[prev in list] [next in list] [prev in thread] [next in thread] 

List:       focus-virus
Subject:    RE: Pwsteal.trojan
From:       rsh () idirect ! com
Date:       2004-04-08 0:39:06
Message-ID: fh79701rrp8sg3c3oihejhq1di0bs0luv8 () 4ax ! com
[Download RAW message or body]

The question to ask is why the AV programs are detecting NON-Virus code
as a false-positive.

If every AV program detected it, that would suggest a problem with the
program, but if only some of these AV programs do, it suggests a problem
with their choice of signature for detecting the nefarious code they are
really after.

In other words, it is the AV product that has the problem, in my view,
and not the business management software you use.

FWIW

R S Heuman
Independent Consultant
Toronto, ON, Canada
------------------------------------
On Wed, 7 Apr 2004 14:12:29 -0500, you wrote:

>Interesting news. I just spoke with the vendor who supplies our business
>management software and the same file that was showing as "infected" is
>1 file of 7 that has recently been shown to cause false-positives in
>some antivirus software. They've provided a patch to our system that
>should mitigate this. This of course raises the question of why they're
>pushing updates to our servers that would cause the false positive, and
>why is their code being detected as a keylogger?


------------------------------------------------------------------------------
----------------------------------------------------------------------------


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic