Startpage-JR virus alert
#1
Posted 04 October 2006 - 08:24 AM
since this morning i have a strange problem using compiled autoit-scripts with the default icon. Everytime i want to compile the script mcAfee pops up with a virus alert "Startpage-JR". If I use another icon than the default one, there are no problems.
Does anyone know this problem too?
Andi
#2
Posted 04 October 2006 - 08:39 AM
Thanks,
Fran Varona
#3
Posted 04 October 2006 - 08:47 AM
Andi
#4
Posted 04 October 2006 - 08:49 AM
or you just get a better virusscanner.Hi people,
since this morning i have a strange problem using compiled autoit-scripts with the default icon. Everytime i want to compile the script mcAfee pops up with a virus alert "Startpage-JR". If I use another icon than the default one, there are no problems.
Does anyone know this problem too?
Andi
#5
Posted 04 October 2006 - 09:16 AM
At least, I have a solution...
#6
Posted 04 October 2006 - 09:22 AM
#7
Posted 04 October 2006 - 10:16 AM
#8
Posted 04 October 2006 - 10:46 AM
#9
Posted 04 October 2006 - 11:42 AM
I have rarely lost a compiled executable UPXed. The blind blame game just continues without thought. Virus makers use UPX but so does the 95 percent or so of other users so in the short term in saying it is a solution is weak. The option now is that a different packer can be used to make a different signiture for the common bin file used which is the more suitable solution, but on the odd chance,so can the virus makers.I always replace the upx.exe file in my installations with a dummy exe which does nothing and I have never touch wood had any virus scanner pick out an AutoIT file as a virus. I'm not bothered about the little bit of extra size in my compiled scripts
Edited by MHz, 04 October 2006 - 11:43 AM.
#10
Posted 04 October 2006 - 11:49 AM
Short term solution.
I will post back the results when McAfee gives me feed back.
Wayne
Edited by wkeeter, 04 October 2006 - 11:52 AM.
#11
Posted 04 October 2006 - 12:21 PM
I have rarely lost a compiled executable UPXed. The blind blame game just continues without thought. Virus makers use UPX but so does the 95 percent or so of other users so in the short term in saying it is a solution is weak. The option now is that a different packer can be used to make a different signiture for the common bin file used which is the more suitable solution, but on the odd chance,so can the virus makers.
Well it seems to me that most of the idiots who try to write viruses with AutoIT are compiling them with the UPX packager, so it is the lame way in which the anti Virus software is detecting them, by not using the UPX packager so far mine have not been detected as a virus.
I can however tell you that someone else in our office had the issue of scripts being deleted and when he remade them without the UPX he had no problem.
So I do not think that I am playing the blind blame game as you put it.
#12
Posted 04 October 2006 - 12:43 PM
My particular AV being used does not complain, so you tell me the difference.So I do not think that I am playing the blind blame game as you put it.
#13
Posted 04 October 2006 - 01:09 PM
Edited by dj9866, 04 October 2006 - 01:29 PM.
#14
Posted 04 October 2006 - 02:02 PM
http://vil.nai.com/vil/content/v_140658.htm
I am in contact with McAfee and AVERT now to try and resolve the issue; I'm not sure McAfee Gold support has that type of clout tho'.
#15
Posted 04 October 2006 - 03:00 PM
"Its not about the 30 inch 1080p display, or the SLI 8800 ultras, or the DDR3 memory. It's about when you turn on your PC, does it return the favor?"Math is like sex. Sure, it may give some practical results, but that is not why we do it
#16
Posted 04 October 2006 - 03:13 PM
Ok today at 10:30am Mcafee has sent me an extra.dat file that resolved this issue with dat version 4865.
My scripts are no longer being deleted.
I guess you should contact them for this file.
Wayne
#17
Posted 04 October 2006 - 05:30 PM
Update!!
Ok today at 10:30am Mcafee has sent me an extra.dat file that resolved this issue with dat version 4865.
My scripts are no longer being deleted.
I guess you should contact them for this file.
Wayne
Would you be able to tell us anything else about the extra.dat so we can specifically request it when we call them?..
I sent them several compiled scripts they can "pick apart"
the website you can submit .exe's to is www.webimmune.net
Just create an account, and click submit a file. In there under Virus Name enter 'StartPage-JR Trojan-FALSE DETECTION'
The more people submit scripts (with out your domain passwords
Edited by ZipleR, 04 October 2006 - 05:31 PM.
#19
Posted 04 October 2006 - 06:51 PM
As I have made a submission to webimmune Analysis ID: 2566204 I have now found that newly released dats today 4866 no longer detect this as a virus.
Just got off the phone with them. You are Correct. 4866 fixes the problem.
Apparently if there is an extra.dat those all get included in the next .dat release
Edited by ZipleR, 04 October 2006 - 06:51 PM.
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users





