AutoIt and Malware: Difference between revisions

From AutoIt Wiki
Jump to navigation Jump to search
mNo edit summary
(→‎Reporting False Positives: added ALL VENDORS LIST)
(23 intermediate revisions by 6 users not shown)
Line 1: Line 1:
If you have been using AutoIt for any length of time you will know that it is a great, and powerful scripting language. As with all powerful languages there comes a downside. Virus creation by those that are malicious. AutoIt has no viruses installed on your system, and if a script you have created has been marked as a virus, (and you're not malicious) then this is a [http://www.pcguide.com/care/data/virus/scanFalse-c.html false positive]. They found a set of instructions in an AutoIt EXE out there somewhere, took the general signature of the file, and now all AutoIt EXE's are marked (or most of them). This can be due to several reasons.
==Overview==
If you have been using AutoIt for any length of time you will know that it is a great and powerful scripting language. As with all powerful languages there comes a downside: virus creation by those with malicious intent. AutoIt has no viruses installed on your system, and if a script you have created has been marked as a virus (and you're not malicious) then this is a [http://www.pcguide.com/care/data/virus/scanFalse-c.html false positive]. The most common cause is an AntiVirus engine has found a set of instructions in an AutoIt EXE and deemed it malicious, took the general signature of the file, and has now flagged all (or most) AutoIt EXE's. This can be due to several reasons:


* AutoIt is packed with UPX. UPX is an open source software compression packer. It is used with many viruses (to make them smaller).
* Compiled AutoIt scripts can optionally be compressed with UPX. UPX is an open source software compression packer. It is used with many viruses (to make them smaller).
* Malicious scripter got the AutoIt script engine recognized as a virus.
* A malicious scripter got the AutoIt script engine recognized as a virus.
 
There are more ways your executable could be marked; this topic covers only the most common causes.
 
==Reporting False Positives==
If you encounter a false positive, in which your script is erroneously recognized as a virus, please alert the offending AV company immediately so the matter can be resolved. Best practice would be to include your source code along with a compiled exe, allowing the AV company to independently verify your report. This process may take up to 24 hours depending on the AV company, but will be resolved much more quickly if you provide source code.
 
A good resource for reporting false positives can be found at: [http://www.techsupportalert.com/content/how-report-malware-or-false-positives-multiple-antivirus-vendors.htm How to Report Malware or False Positives to Multiple Antivirus Vendors]. There are also some links below to help.


And I am sure there are more ways your executable could be marked, but that covers the basics. Now I am sure you are wanting to know what you can do to get back up and running without being recognized as a virus. You have to send in a report to the offending AV company alerting them to the false positive they have made. It never hurts to send in your source code along with a compiled exe, to help them realize their mistake. You may have to wait up to 24 hours for them to release an update. The time it takes really depends on the offending AV company. Anti-Virus Links


* AntiVir
* AntiVir
** [http://www.avira.com/ Website]
** [http://www.avira.com/ Website]
** [http://forum.avira.de/board.php?boardid=91 Contact]
** [https://analysis.avira.com/en/submit Contact]


* Avast!
* Avast!
Line 16: Line 23:
* McAfee
* McAfee
** [http://www.mcafee.com/ Website]
** [http://www.mcafee.com/ Website]
** [mailto:vendor_questions@mcafee.com Contact] (email address)
** [https://community.mcafee.com/thread/2016 Contact]


* Symantec (Norton)
* Symantec (Norton)
** [http://www.symantec.com/ Website]
** [http://www.symantec.com/ Website]
** [https://symantec.iseva.net/customerservice.aspx Contact]
** [https://submit.symantec.com/false_positive/?inid=us_sr_flyout_contact_reportfalse Contact]


* AVG
* AVG
** [http://www.grisoft.com/ Website]
** [http://www.grisoft.com/ Website]
** [http://www.grisoft.com/doc/110/lng/us/tpl/tpl01 Contact] (It says sales or other ?'s I assume this will work)
** [http://forums.avg.com/ww-en/avg-forums?sec=thread&act=show&id=395 Contact]
 
* G Data
** [https://www.gdatasoftware.com/securitylabs.html Sample Submission]


