And just today I heard someone praising nod32 for having such great heuristics that it often picks up even undiscovered new viruses... looks like sometimes it's a little over-eager![]()
lol, yea I realize it's open source, but which part of the rr.exe code would trigger this alert![]()
And just today I heard someone praising nod32 for having such great heuristics that it often picks up even undiscovered new viruses... looks like sometimes it's a little over-eager![]()
But don't take it from me! here's a quote from a real, live newbie:
eegeek.netOriginally Posted by Viscouse
AFAIK, all heuristic virus scanners give way too many false positives.
I turn heuristic scanning off for that reason, regardless of the anti-virus software.
Think about it..
The whole idea behind heuristic scanning is for the software to say "Hey! This file might be a virus!"
****... ANY file could be flagged as something virulent.
Actually, you are wrong, it will do that to anything it wants to. When it doesn't know what the exe belongs to, it will pop up a warning message.
The problem is the scanner can't figure it out what RR is, and most likely because it calls and interacts with the other programs on your computer, like Winamp and whatever, it THINKS it might be a virus, so it calls it one.
Michael
...I love the French language...especially to curse with...Nom de Dieu de putain de bordel de merde de saloperies de connards d'enculés de ta mère. You see, it's like wiping your *** with silk, I love it.
Either of those might trigger alerts:
-The number of (and which) windows API functions used in RR
-The on-the-fly compressor used to make the EXE smaller
IMHO, the best anti-virus you can use is yourself. The existing anti-virus applications are in many cases worse (in effect) than many existing viruses... in any case, if you toggle the auto-protect off and just scan suspicious files manually it should virtually have o adverse effect on the machine performance and use (except your waste of time). The best policy is, if you don't trust it, don't open it.. if you doubt the integrity of the RR.EXE file for instance, you can simply not use it OR get the sources and compile it yourself.. I have done research on bypassing this kind of heuristic flags and they're very easy to fool -- so I personally find it very useless.
Ride Runner RR's Myspace
"Being happy is not about having what you want, it's about wanting what you have."
"The best things in life are always free - but that doesn't mean money can't buy you good things."
Bookmarks