AutoIt and Malware: Difference between revisions
JLogan3o13 (talk | contribs) No edit summary |
mNo edit summary |
||
Line 1: | Line 1: | ||
If you have been using AutoIt for any length of time you will know that it is a great and powerful scripting language. As with all powerful languages there comes a downside: virus creation by those with malicious intent. AutoIt has no viruses installed on your system, and if a script you have created has been marked as a virus (and you're not malicious) then this is a [http://www.pcguide.com/care/data/virus/scanFalse-c.html false positive]. The most common cause is an AntiVirus engine has found a set of instructions in an AutoIt EXE and deemed it malicious, took the general signature of the file, and has now flagged all (or most) AutoIt EXE's. This can be due to several reasons: | If you have been using AutoIt for any length of time you will know that it is a great and powerful scripting language. As with all powerful languages there comes a downside: virus creation by those with malicious intent. AutoIt has no viruses installed on your system, and if a script you have created has been marked as a virus (and you're not malicious) then this is a [http://www.pcguide.com/care/data/virus/scanFalse-c.html false positive]. The most common cause is an AntiVirus engine has found a set of instructions in an AutoIt EXE and deemed it malicious, took the general signature of the file, and has now flagged all (or most) AutoIt EXE's. This can be due to several reasons: | ||
* Compiled AutoIt scripts can optionally be compressed with UPX. UPX is an open source software compression packer. It is used with many viruses (to make them smaller). | |||
* A malicious scripter got the AutoIt script engine recognized as a virus. | |||
There are more ways your executable could be marked; this topic covers only the most common causes. If you encounter a false positive, in which your script is erroneously recognized as a virus, please alert the offending AV company immediately so the matter can be resolved. Best practice would be to include your source code along with a compiled exe, allowing the AV company to independently verify your report. This process may take up to 24 hours depending on the AV company, but will be resolved much more quickly if you provide source code. | There are more ways your executable could be marked; this topic covers only the most common causes. If you encounter a false positive, in which your script is erroneously recognized as a virus, please alert the offending AV company immediately so the matter can be resolved. Best practice would be to include your source code along with a compiled exe, allowing the AV company to independently verify your report. This process may take up to 24 hours depending on the AV company, but will be resolved much more quickly if you provide source code. |
Revision as of 13:06, 18 January 2013
If you have been using AutoIt for any length of time you will know that it is a great and powerful scripting language. As with all powerful languages there comes a downside: virus creation by those with malicious intent. AutoIt has no viruses installed on your system, and if a script you have created has been marked as a virus (and you're not malicious) then this is a false positive. The most common cause is an AntiVirus engine has found a set of instructions in an AutoIt EXE and deemed it malicious, took the general signature of the file, and has now flagged all (or most) AutoIt EXE's. This can be due to several reasons:
- Compiled AutoIt scripts can optionally be compressed with UPX. UPX is an open source software compression packer. It is used with many viruses (to make them smaller).
- A malicious scripter got the AutoIt script engine recognized as a virus.
There are more ways your executable could be marked; this topic covers only the most common causes. If you encounter a false positive, in which your script is erroneously recognized as a virus, please alert the offending AV company immediately so the matter can be resolved. Best practice would be to include your source code along with a compiled exe, allowing the AV company to independently verify your report. This process may take up to 24 hours depending on the AV company, but will be resolved much more quickly if you provide source code.
- ClamAV