email contained the text string used to launch Nimda "window.open <"readme.eml", null" (we've changed ( to < in order to avoid getting caught ourselves), his email was quarantined and deleted.

Subsequent correspondence with support staff prompted requests from them to explain what operating system and version of VirusScan he was using, rather missing the point.

You can debate whether automatic detection (heuristics) in virus scanners does more good than harm, and we're inclined to argue that the occasional false alarm is a price worth paying. Being wrongly told a site is infected with Nimda is annoying but how does that inconvenience compare with having a virus slip through your protection(something heuristics is designed to prevent)?

That said, Russell has a reasonable question when he asks McAfee: "wouldn't it be better to define your virus definitions around the PAYLOAD (which is binary and more difficult to modify), instead of the launch mechanism." ®

Related stories

Norton AV update rings false alarm bells
MSN.co.uk virus alert is false alarm
Sophos rebuffs virus-spreading charge
Firms hit in Nimda mutant outbreak
Nimda worm tails off
Teenage Mutant Nimda email rides the Code Red worm>

New hybrid storage solutions

More from The Register

next story
Google recommends pronounceable passwords
Super Chrome goes into battle with Mr Mxyzptlk
Infosec geniuses hack a Canon PRINTER and install DOOM
Internet of Stuff securo-cockups strike yet again
Reddit wipes clean leaked celeb nudie pics, tells users to zip it
Now we've had all THAT TRAFFIC, we 'deplore' this theft
Apple Pay is a tidy payday for Apple with 0.15% cut, sources say
Cupertino slurps 15 cents from every $100 purchase
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
TorrentLocker unpicked: Crypto coding shocker defeats extortionists
Lousy XOR opens door into which victims can shove a foot
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
Top 5 reasons to deploy VMware with Tegile
Data demand and the rise of virtualization is challenging IT teams to deliver storage performance, scalability and capacity that can keep up, while maximizing efficiency.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.