Author Topic: AutoIt false positives  (Read 12220 times)

0 Members and 1 Guest are viewing this topic.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
AutoIt false positives
« on: October 17, 2006, 08:23:30 PM »
I have sent a lot of files to analysis in the past that were false positives of AutoIt scripts.
In the last VPS, a lot of false detections were back again  :'(
Igor, can you check?

17/10/2006 15:08:32 1161108512 SYSTEM 924 Sign of "Win32:Autoit [Trj]" has been found in "...\Flush DNS.exe\[UPX]" file.
17/10/2006 15:09:14 1161108554 SYSTEM 924 Sign of "Win32:Autoit [Trj]" has been found in "...\avast! Update Silent.exe\[UPX]" file.
The best things in life are free.

Stevieboy

  • Guest
Re: AutoIt false positives
« Reply #1 on: October 17, 2006, 08:37:40 PM »
Same here ...  :o  ;D

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: AutoIt false positives
« Reply #2 on: October 17, 2006, 09:18:09 PM »
I would have though that by now that Alwil wouldn't have just given a specific autoit malware name, but obtained a copy of autoit and tried to identify what it is in the autoit conversion process to an executable file that caused the problem ???
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

SWINX

  • Guest
Re: AutoIt false positives
« Reply #3 on: October 17, 2006, 11:26:11 PM »
I've created a sort of task sheduler with AutoIt which runs a program on a certain time.
The task shedular exe runs without any problem, but when it calls the backup utility, Avast gives the trojan horse alert (Win32.AutoIt Trojan Horse). Both programs are created with the same AutoIt version.
The filename is mentioned as backup.exe\[UPX] on the Avast alert message.

This shouldn't be an trojan...

[edit] The task shedular was already running some hours before avast updated his virus definitions this night.
It also won't run anymore now because avast denies the access :(
« Last Edit: October 17, 2006, 11:31:33 PM by SWINX »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: AutoIt false positives
« Reply #4 on: October 17, 2006, 11:37:47 PM »
If you are certain it isn't infected (and it probably isn't) add it to the exclusions lists:
Standard Shield, Customize, Advanced add the path and file name e.g. C:\*\autoit-file-folder\backup.exe the wild card can be used to shorten the path.
Program Settings, Exclusions

I'm not sure of the benefit of sending it to avast other than highlight yet another autoit compiled file being detected again.
Also see (Mini Sticky) False Positives, how to report and what to do to exclude them until the problem is corrected.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: AutoIt false positives
« Reply #5 on: October 18, 2006, 03:09:42 AM »
I've created a sort of task sheduler with AutoIt which runs a program on a certain time.
It won't be bad if they test more than now, because I know they test AutoIt executable files.
My avast! tweaker, which development is 'stopped' right now, I'm with very little 'spare' time, it is detected by avast too.
Well, false positives are really a pain. I've added my AutoIt executables to the avast Exclusion lists. Peace  8)
The best things in life are free.

Nathan Baulch

  • Guest
Re: AutoIt false positives
« Reply #6 on: October 18, 2006, 03:19:58 AM »
Same here when trying to use "Universal Extractor".
And to make matters worse, the following two exclusions:

C:\Program Files\Universal Extractor\bin\*
C:\Program Files\Universal Extractor\bin\UniExtract.exe

still dont fix the problem!
Running "UniExtract.exe" causes a windows error "Windows cannot access the specified device, path, or file.  You may not have the appropriate permissions to access the item."
If I reboot and run it again, I get an Avast infection notification.
This is so incredibly anoying...

lian

  • Guest
Re: AutoIt false positives
« Reply #7 on: October 18, 2006, 09:46:33 AM »
Same Autoit problem with a little script running two exe files.

Offline XMAS

  • Avast translator
  • Super Poster
  • ***
  • Posts: 1211
  • Santa is watching you ;)
    • avast! in Bulgarian
Re: AutoIt false positives
« Reply #8 on: October 18, 2006, 01:52:22 PM »
The problem seems to be fixed with the latest VPS update - 0642-1.
Tech's Tweaker is no longer detected as virus. Can someone confirm this.  ::)

EDIT: Now the latest VPS is 0642-2.
« Last Edit: October 18, 2006, 02:59:13 PM by .:XMAS:. »
You've Got To Get Close To The Flame To See What It's Made Of...

Offline TedNelly

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1538
  • Trust No-One!
Re: AutoIt false positives
« Reply #9 on: October 18, 2006, 02:59:44 PM »
  hello .:XMAS:. the latest VPS update - 0642-1  seem to have fixed the problem with Tech's Tweaker

sorry VPS update - 0642-2

Windows 10 Pro | Intel I7 CPU | 16 Gig 2133 RAM | Avast beta 17.5.2295 | Firefox 54 b9(64-bit) | Cyberfox 52.1 | T-Bird 52.1.1 | SpyWareBlaster 5.5 | MalwareBytes 3.0.0.865 | WinPatrol 35.5.2 | GlassWire 1.2.100 | Cybereason Ransomfree 2.2.7 |  Pulla-dePlug Final!

Stevieboy

  • Guest
Re: AutoIt false positives
« Reply #10 on: October 18, 2006, 09:54:01 PM »
I love it when a plan comes together.

It's fixed  ;D

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: AutoIt false positives
« Reply #11 on: October 19, 2006, 03:14:14 AM »
Well... I've blamed. So I've thank avast now for solved the issue  ;)
The best things in life are free.

1st_Moon

  • Guest
Re: AutoIt false positives
« Reply #12 on: January 04, 2008, 08:54:08 AM »
The problem seems to be fixed with the latest VPS update - 0642-1.

So I've installed the current AutoIt 3.2.81 and the Scite version that comes with it. Now the

Autoit3Wrapper.exe
Autoit3WrapperGUI.exe

are detected as infected with Win32:Agent-OYT [tri]

Now is this a false positive or what? Thx.

Offline misak

  • Moderator
  • Sr. Member
  • *
  • Posts: 234
    • Personal page (CZE)
Re: AutoIt false positives
« Reply #13 on: January 04, 2008, 10:17:06 AM »
Are you sure, that your Avast VPS database is up to date? All AutoIt 3.2.8.1 files tested with current VPS (080103-0) are clear.

1st_Moon

  • Guest
Re: AutoIt false positives
« Reply #14 on: January 04, 2008, 04:46:39 PM »
Yes, I do have that very same VPS database installed.

However, these files are only installed when you also install the current Scite version from the AutoIt page. The files reside in \AutoIt\Scite\AutoIt3Wrapper.

I've mailed those files to virus (at) avast (dot) com, maybe they can sort it out.
« Last Edit: January 04, 2008, 04:51:28 PM by 1st_Moon »