TheDcoder Posted November 22, 2017 Share Posted November 22, 2017 Windows Defender does not have a reliable detection consistency, each user has different experience with files. I guess it depends on the heuristics and origin of the files. I have also found that not using UPX greatly reduces false positives... I had 46 detections when using UPX, went down to 2 without UPX . EasyCodeIt - A cross-platform AutoIt implementation - Fund the development! (GitHub will double your donations for a limited time) DcodingTheWeb Forum - Follow for updates and Join for discussion Link to comment Share on other sites More sharing options...
KaFu Posted November 22, 2017 Share Posted November 22, 2017 I do not UPX anything by default, but maybe some of the dlls or supporting exes are upxed and trigger the detection. OS: Win10-22H2 - 64bit - German, AutoIt Version: 3.3.16.1, AutoIt Editor: SciTE, Website: https://funk.eu AMT - Auto-Movie-Thumbnailer (2024-Oct-13) BIC - Batch-Image-Cropper (2023-Apr-01) COP - Color Picker (2009-May-21) DCS - Dynamic Cursor Selector (2024-Oct-13) HMW - Hide my Windows (2024-Oct-19) HRC - HotKey Resolution Changer (2012-May-16) ICU - Icon Configuration Utility (2018-Sep-16) SMF - Search my Files (2024-Oct-20) - THE file info and duplicates search tool SSD - Set Sound Device (2017-Sep-16) Link to comment Share on other sites More sharing options...
Earthshine Posted November 22, 2017 Share Posted November 22, 2017 (edited) i ran it at work and that happened. lol said it was a trojan. i just run it in vms Edited November 22, 2017 by Earthshine My resources are limited. You must ask the right questions Link to comment Share on other sites More sharing options...
Deye Posted November 24, 2017 Share Posted November 24, 2017 Bad rep added : How to prevent static AV detection ? posted just a few days ago : https://threatpost.com/autoit-scripting-used-by-overlay-malware-to-bypass-av-detection/128845/ Earthshine 1 Link to comment Share on other sites More sharing options...
Earthshine Posted November 24, 2017 Share Posted November 24, 2017 After I ran SMF that Trojan warning triggered My resources are limited. You must ask the right questions Link to comment Share on other sites More sharing options...
Earthshine Posted November 27, 2017 Share Posted November 27, 2017 @KaFu, it was the SMF_TNP.exe helper that triggers the Trojan My resources are limited. You must ask the right questions Link to comment Share on other sites More sharing options...
iamtheky Posted November 27, 2017 Share Posted November 27, 2017 On 11/24/2017 at 4:47 AM, Deye said: Bad rep added : How to prevent static AV detection ? posted just a few days ago : https://threatpost.com/autoit-scripting-used-by-overlay-malware-to-bypass-av-detection/128845/ While 1 For every post in the "is my exe really infected" thread, there is an article about malware authors compiling with AutoIt to obfuscate signatures. Wend Earthshine 1 ,-. .--. ________ .-. .-. ,---. ,-. .-. .-. .-. |(| / /\ \ |\ /| |__ __||| | | || .-' | |/ / \ \_/ )/ (_) / /__\ \ |(\ / | )| | | `-' | | `-. | | / __ \ (_) | | | __ | (_)\/ | (_) | | .-. | | .-' | | \ |__| ) ( | | | | |)| | \ / | | | | | |)| | `--. | |) \ | | `-' |_| (_) | |\/| | `-' /( (_)/( __.' |((_)-' /(_| '-' '-' (__) (__) (_) (__) Link to comment Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now