AutoHotkey Homepage AutoHotkey Community
Let's help each other out
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

Compiled AutoHotkey scripts detected as virus by AVG
Goto page Previous  1, 2
 
Post new topic   Reply to topic    AutoHotkey Community Forum Index -> Ask for Help
View previous topic :: View next topic  
Author Message
Lexikos



Joined: 17 Oct 2006
Posts: 2739
Location: Australia, Qld

PostPosted: Thu Jan 17, 2008 6:10 am    Post subject: Reply with quote

Code:
MsgBox
I just tried compiling this with a v1.0.47.04 AutoHotkeySC.bin.
AVG: Threat Detected! wrote:
While opening file: Z:\MsgBox.exe
Virus identified Worm/Autoit.LM
Ahk2Exe Error wrote:
Error: Unable to create the compiled archive.
I had to use 7-zip to extract the bin file from the installer, since I didn't have the old zip version.

Scripts compiled with v1.0.45.04 are not detected as viruses, at least for me. I guess only v1.0.47.04 matched the virus signature. Perhaps someone wrote a virus with this version of AutoHotkey and it was reported to AVG.

I'm curious about why "Autoit" is in the name, given that I used the same version of Ahk2Exe and different versions of AutoHotkeySC.bin...

I've sent a sample (MsgBox.exe) to AVG.


Edit: btw, the description for Ask for Help is
Quote:
Ask questions and (hopefully) get answers.
NOT
Quote:
Ask for help with scripting
That aside, anti-virus false positives prevent users from running the scripts. It is a problem that needs a solution, and it relates directly to AutoHotkey. I strongly suggest that this thread belongs in Ask for Help.

[Mod edit: yes I think so too; I guess another moderator thought there was a conflict of interests earlier on in this discussion]
Back to top
View user's profile Send private message
Lexikos



Joined: 17 Oct 2006
Posts: 2739
Location: Australia, Qld

PostPosted: Thu Jan 17, 2008 12:14 pm    Post subject: Reply with quote

AVG Technical Support wrote:
Dear Sir/Madam,

Thank you for your email.

We have analyzed the file you have sent to us and it is false
detection. This issue will be fixed in next update as soon as
possible.

Please accept our apologize for any inconvenience this may cause to
you.

If there are any other suspicious files, please feel free to contact
us again.

Thank you for your cooperation.
Back to top
View user's profile Send private message
ManaUser



Joined: 24 May 2007
Posts: 906

PostPosted: Thu Jan 17, 2008 5:17 pm    Post subject: Reply with quote

Ah, good that this is (hopefully) taken care of.
Back to top
View user's profile Send private message
POINTS



Joined: 17 Jan 2006
Posts: 284

PostPosted: Tue Feb 12, 2008 9:19 am    Post subject: AVG Reply with quote

For anyone having this problem again, I was able to use my compiled code when I rolled back to 1.0.47.3. (I don't have 1.0.47.4 but that might work too.)
_________________
My AutoHotkey Program for Warcraft III:
Warkeys
http://warkeys.sourceforge.net/

Remap your hotkeys
Healthbars always on
Remap inventory
Back to top
View user's profile Send private message Visit poster's website
BikerDude
Guest





PostPosted: Sun Feb 24, 2008 2:42 pm    Post subject: Reply with quote

Just did a scan with http://virusscan.jotti.org/ and got 2 hits

Scan taken on 24 Feb 2008 14:21:50 (GMT)
A-Squared
Found nothing
AntiVir
Found nothing
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found nothing
CPsecure
Found Troj.Spy.W32.Agent.bdw
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
F-Secure Anti-Virus
Found nothing
Fortinet
Found nothing
Ikarus
Found nothing
Kaspersky Anti-Virus
Found nothing
NOD32
Found nothing
Norman Virus Control
Found nothing
Panda Antivirus
Found nothing
Rising Antivirus
Found nothing
Sophos Antivirus
Found nothing
VirusBuster
Found nothing
VBA32
Found Trojan-Spy.Win32.Agent.bbg

So there still some out that causing this issue
Back to top
Guest.2
Guest





PostPosted: Fri Mar 07, 2008 9:48 am    Post subject: Reply with quote

Still got Hits with

eSafe 7.0.15.0 2008.03.06 suspicious Trojan/Worm
Ikarus T3.1.1.20 2008.03.07 Trojan-Spy.Win32.Agent.bbg
Panda 9.0.0.4 2008.03.06 Suspicious file

CPsecure Troj.Spy.W32.Agent.bdw (this one from jotti)

weird:
NOD32v2 2928 2008.03.06 archive damaged

using 1.0.47.05


Now I'm using 1.0.46.17 again, no false positives so far. I habe no choice than to avoid those alerts.
Back to top
Oberon



Joined: 18 Feb 2008
Posts: 453

PostPosted: Fri Mar 07, 2008 1:44 pm    Post subject: Reply with quote

The best course of action is to use and distribute text scripts instead of compiled ones. AutoHotkey.exe is the only required dependency.
Back to top
View user's profile Send private message
CuriousUser
Guest





PostPosted: Thu Apr 03, 2008 8:00 pm    Post subject: Autoit.ABB in AVG Reply with quote

So they updated AVG and now it detects the Worm\Autoit.ABB in warkeys. I emailed AVG with no response yet. Any Idea as to why this is happening ? I cant set my keys currently because AVG will not let me access the file.
Back to top
AnotherCuriousGuest
Guest





PostPosted: Sun Apr 13, 2008 2:58 am    Post subject: Reply with quote

Ya I'm having the same trouble as "CuriousGuest"

I just updated to the newest version of both warkeys and avg and I get Threat Detected! Warkeys.exe ... virus identified Worm / Autoit.ABB
Back to top
ahklerner



Joined: 26 Jun 2006
Posts: 1249
Location: USA

PostPosted: Sun Apr 13, 2008 3:01 am    Post subject: Reply with quote

I looked for the post by "CuriousGuest" and could not locate it.
_________________

ʞɔпɟ əɥʇ ʇɐɥʍ
Back to top
View user's profile Send private message
AnotherCuriousGuest
Guest





PostPosted: Sun Apr 13, 2008 10:10 pm    Post subject: Reply with quote

sorry i meant "CuriousUser" ... the post directly above mine
Back to top
TecnoCR
Guest





PostPosted: Sun Aug 17, 2008 2:53 pm    Post subject: Reply with quote

For my was on a corporate network, and it's not detected as a virus but detected as a possible threat, script creating copiled exe, basic virus behavior. I have the rules and keys that needs to be created for Symantec Corporate, if any body is interested.
Back to top
Display posts from previous:   
Post new topic   Reply to topic    AutoHotkey Community Forum Index -> Ask for Help All times are GMT
Goto page Previous  1, 2
Page 2 of 2

 
Jump to:  
You can post new topics in this forum
You can reply to topics in this forum


Powered by phpBB © 2001, 2005 phpBB Group