New tool, Jotti says: 3 scanners found malware menu

User Tag List

Results 1 to 5 of 5
  1. #1
    radarlove's Avatar Contributor
    Reputation
    158
    Join Date
    Jun 2012
    Posts
    205
    Thanks G/R
    2/11
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    New tool, Jotti says: 3 scanners found malware

    Hi,

    I’m currently working on a new third party tool, and am almost ready to publish it.
    I ran it through Jotti’s Malware scan (Jotti's malware scan) and got three warnings:
    - Dr.Web says: BackDoor.Siggen.32606
    - Ikarus says: Trojan-Downloader.Win32.Delf
    - Panda says: Generic

    The rest of the virusscanners (like: avast, antivir, f-secure, kasperski, trendmicro, etc) says there is no malware detected.

    The programme I created is a pretty straight forward HTTP server that retrieves chat messages from WoW and presents it through a webpage.
    I didn’t put any malware in the executable, but why do these three virusscanners say there are Trojan inside?

    Thx for replies,
    RL
    Last edited by radarlove; 07-29-2013 at 05:31 AM.

    New tool, Jotti says: 3 scanners found malware
  2. #2
    zaeBOOST's Avatar Contributor MASTER BOOSTER CoreCoins Purchaser
    Reputation
    156
    Join Date
    Feb 2013
    Posts
    205
    Thanks G/R
    3/1
    Trade Feedback
    28 (96%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    "Ikarus says: Trojan-Downloader.Win32.Delf"
    "Panda says: Generic"

    Because of the "connect to the HTTP server and retrieve files" behavior.

    What are you coding in?

  3. #3
    Eryx's Avatar Former Staff ✲ B26354 ✲ CoreCoins Purchaser Authenticator enabled
    Reputation
    894
    Join Date
    Jul 2011
    Posts
    3,815
    Thanks G/R
    574/277
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Anti malware/spypware/virus software uses code recognition to identify threats, and some times similar code can be found in "legit" software and then the security software can believe it is a threat even if it isn't.

    If it is a tool that reads memory/reading and interacting with other processes and uses low level code to do so, I guess its your "Jotti" that is a bit paranoid.

  4. #4
    radarlove's Avatar Contributor
    Reputation
    158
    Join Date
    Jun 2012
    Posts
    205
    Thanks G/R
    2/11
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by Kurnik View Post
    "Ikarus says: Trojan-Downloader.Win32.Delf"
    "Panda says: Generic"

    Because of the "connect to the HTTP server and retrieve files" behavior.

    What are you coding in?
    Coding in oldskool Delphi/Pascal
    I just looked into a few other published tools and I noticed there's also red flags in those virusscans. Guess some scanners are just freaking paranoid...

    Im also making another tool, tcp client/server which makes it possible to char over the internet... Probably also will get a lot of warnings..
    Last edited by radarlove; 07-29-2013 at 05:35 AM.

  5. #5
    Nikentic's Avatar Elite User
    Reputation
    453
    Join Date
    Oct 2007
    Posts
    1,556
    Thanks G/R
    10/4
    Trade Feedback
    6 (100%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Delphi actually gives a lot of "false positives", just by having code that handles HTTP. Been experiencing it a few times, don't remember what to do about it though.

Similar Threads

  1. New Tool for wow.
    By Sub-Zero5 in forum WoW EMU Programs
    Replies: 6
    Last Post: 01-11-2009, 09:58 AM
  2. Account Dictionizer (A new tool for account scammers)
    By Apoc in forum World of Warcraft Bots and Programs
    Replies: 65
    Last Post: 10-05-2008, 10:38 AM
  3. A New Tool For WOW
    By biglew2k99 in forum WoW EMU Programs
    Replies: 5
    Last Post: 02-29-2008, 05:50 AM
  4. New Registrant just saying hello!
    By Xavamoo in forum Community Chat
    Replies: 1
    Last Post: 01-08-2008, 10:01 PM
  5. New Here and Saying Thanks
    By The-Dark-Sahdow in forum Community Chat
    Replies: 3
    Last Post: 11-02-2007, 07:24 PM
All times are GMT -5. The time now is 12:03 PM. Powered by vBulletin® Version 4.2.3
Copyright © 2024 vBulletin Solutions, Inc. All rights reserved. User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
Digital Point modules: Sphinx-based search