* ClamWin
* ClamWin
** [http://www.clamwin.com/ Website]
** [http://www.clamwin.com/ Website]
** [http://forums.clamwin.com/ Contact]
** [http://www.clamav.net/lang/en/sendvirus/submit-fp/ Contact]


* ClamAV
* ClamAV
Line 44: Line 54:
* Norman
* Norman
** [http://www.norman.com/ Website]
** [http://www.norman.com/ Website]
** [mailto:support@norman.com Contact] (email address)
** [mailto:support@norman.com Contact]


* eSafe
* eSafe
** [http://www.ealaddin.com/ Website]
** [http://www.ealaddin.com/ Website]
** [http://techsup.ealaddin.com/ Contact] (login required)
** [https://portal.aladdin.com/ Contact] (login required)


* A-Squared
* A-Squared
** [http://www.emsisoft.com/ Website]
** [http://www.emsisoft.com/ Website]
** [mailto:fp@emsisoft.com Contact] (email address)
** [mailto:fp@emsisoft.com Contact]
 
* SUPERAntiSpyware
** [http://www.superantispyware.com/ Website]
** [http://www.superantispyware.com/downloads/SUPERSampleSubmit.exe Contact]
 
* ESET
** [http://www.eset.com/int/ Website]
** [http://kb.eset.com/esetkb/index?page=content&id=SOLN141 Contact]
 
* Kaspersky
** [http://www.kaspersky.com/ Website]
** [https://my.kaspersky.com/?logonSessionData=MyAccount&returnUrl=en%2fsupport Contact] (login required)
 
* Microsoft Security Essentials
** [http://www.microsoft.com/ Website]
** [https://support.microsoftsecurityessentials.com/default.aspx?productkey=morromalware&mytask=country Contact]
 
* Avira Free Antyvirus
** [http://www.avira.com/en/avira-free-antivirus Website]
** [https://analysis.avira.com/en/submit Contact]
 
* Panda Security
** [http://www.pandasecurity.com/poland/homeusers/solutions/antivirus/ Website]
** [http://support.pandasecurity.com/forum/viewtopic.php?f=5&t=337 Contact]
 
* Trend Micro
** [http://www.trendmicro.de/ Website]
** [http://esupport.trendmicro.com/consumer/default.aspx Contact]
 
* F-secure
** [http://www.f-secure.com/ Website]
** [http://www.f-secure.com/v-descs/false_positive.shtml Contact]
 
 
* How to Report Malware or False Positives to Multiple Antivirus Vendors
** [http://www.techsupportalert.com/content/how-report-malware-or-false-positives-multiple-antivirus-vendors.htm#List_Of_All_Vendors ALL VENDORS LIST]
 
[[Category:AutoIt_Wiki]]

Revision as of 08:25, 24 June 2014

Overview

If you have been using AutoIt for any length of time you will know that it is a great and powerful scripting language. As with all powerful languages there comes a downside: virus creation by those with malicious intent. AutoIt has no viruses installed on your system, and if a script you have created has been marked as a virus (and you're not malicious) then this is a false positive. The most common cause is an AntiVirus engine has found a set of instructions in an AutoIt EXE and deemed it malicious, took the general signature of the file, and has now flagged all (or most) AutoIt EXE's. This can be due to several reasons:

  • Compiled AutoIt scripts can optionally be compressed with UPX. UPX is an open source software compression packer. It is used with many viruses (to make them smaller).
  • A malicious scripter got the AutoIt script engine recognized as a virus.

There are more ways your executable could be marked; this topic covers only the most common causes.

Reporting False Positives

If you encounter a false positive, in which your script is erroneously recognized as a virus, please alert the offending AV company immediately so the matter can be resolved. Best practice would be to include your source code along with a compiled exe, allowing the AV company to independently verify your report. This process may take up to 24 hours depending on the AV company, but will be resolved much more quickly if you provide source code.

A good resource for reporting false positives can be found at: How to Report Malware or False Positives to Multiple Antivirus Vendors. There are also some links below to help.


  • ClamAV
    • Website
    • Contact (I would only contact the ones with "virusdb maintainer or virus submission management")


  • How to Report Malware or False Positives to Multiple Antivirus Vendors