AutoHotkey Community

It is currently May 27th, 2012, 7:52 am

All times are UTC [ DST ]




Post new topic Reply to topic  [ 8 posts ] 
Author Message
PostPosted: November 27th, 2006, 11:42 pm 
Offline

Joined: October 10th, 2005, 10:44 am
Posts: 299
Location: Germany
Hey guys,

While I'm aware that some virus scanners see AHK as malware (due to possible keylogging IIRC), I was pretty shocked when Avira AntiVir just flagged AHK as a virus:

The whole thing started with AnitVir alerting me that my mIRC.exe was a trojan horse called TR/Dldr.Stration.I.
Quite worried (I've been using that very file for ages!), I ran a full system scan, which brought up AutoHotkey104414.zip, AU3_Spy.exe and AutoScriptWriter.exe as being (infected with?) the same virus or trojan horse.
And just now, PSPad's Notepad.exe was flagged with the same malware.

If it were only for AHK, I'd say AntiVir is a little too sensitive, but this mIRC thing worries me - that can't be a coincidence, can it?
A Google search didn't bring up any results on TR/Dldr.Stration.I, so I'm pretty much lost right now...

Any help would be appreciated!


Report this post
Top
 Profile  
Reply with quote  
 Post subject:
PostPosted: November 28th, 2006, 12:31 am 
Offline

Joined: April 26th, 2006, 4:10 am
Posts: 657
Location: New Mexico, USA
It is possible, but highly unlikely, that the files may have been hacked. Agian, this seems to not be the case. I would have to say that the detection of those files is a False positive. Maybe chris, or someone else who has access, can manual check the files, but I still think it has to be a false positive. If you could, you should email AnitVir support asking for exact information about the trojan, and ask if it is likely to be a false positive detection on those files.


Report this post
Top
 Profile  
Reply with quote  
 Post subject:
PostPosted: November 28th, 2006, 1:47 pm 
Offline

Joined: December 27th, 2005, 1:46 pm
Posts: 6837
Location: France (near Paris)
Funny, I just had the same alert from my Avira AntiVir PersonalEdition Classic... I had the idea to search for "virus" on the forum before alerting everybody... So here I am! We must have got the same update. :evil:

To be sure, I used BitDefender Online Scanner (need IE) and it reported no virus... So that's probably a false alert. I know that UPX compressed exes are sometime reported as virus, that's probably the common link between your various programs.

I am also trying Kaspersky Lab Online Scanner to be sure, but it choked on au3_spy.exe... I am re-trying. [UPDATE] OK, it was stuck because Avira blocked access to it, waiting I tell it to ignore it... This anti-virus is becoming a major annoyance, as it ask me regularly what to do with these files... I hope they will issue a new update.

Note 1: I first tried Secuser's online anti-virus, but unlike BitDefender's it cannot go beyond XP SP2's protection on running ActiveX, so I couldn't run it.

Note 2: I give French links, that's what I got, try these where I replaced the .fr with .com, perhaps it will work for you:
BitDefender Online Scanner
Kaspersky Lab Online Scanner

_________________
Image vPhiLho := RegExReplace("Philippe Lhoste", "^(\w{3})\w*\s+\b(\w{3})\w*$", "$1$2")


Last edited by PhiLho on November 28th, 2006, 4:00 pm, edited 2 times in total.

Report this post
Top
 Profile  
Reply with quote  
 Post subject:
PostPosted: November 28th, 2006, 2:17 pm 
Hmm, I updated the definitions, and scanned the AutoHotkey folder with Avira AntiVir PE: Nothing found 8)


Report this post
Top
  
Reply with quote  
 Post subject: Me too
PostPosted: November 28th, 2006, 9:51 pm 
Hi there,

I also get the "virus found" message:

The files
AU3_Spy.exe and AutoScriptWriter.exe
are infected with the trojan horse "TR/Dldr.Stration.I".
I Think, that's a false alarm, but does anybody ahs some more infos about his?

Daniel


Report this post
Top
  
Reply with quote  
 Post subject: false positive?
PostPosted: November 29th, 2006, 1:38 pm 
Same here. AU3_Spy.exe AutoScriptWriter.exe and A0066881.exe (whatever this file might be) ... have them in quarantine right now. Can anybody confirm that these are false positives so that I can move the files back in place?

Thanks in advance!


Report this post
Top
  
Reply with quote  
 Post subject:
PostPosted: November 29th, 2006, 1:45 pm 
Avira support forum


Report this post
Top
  
Reply with quote  
 Post subject:
PostPosted: November 30th, 2006, 9:05 am 
Offline

Joined: October 10th, 2005, 10:44 am
Posts: 299
Location: Germany
Thanks for the responses, guys.
I've also filed a report to Avira - haven't heard back from them yet, but it looks like they're aware of the issue.

*phew* When mIRC was showing up as infected, I really thought I'd caught a virus there - glad that's not the case.


Report this post
Top
 Profile  
Reply with quote  
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 8 posts ] 

All times are UTC [ DST ]


Who is online

Users browsing this forum: bobbysoon, HotkeyStick, just me and 68 guests


You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Powered by phpBB® Forum Software © phpBB Group