Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

prebuild FindZombieHandles flagged as malicious by many virus scanners #14

Open
burkhardgerlach opened this issue Feb 27, 2024 · 2 comments

Comments

@burkhardgerlach
Copy link

Virustotal flags the prebuild FindZombieHandles.exe as potential malicous...29 scanners show a red flag...

@randomascii
Copy link
Owner

https://www.virustotal.com/gui/file/9065ebf849e9760d8431921c07e372a83850b0350de1545ae1fc82335e13ca9c

It's down to 9 scanners showing a red flag now, as far as I can tell. And, they are mostly calling it "Trojan.Generic" which is "A generic detection has identified a program or file with code or behavior similar to trojans" (https://www.f-secure.com/v-descs/trojan-java-generic.shtml). So, these companies have some heuristic and they have no accountability for false positives.

Sorry but I don't think I can do anything about this. I'm pretty sure it's not malicious, and absent some plausible analysis showing that it is malicious it's not worth my time to investigate. And I don't know what I could do anyway, given the lack of detail shared by these red flags.

@randomascii
Copy link
Owner

Also, feel free to examine the source and build it from source, although you probably won't get a matching binary because the CLR has moved on.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants