AutoHotkey Community

It is currently May 26th, 2012, 12:01 am

All times are UTC [ DST ]




Post new topic This topic is locked, you cannot edit posts or make further replies.  [ 29 posts ]  Go to page Previous  1, 2
Author Message
 Post subject:
PostPosted: January 17th, 2008, 7:10 am 
Offline

Joined: October 17th, 2006, 4:15 pm
Posts: 7501
Location: Australia
Code:
MsgBox
I just tried compiling this with a v1.0.47.04 AutoHotkeySC.bin.
AVG: Threat Detected! wrote:
While opening file: Z:\MsgBox.exe
Virus identified Worm/Autoit.LM
Ahk2Exe Error wrote:
Error: Unable to create the compiled archive.
I had to use 7-zip to extract the bin file from the installer, since I didn't have the old zip version.

Scripts compiled with v1.0.45.04 are not detected as viruses, at least for me. I guess only v1.0.47.04 matched the virus signature. Perhaps someone wrote a virus with this version of AutoHotkey and it was reported to AVG.

I'm curious about why "Autoit" is in the name, given that I used the same version of Ahk2Exe and different versions of AutoHotkeySC.bin...

I've sent a sample (MsgBox.exe) to AVG.


Edit: btw, the description for Ask for Help is
Quote:
Ask questions and (hopefully) get answers.
NOT
Quote:
Ask for help with scripting
That aside, anti-virus false positives prevent users from running the scripts. It is a problem that needs a solution, and it relates directly to AutoHotkey. I strongly suggest that this thread belongs in Ask for Help.

[Mod edit: yes I think so too; I guess another moderator thought there was a conflict of interests earlier on in this discussion]


Report this post
Top
 Profile  
Reply with quote  
 Post subject:
PostPosted: January 17th, 2008, 1:14 pm 
Offline

Joined: October 17th, 2006, 4:15 pm
Posts: 7501
Location: Australia
AVG Technical Support wrote:
Dear Sir/Madam,

Thank you for your email.

We have analyzed the file you have sent to us and it is false
detection. This issue will be fixed in next update as soon as
possible.

Please accept our apologize for any inconvenience this may cause to
you.

If there are any other suspicious files, please feel free to contact
us again.

Thank you for your cooperation.


Report this post
Top
 Profile  
Reply with quote  
 Post subject:
PostPosted: January 17th, 2008, 6:17 pm 
Offline

Joined: May 24th, 2007, 3:45 am
Posts: 1121
Ah, good that this is (hopefully) taken care of.


Report this post
Top
 Profile  
Reply with quote  
 Post subject: AVG
PostPosted: February 12th, 2008, 10:19 am 
Offline

Joined: January 18th, 2006, 12:37 am
Posts: 290
For anyone having this problem again, I was able to use my compiled code when I rolled back to 1.0.47.3. (I don't have 1.0.47.4 but that might work too.)

_________________
My AutoHotkey Program for Warcraft III:
Warkeys
http://warkeys.sourceforge.net/

Remap your hotkeys
Healthbars always on
Remap inventory


Report this post
Top
 Profile  
Reply with quote  
 Post subject:
PostPosted: February 24th, 2008, 3:42 pm 
Just did a scan with http://virusscan.jotti.org/ and got 2 hits

Scan taken on 24 Feb 2008 14:21:50 (GMT)
A-Squared
Found nothing
AntiVir
Found nothing
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found nothing
CPsecure
Found Troj.Spy.W32.Agent.bdw
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
F-Secure Anti-Virus
Found nothing
Fortinet
Found nothing
Ikarus
Found nothing
Kaspersky Anti-Virus
Found nothing
NOD32
Found nothing
Norman Virus Control
Found nothing
Panda Antivirus
Found nothing
Rising Antivirus
Found nothing
Sophos Antivirus
Found nothing
VirusBuster
Found nothing
VBA32
Found Trojan-Spy.Win32.Agent.bbg

So there still some out that causing this issue


Report this post
Top
  
Reply with quote  
 Post subject:
PostPosted: March 7th, 2008, 10:48 am 
Still got Hits with

eSafe 7.0.15.0 2008.03.06 suspicious Trojan/Worm
Ikarus T3.1.1.20 2008.03.07 Trojan-Spy.Win32.Agent.bbg
Panda 9.0.0.4 2008.03.06 Suspicious file

CPsecure Troj.Spy.W32.Agent.bdw (this one from jotti)

weird:
NOD32v2 2928 2008.03.06 archive damaged

using 1.0.47.05


Now I'm using 1.0.46.17 again, no false positives so far. I habe no choice than to avoid those alerts.


Report this post
Top
  
Reply with quote  
 Post subject:
PostPosted: March 7th, 2008, 2:44 pm 
Offline

Joined: February 18th, 2008, 8:26 pm
Posts: 442
The best course of action is to use and distribute text scripts instead of compiled ones. AutoHotkey.exe is the only required dependency.


Report this post
Top
 Profile  
Reply with quote  
 Post subject: Autoit.ABB in AVG
PostPosted: April 3rd, 2008, 9:00 pm 
So they updated AVG and now it detects the Worm\Autoit.ABB in warkeys. I emailed AVG with no response yet. Any Idea as to why this is happening ? I cant set my keys currently because AVG will not let me access the file.


Report this post
Top
  
Reply with quote  
 Post subject:
PostPosted: April 13th, 2008, 3:58 am 
Ya I'm having the same trouble as "CuriousGuest"

I just updated to the newest version of both warkeys and avg and I get Threat Detected! Warkeys.exe ... virus identified Worm / Autoit.ABB


Report this post
Top
  
Reply with quote  
 Post subject:
PostPosted: April 13th, 2008, 4:01 am 
Offline

Joined: June 26th, 2006, 6:14 pm
Posts: 1379
Location: USA
I looked for the post by "CuriousGuest" and could not locate it.

_________________
Image
ʞɔпɟ əɥʇ ʇɐɥʍ


Report this post
Top
 Profile  
Reply with quote  
 Post subject:
PostPosted: April 13th, 2008, 11:10 pm 
sorry i meant "CuriousUser" ... the post directly above mine


Report this post
Top
  
Reply with quote  
 Post subject:
PostPosted: August 17th, 2008, 3:53 pm 
For my was on a corporate network, and it's not detected as a virus but detected as a possible threat, script creating copiled exe, basic virus behavior. I have the rules and keys that needs to be created for Symantec Corporate, if any body is interested.


Report this post
Top
  
Reply with quote  
PostPosted: April 29th, 2009, 1:45 am 
FYI - Three years later, April 2009, I get the same error using Synantec. I'm guessing that it's caused by the fact that ahk captures keystrokes.

All of my executables are listed as Trojans.


Report this post
Top
  
Reply with quote  
PostPosted: September 14th, 2009, 2:34 pm 
den wrote:
FYI - Three years later, April 2009, I get the same error using Synantec. I'm guessing that it's caused by the fact that ahk captures keystrokes.

All of my executables are listed as Trojans.

OFFTOPIC: Then they are viruses *aaah!!!* :lol:
ONTOPIC:
Antivirus Version Last Update Result
eSafe 7.0.17.0 2009.09.14 Suspicious File

The rest all said nothing.
P.S. Converted by SciTE4AutoHotkey


Report this post
Top
  
Reply with quote  
Display posts from previous:  Sort by  
Post new topic This topic is locked, you cannot edit posts or make further replies.  [ 29 posts ]  Go to page Previous  1, 2

All times are UTC [ DST ]


Who is online

Users browsing this forum: dra, Google Feedfetcher, LazyMan, Leef_me, tank, Tegno, Yahoo [Bot] and 15 guests


You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Powered by phpBB® Forum Software © phpBB Group