View Full Version : TEMS detects Kaspersky 8 as a High Risk threat
RavenMacDaddy
05-17-2008, 04:27 PM
Running the scanner detected one of KIS8's files as being a very high risk threat currently running. See the screenshot for the details. ;)
EDIT: Overall it's being detected as just that through "ThreatExpert" too. Doesn't look good to me...
Sergei
05-20-2008, 06:07 AM
Thanks for pointing this out. TEMS has detected the same malware signatures that Kaspersky module uses to detect malware.
Think about it this way: TEMS is a drug-sniffing dog trained to alert in case of presence of illegal drugs. In this case, however, TEMS has drawn your attention to a crime lab of a different police department because it handles the samples of illegal drugs too.
We won't pull the malware signatures from TEMS to "fix" this detection, or otherwise it will stop detecting malware. Instead, we'll train it to distingush the legitimate modules of different AV products.
Meanwhile, please be aware that TEMS may trigger detection of the memory modules of other AV products that load malware signatures in memory and store them in unencrypted form.
RavenMacDaddy
05-20-2008, 05:15 PM
I see, thx for the info. and I'm looking forward to this getting fixed. ;)
ZeusVictim
05-20-2010, 07:40 PM
Meanwhile, please be aware that TEMS may trigger detection of the memory modules of other AV products that load malware signatures in memory and store them in unencrypted form.
I assume this is also what has been happening here in at least one case, when the windows defender and antivir guard processes were reported to contain heap pages with zeus/zbot signatures, I still wonder though why TEMS only reports those signatures specifically, instead of finding way more matches due to the size of antivirus signature db in both services ...
Is the zbot/zeus detection routine in any way significantly different from the other signatures? That would possibly explain those matches.
Powered by vBulletin™ Version 4.1.0 Copyright © 2012 vBulletin Solutions, Inc. All rights reserved.