Author Topic: What Is HEUR.ADVML.B ?  (Read 14344 times)

sticky1202

  • Full Member
  • ***
  • Posts: 189
What Is HEUR.ADVML.B ?
« on: October 24, 2017, 01:23:42 pm »
A file named HEUR.ADVML.B lust got flagged by my anti-virus program. Does it have anything to do with FSDT, specifically the updater? Thanks!

Jim

virtuali

  • Administrator
  • Hero Member
  • *****
  • Posts: 50683
    • VIRTUALI Sagl
Re: What Is HEUR.ADVML.B ?
« Reply #1 on: October 24, 2017, 01:35:02 pm »
Does it have anything to do with FSDT, specifically the updater?

Of course it doesn't. It only indicates your antivirus is bugged. "HEUR" is not the name of a virus, it tells the antivirus is trying to detect "HEURistically" that a file MIGHT be dangerous, using its own (flawed) logic.

Here's a thread on Symantec forum, full of complaints that software proven to be legit has started to be detected by Norton as "HEUR.ADVML.B"

https://community.norton.com/en/forums/heuradvmlb-detected-false-positive-or-not

Heuristic is a very questionable technique that has been designed to detect dangerous file before it has proven to be dangerous. It's a way to advertise the antivirus being able to discover threats "before they are been discovered", with the only result that it will end up blocking most legit files. It's likely the "dangerous" behavior that triggered the flag is the very act of *downloading* something, which is obviously everything that an updater is supposed to do.

The usual suggestion that antivirus developers provide to legit software developers, is to digitally sign their executables, which we obviously do, but some antivirus are so bugged they don't seem to care...

I suggest to switch to a more reliable antivirus, one that doesn't make you lose your time chasing ghosts and blocking legit products to do their work.