Jump to content

Recommended Posts

Posted

Did you read this >thread?

You need to give us more information. Which AutoIt version do you use to compile yourscript? Do you use UPX?

My UDFs and Tutorials:

  Reveal hidden contents

 

Posted

@jiks,

1) testing exe's with VirusTotal is a good habit. keep up with it.

2) see the thread water linked to.

3) it is possible that the exe is infected because your computer is infected. are you sure you are clean? what AV are you using? 

4) since the au3 code is basically stored as text in the exe, what triggers the AV engines is the AutoIt engine, so basically it makes very little difference what is the au3 code you compile.

5) i reproduced you test:

default compiler settings:

https://www.virustotal.com/en/file/7338b6828d47e24cb4f971bc727323ee2dd980d21160dd1d8eb6bb2b214ebbb4/analysis/1376380149/

UPX disabled:

https://www.virustotal.com/en/file/f15eb01b0f36bdcce6f10b12211767f3c2d8772f68838c49458ae12e02540c5e/analysis/1376380323/

2/45 is clean. if it was infected, the result would be around 40/45.

side note: what is bothering is that one of the false positives comes from McAfee (gateway heuristics). however, i bet you Obama's paycheck that this will be changed in one of the upcoming updates, these things tend to be random.

6) please link to your test results page in VirusTotal.

Signature - my forum contributions:

  Reveal hidden contents

 

Posted
  On 8/13/2013 at 8:13 AM, FireFox said:

If you really want a result of 0/45, compile it with the latest beta.

why is that?

Signature - my forum contributions:

  Reveal hidden contents

 

Posted

The internal structure is not yet known by the AV to analyze it (this is a personal deduction and I may be wrong and I hope someone to correct me :) )

Posted (edited)

  On 8/13/2013 at 8:27 AM, FireFox said:

The internal structure is not yet known by the AV to analyze it (this is a personal deduction and I may be wrong and I hope someone to correct me :) )

I think it's because the betas are in a state of change so few if any are writing malicious applications with them.

Sadly I think all this will change once a stable version is released, but for now armored or unarmored beta standalones cause very few false positives.

Ed: I wouldn't start telling people to not use older au3 versions simply because of crummy Av flags.

Edited by Mobius

wtfpl-badge-1.png

  • Moderators
Posted

Hi,

I think the Oozlum bird has had its exercise for the day and vanished up its own fundament as usual. :D

M23

Public_Domain.png.2d871819fcb9957cf44f4514551a2935.png Any of my own code posted anywhere on the forum is available for use by others without any restriction of any kind

Open spoiler to see my UDFs:

  Reveal hidden contents

 

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...