Grendel, anti-virus vendors do not intentionally add false positives or blacklists. What usually happens is, a user or an administrator may discover that their system has been compromised and will submit the "root kit" related files. (Using the reporting tool included with their anti-virus software, etc.) Eventually, the anti-virus vendor will include signatures for those applications; not all vendors spend a great amount of time determining whether those applications are legitimate or actually âroot kitâ files.
|