Kitz ADSL Broadband Information
adsl spacer  
Support this site
Home Broadband ISPs Tech Routers Wiki Forum
 
     
   Compare ISP   Rate your ISP
   Glossary   Glossary
 
Please login or register.

Login with username, password and session length
Advanced search  

News:

Author Topic: Bitdefender detects malware in dslstatssampling.exe  (Read 1957 times)

MikeZ

  • Member
  • **
  • Posts: 96
Bitdefender detects malware in dslstatssampling.exe
« on: August 30, 2015, 01:31:23 PM »

I'm sure it's a false positive - I uploaded it to virustotal and only 9 out of 56 scanners detected anything. It claims to detect Gen:Variant.Jaike.745.

Maybe something that dslstatssampling.exe does looks 'suspicious'.
Logged

roseway

  • Administrator
  • Senior Kitizen
  • *
  • Posts: 43608
  • Penguins CAN fly
    • DSLstats
Re: Bitdefender detects malware in dslstatssampling.exe
« Reply #1 on: August 30, 2015, 03:48:06 PM »

I'm fairly amazed, because dslstatssampling.exe doesn't do anything. It simply sits there for a maximum of 10 seconds while sampling proceeds. It acts as a marker which HG612_Modem_Stats can detect to avoid clashes between the two programs.

Presumably there's some sequence of bytes in the executable which corresponds with that particular item of malware.

At present it's a rather large executable to do so little, which is a consequence of the lazy way I wrote it. I'll have another look at it and slim it down, which hopefully will get rid of the false positive.
Logged
  Eric

lloyd

  • Reg Member
  • ***
  • Posts: 109
Re: Bitdefender detects malware in dslstatssampling.exe
« Reply #2 on: August 30, 2015, 04:25:44 PM »

The fact that it sits and does nothing is in itself suspicious. One trick the malware writers use is to do nothing, waiting for the Av scan to timeout looking for odd behaviour.
Logged

roseway

  • Administrator
  • Senior Kitizen
  • *
  • Posts: 43608
  • Penguins CAN fly
    • DSLstats
Re: Bitdefender detects malware in dslstatssampling.exe
« Reply #3 on: August 30, 2015, 06:38:02 PM »

I suppose I could make it do something innocuous. Better though, perhaps I can contact Bitdefender and persuade them that it's innocent.
Logged
  Eric

MikeZ

  • Member
  • **
  • Posts: 96
Re: Bitdefender detects malware in dslstatssampling.exe
« Reply #4 on: August 30, 2015, 06:59:50 PM »

I submitted it to them for checking as a false-positive.
Logged

roseway

  • Administrator
  • Senior Kitizen
  • *
  • Posts: 43608
  • Penguins CAN fly
    • DSLstats
Re: Bitdefender detects malware in dslstatssampling.exe
« Reply #5 on: August 30, 2015, 07:27:03 PM »

Thanks, I'll await the outcome. The source code is available if needed.
Logged
  Eric