topbanner_forum
  *

avatar image

Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
  • Friday April 19, 2024, 2:28 am
  • Proudly celebrating 15+ years online.
  • Donate now to become a lifetime supporting member of the site and get a non-expiring license key for all of our programs.
  • donate

Author Topic: Backdoor Malware  (Read 4522 times)

beethoven

  • Supporting Member
  • Joined in 2006
  • **
  • Posts: 46
    • View Profile
    • Donate to Member
Backdoor Malware
« on: November 15, 2008, 07:07 PM »
I have been using Find and Run for a few years now and think it's a great program. I am not updating each time an update comes out, my experience is sometimes when things work for you, don't mess with them.
Still, I do come back regularly to see if I am missing something and eventually will look for the upgrade.

Just wondering why the current version shows us with some alerts on Jotti or Virustotal: Backdoor.XiaoBird.42 (paranoid heuristics) (probable variant) - I assume this is a FP but is this something that could be cleared up with VBA?

mouser

  • First Author
  • Administrator
  • Joined in 2005
  • *****
  • Posts: 40,900
    • View Profile
    • Mouser's Software Zone on DonationCoder.com
    • Read more about this member.
    • Donate to Member
Re: Backdoor Malware
« Reply #1 on: November 15, 2008, 07:21 PM »
paranoid heuristics
thats a very good indicator that this is a false positive alarm -- i find those "advanced" heuristics to be totally worthless and harmful.

f0dder

  • Charter Honorary Member
  • Joined in 2005
  • ***
  • Posts: 9,153
  • [Well, THAT escalated quickly!]
    • View Profile
    • f0dder's place
    • Read more about this member.
    • Donate to Member
Re: Backdoor Malware
« Reply #2 on: November 15, 2008, 10:40 PM »
Unfortunately, reliable virus detection is a very hard game. You want to be able to find the really nasty malware (which can be pretty darn tricky at hiding itself), but you also want to avoid false positives. False positives (like FARR being marked as "a virus") are bad - and it happens even with "Non-niche" software; lately, AVG flagged a critical windows component as a virus. If it can happen to something as high-volume as that, it can certainly happen to DonationCoder software as well >_<
- carpe noctem