Results 1 to 5 of 5
  1. #1
    Contributor Kubiatsu's Avatar
    Reputation
    158
    Join Date
    Feb 2007
    Posts
    501
    CoreCoins
    0

    Trade Feedbacks

    Positive
    0
    Negative
    0

    [Info] Are my AutoIt EXEs really infected?

    Many AutoIt EXEs sometimes show that they are infected when scanned, and people are wrongly accused when they post a new program/bot so I thought I would share some information for people who do not understand why AutoIt EXEs can show as infected when they are infact not infected at all.

    Taken from the official AutoIt forums:


    If you have been using AutoIt for any length of time you will know that it is a great, and powerful scripting language. As with all powerful languages there comes a downside. Virus creation by those that are malicious.

    AutoIt has no virii installed on your system, and if a script you have created has been marked as a virus, (and you're not malicious) then this is a false positive. They found a set of instructions in an AutoIt EXE out there somewhere, took the general signature of the file, and now all AutoIt EXE's are marked (or most of them). This can be due to several reasons.
    1. AutoIt is packed with UPX. UPX is an open source software compression packer. It is used with many virii (to make them smaller).
    2. Malicious scripter got the AutoIt script engine recognized as a virus.
    And I am sure there are more ways your executable could be marked, but that covers the basics.

    Now I am sure you are wanting to know what you can do to get back up and running without being recognized as a virus. You have to send in a report to the offending AV company alerting them to the false positive they have made. It never hurts to send in your source code along with a compiled exe, to help them realize their mistake.

    You may have to wait up to 24 hours for them to release an update. The time it takes really depends on the offending AV company.

    Anti-Virus Links

    I hope this helps you understand why your AutoIt executables are marked as virii.


    I hope this clears a few things up.

  2. #2
    Banned
    Reputation
    17
    Join Date
    Feb 2007
    Posts
    61
    CoreCoins
    0

    Trade Feedbacks

    Positive
    0
    Negative
    0

    Re: [Info] Are my AutoIt EXEs really infected?

    nice explanation + rep

  3. #3
    Banned
    Reputation
    9
    Join Date
    Apr 2007
    Location
    37
    Posts
    195
    CoreCoins
    0

    Trade Feedbacks

    Positive
    0
    Negative
    0

    Re: [Info] Are my AutoIt EXEs really infected?

    Nice explanation dude + rep

  4. #4
    lag
    lag is offline
    The ERP Chicken lag's Avatar
    Reputation
    453
    Join Date
    Jan 2007
    Location
    At Work
    Posts
    641
    CoreCoins
    3

    Trade Feedbacks

    Positive
    0
    Negative
    0

    Re: [Info] Are my AutoIt EXEs really infected?

    Good infos, although I think it is still good to run AutoIt applications in a sandbox environment first if you are unsure.

    +rep when I can again

    Marlo was here || idusy was here cause he feels left out || Im in ur sig , shardin ur letters - Flying Piggy || Errage was here- Wait, what? || ''Edge was here'' imo =P || Dragonshadow's name makes this too long |2d is hot|

  5. #5
    Master Sergeant Brandaho's Avatar
    Reputation
    15
    Join Date
    Sep 2007
    Location
    Right Here
    Posts
    129
    CoreCoins
    0

    Trade Feedbacks

    Positive
    0
    Negative
    0

    Re: [Info] Are my AutoIt EXEs really infected?

    One this up and make it a sticky. So people can easily find it.

 

 

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
All times are GMT -4. The time now is 10:32 AM. Powered by vBulletin® Version 4.2.0
Copyright © 2013 vBulletin Solutions, Inc. All rights reserved.
Content Relevant URLs by vBSEO
vBulletin Optimisation by vB Optimise. Digital Point modules: Sphinx-based search

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192