Detox is absolutely right about the capabilities of heuristics. They are not as effective as advertised and can lead to many more false detections that actual detections. They often lead to a waste of system resources.

They only attempt to identify activity that seems suspicious, however what is suspicious? Who defines it and what standard functions could make an api call of an alteration that fits the mold.

I say turn the baby of and harden the box....