Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.basic.visual.misc > #1931

Re: After Install/Run antivirus software classifies my EXEs as 'suspicious'

From GS <gs@somewhere.net>
Newsgroups comp.lang.basic.visual.misc, microsoft.public.vb.general.discussion
Subject Re: After Install/Run antivirus software classifies my EXEs as 'suspicious'
Date 2013-12-19 23:03 -0500
Organization A noiseless patient Spider
Message-ID <l90fio$eg0$1@dont-email.me> (permalink)
References <l90a9j$n0l$1@dont-email.me> <k4d7b9h627tv0vfn074ik2lskcpevtqape@4ax.com>

Cross-posted to 2 groups.

Show all headers | View raw


> First off, is this a joke? Of course there is no such 'flag'! If 
> there
> really was such a thing the very first step anyone, planning evil,
> would do is to set the 'flag'. <G>

Yeah.., dumb Q now that I think of it!
>
> Your application is considered 'suspicious' because when scanned by
> antivirus software it appears to contain malicious code.  Exactly 
> what
> that code might be can be difficult at times to determine. Your app
> may in fact, albeit innocently, be attempting to do something
> considered nefarious.

They're frontloader EXEs that automate Excel, mostly. (One is an actual 
 VB6 app)
>
> Take a hard look at what your application is doing. If it is taking
> liberties with security - re-write it.

Not the case, though they all use WMI at startup.
>
> Or it may be a false positive. This happens on occasion and can come
> about purely by accident. Some arrangement within your application of
> perfectly benign statements creates a series of bits in the binary
> which map 'signatures' of known malware.
>
> Can be very tough to ferret out. Unfortunately, the usual procedure 
> is
> to remove blocks of functionality until you can isolate the problem 
> to
> a limited area, then often a simple rearrangement of code can resolve
> the problem.

Perhaps I'll test without the code using WMI. Everything else is basic 
VB...
>
> Then of course your compiler, components, or installer may have 
> picked
> up a virus. Is your development box clean?

Yes!
>
> Most antivirus software allow you to over-ride some complaints.
> Generally consider unwise to grant exceptions but can be employed in 
> a
> pinch. In-house that is. 

Yeah, I have to set exceptions on their top level folder in my 
antivirus software.
> Don't expect any customers to be so trusting.

-- 
Garry

Free usenet access at http://www.eternal-september.org
Classic VB Users Regroup!
  comp.lang.basic.visual.misc
  microsoft.public.vb.general.discussion



---
This email is free from viruses and malware because avast! Antivirus protection is active.
http://www.avast.com

Back to comp.lang.basic.visual.misc | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

