| View previous topic :: View next topic |
| Author |
Message |
NTHRIWZ
Joined: 21 Aug 2007 Posts: 7
|
Posted: Thu Jan 10, 2008 8:08 pm Post subject: Autoit.KV worm detected |
|
|
I just had AVG get hits on the Autoit.KV worm in a ZIP file that had 4 work-in-progress (as I was creating something) .EXEs created by AutoHotkey v 1.0.47.03 on 8-20-07. Strangely enough the ones I created 59 minutes later (that day) were not tagged as being infected.
I believe these are false-positive hits but you people are the AutoHotkey geniuses and I defer to you. _________________ This is all SO repetitive... |
|
| Back to top |
|
 |
neXt
Joined: 18 Mar 2007 Posts: 504
|
Posted: Thu Jan 10, 2008 8:13 pm Post subject: |
|
|
| search the forum it was discussed millions of times. |
|
| Back to top |
|
 |
NTHRIWZ
Joined: 21 Aug 2007 Posts: 7
|
Posted: Fri Jan 11, 2008 6:47 am Post subject: |
|
|
I searched before I asked and came up with 9 pages of hits that have nothing to do with the Autoit.KV worm I asked about.
Hopefully someone can direct me to something helpful. _________________ This is all SO repetitive... |
|
| Back to top |
|
 |
Guest
|
Posted: Fri Jan 11, 2008 7:19 am Post subject: |
|
|
| NTHRIWZ wrote: | | I searched before I asked... |
...yes, I agree, people on this forum shouldn't be so dismissive about virus reports...each one should be dealt with individually...remembering that AutoHotkey itself isn't the virus, but those .exe's you compiled could've visited an infected computer & actually got infected...if you have the source I would recommend re-compiling & storing the "virus infected (or false positive) copies in a separate directory...please read this thread for info on what I did with a False Positive...
...scan those .exe's at virusscan.jotti.org & report the results... |
|
| Back to top |
|
 |
neXt
Joined: 18 Mar 2007 Posts: 504
|
|
| Back to top |
|
 |
NTHRIWZ
Joined: 21 Aug 2007 Posts: 7
|
Posted: Sat Jan 12, 2008 2:58 am Post subject: |
|
|
Thanks for the links they were most helpful.
I ran the file (renamed to make it easy for the scanner) through Jotti's scanner and it got several hits. Amazingly these are .EXEs in a .ZIP that's never been off of this machine. Go figure...
Nevertheless here are the results per your request.
Scan taken on 12 Jan 2008 02:27:16 (GMT)
AntiVir
Found nothing
ArcaVir
Found Trojan.Downloader.Agent.Ejc
Avast
Found nothing
AVG Antivirus
Found Worm/Autoit.KV
BitDefender
Found nothing
ClamAV
Found nothing
CPsecure
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
F-Secure Anti-Virus
Found nothing
Fortinet
Found nothing
Ikarus
Found F9 test version, it works.exe - Signature 'Virus.Win32.AutoRun.wv, Ctrl keypress version - original.exe - Signature 'Virus.Win32.AutoRun.wv, Ctrl keypress version.exe - Signature 'Virus.Win32.AutoRun.wv, non-Ctrl keypress version.exe - Signature 'Virus.Win32.AutoRun.wv, non-Ctrl keypress version - blue & tan.exe - Signature 'Virus.Win32.AutoRun.wv, blue pyramid - blue pyramid.exe - Signature 'Virus.Win32.AutoRun.wv, non-Ctrl keypress version - red.exe - Signature 'Virus.Win32.AutoRun.wv, Ctrl keypress version - red.exe - Signature 'Virus.Win32.AutoRun.wv, Virus.Win32.AutoRun.wv
Kaspersky Anti-Virus
Found nothing
NOD32
Found nothing
Norman Virus Control
Found W32/AutoRun.AFH
Panda Antivirus
Found nothing
Rising Antivirus
Found Worm.Win32.Autorun.ity
Sophos Antivirus
Found nothing
VirusBuster
Found nothing
VBA32
Found nothing
_________________ This is all SO repetitive... |
|
| Back to top |
|
 |
badmojo
Joined: 11 Nov 2005 Posts: 202
|
Posted: Mon Jan 14, 2008 4:15 am Post subject: |
|
|
i have an alert too on AVG Free.. no doubt, it's a false positive but just posting here and going to notify the AVG people as well..
 |
|
| Back to top |
|
 |
vdongen
Joined: 08 May 2005 Posts: 41 Location: Jakarta, Indonesia
|
Posted: Mon Jan 14, 2008 2:01 pm Post subject: Same result from AVG |
|
|
I got the same message from AVG. how to solve the problem?
Bart |
|
| Back to top |
|
 |
Jamey (forgot password) Guest
|
Posted: Mon Jan 14, 2008 5:02 pm Post subject: solution? |
|
|
I got the exact same AVG virus warning as badmojo did:
AVG Free Edition Resident Shield
Threat Detected!
While opening file: D:\...\AnAutoHotKeyEXE.exe
Virus identified Worm/Autoit.LM
For the moment I seem to have side-stepped the problem. I uninstalled my AutoHotKey version 1.0.47.04, and I installed the new version, 1.0.47.05. I "re-compiled" the same AHK script (whose EXE had been giving the virus warning), and the new EXE no longer generated any complaints from AVG. It is possible that my computer has some virus infection on it, after all - so scanning time, I guess. I mean, I doubt (?) the newest version changes involved fixing a false-positive virus warning; and the same AHK EXE gave no AVG complaints for the last 6 months until today (and today, is after I had just re-installed and updated AVG Free with the latest released version). |
|
| Back to top |
|
 |
|