blogstuff icon indicating copy to clipboard operation
blogstuff copied to clipboard

prebuild FindZombieHandles flagged as malicious by many virus scanners

Open burkhardgerlach opened this issue 1 year ago • 2 comments

Virustotal flags the prebuild FindZombieHandles.exe as potential malicous...29 scanners show a red flag...

burkhardgerlach avatar Feb 27 '24 08:02 burkhardgerlach

https://www.virustotal.com/gui/file/9065ebf849e9760d8431921c07e372a83850b0350de1545ae1fc82335e13ca9c

It's down to 9 scanners showing a red flag now, as far as I can tell. And, they are mostly calling it "Trojan.Generic" which is "A generic detection has identified a program or file with code or behavior similar to trojans" (https://www.f-secure.com/v-descs/trojan-java-generic.shtml). So, these companies have some heuristic and they have no accountability for false positives.

Sorry but I don't think I can do anything about this. I'm pretty sure it's not malicious, and absent some plausible analysis showing that it is malicious it's not worth my time to investigate. And I don't know what I could do anyway, given the lack of detail shared by these red flags.

randomascii avatar Feb 29 '24 04:02 randomascii

Also, feel free to examine the source and build it from source, although you probably won't get a matching binary because the CLR has moved on.

randomascii avatar Feb 29 '24 04:02 randomascii