After Install/Run antivirus software classifies my EXEs as 'suspicious' GS <gs@somewhere.net> - 2013-12-19 21:33 -0500
  Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' ralph <nt_consulting@yahoo.com> - 2013-12-19 21:41 -0600
    Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' GS <gs@somewhere.net> - 2013-12-19 23:03 -0500
    Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' Tony Toews <ttoews@telusplanet.net> - 2013-12-19 22:59 -0700
  Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' "Mayayana" <mayayana@invalid.nospam> - 2013-12-19 23:06 -0500
    Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' GS <gs@somewhere.net> - 2013-12-19 23:48 -0500
      Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' "Mayayana" <mayayana@invalid.nospam> - 2013-12-20 08:32 -0500
        Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' ralph <nt_consulting@yahoo.com> - 2013-12-20 10:39 -0600
          Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' "Mayayana" <mayayana@invalid.nospam> - 2013-12-20 18:09 -0500
            Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' ralph <nt_consulting@yahoo.com> - 2013-12-20 17:22 -0600
        Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' GS <gs@somewhere.net> - 2013-12-20 13:05 -0500
  Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' "Farnsworth" <nospam@nospam.com> - 2013-12-20 00:01 -0500
    Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' GS <gs@somewhere.net> - 2013-12-20 14:50 -0500
  Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' Tony Toews <ttoews@telusplanet.net> - 2013-12-19 23:02 -0700
  Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' ObiWan <obiwan@mvps.org> - 2013-12-20 08:29 +0100
    Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' GS <gs@somewhere.net> - 2013-12-20 12:57 -0500
  a/v report GS <gs@somewhere.net> - 2013-12-20 13:16 -0500
    Re: a/v report "Farnsworth" <nospam@nospam.com> - 2013-12-20 14:21 -0500
      Re: a/v report GS <gs@somewhere.net> - 2013-12-20 14:28 -0500
        Re: a/v report "CoderX" <coder@x.com> - 2013-12-22 12:57 -0500
        Re: a/v report Wolfgang Enzinger <we_usenet@nurfuerspam.de> - 2013-12-23 23:12 +0100
    Re: a/v report "Brian Kelly" <Brian@mcmail.com.not> - 2013-12-20 20:52 +0000
      Re: a/v report GS <gs@somewhere.net> - 2013-12-20 16:08 -0500
        Re: a/v report Wolfgang Enzinger <we_usenet@nurfuerspam.de> - 2013-12-21 12:36 +0100
          Re: a/v report ralph <nt_consulting@yahoo.com> - 2013-12-21 07:12 -0600
            Re: a/v report Wolfgang Enzinger <we_usenet@nurfuerspam.de> - 2013-12-23 23:12 +0100
          Re: a/v report GS <gs@somewhere.net> - 2013-12-21 10:54 -0500
          Re: a/v report ObiWan <obiwan@mvps.org> - 2013-12-22 18:08 +0100
            Re: a/v report Wolfgang Enzinger <we_usenet@nurfuerspam.de> - 2013-12-23 23:11 +0100
  VirusTotal report GS <gs@somewhere.net> - 2013-12-20 14:34 -0500
    Re: VirusTotal report "CoderX" <coder@x.com> - 2013-12-22 12:59 -0500
      Re: VirusTotal report Tony Toews <ttoews@telusplanet.net> - 2013-12-22 12:52 -0700
        Re: VirusTotal report GS <gs@somewhere.net> - 2013-12-22 19:51 -0500
          Re: VirusTotal report "CoderX" <coder@x.com> - 2013-12-23 15:57 -0500
        Re: VirusTotal report "CoderX" <coder@x.com> - 2013-12-23 15:59 -0500
  Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' "Abhishek" <abhishek007p@hotmail.com> - 2013-12-21 17:28 +0530
    Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' "Mayayana" <mayayana@invalid.nospam> - 2013-12-21 09:08 -0500
      Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' GS <gs@somewhere.net> - 2013-12-21 10:59 -0500
        Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' "Mayayana" <mayayana@invalid.nospam> - 2013-12-21 14:53 -0500
          Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' GS <gs@somewhere.net> - 2013-12-21 16:06 -0500
          Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' GS <gs@somewhere.net> - 2013-12-21 16:40 -0500
    Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' "Abhishek" <abhishek007p@hotmail.com> - 2013-12-21 22:58 +0530
      Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' GS <gs@somewhere.net> - 2013-12-21 13:43 -0500
        Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' Deanna Earley <dee.earley@icode.co.uk> - 2013-12-23 09:08 +0000
          Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' Tony Toews <ttoews@telusplanet.net> - 2013-12-23 03:04 -0700
            Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' Deanna Earley <dee.earley@icode.co.uk> - 2013-12-23 10:24 +0000
              Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' GS <gs@somewhere.net> - 2013-12-23 11:42 -0500
                Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' ralph <nt_consulting@yahoo.com> - 2013-12-23 11:25 -0600
                Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' GS <gs@somewhere.net> - 2013-12-23 12:48 -0500
                Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' Tony Toews <ttoews@telusplanet.net> - 2013-12-23 12:08 -0700
                Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' ralph <nt_consulting@yahoo.com> - 2013-12-23 13:54 -0600
                Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' Tony Toews <ttoews@telusplanet.net> - 2013-12-23 12:06 -0700
                Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' GS <gs@somewhere.net> - 2013-12-23 15:15 -0500
                Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' Deanna Earley <dee.earley@icode.co.uk> - 2014-01-02 14:49 +0000
                Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' ObiWan <obiwan@mvps.org> - 2014-01-02 16:03 +0100
                Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' Deanna Earley <dee.earley@icode.co.uk> - 2014-01-02 15:06 +0000
                Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' ObiWan <obiwan@mvps.org> - 2014-01-02 16:17 +0100
                Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' Tony Toews <ttoews@telusplanet.net> - 2014-01-04 23:23 -0700
                Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' ObiWan <obiwan@mvps.org> - 2014-01-05 17:09 +0100
              Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' Tony Toews <ttoews@telusplanet.net> - 2013-12-23 11:58 -0700
                Re: After Install/Run antivirus software classifies my EXEs as 'suspicious' Tony Toews <ttoews@telusplanet.net> - 2013-12-23 12:09 -0700

csiph-web