PDA

View Full Version : Why is anything written in autoit coming up as a trojan?


ChronoStriker1
July 27th, 2009, 08:26 AM
Our company uses the autoit scripting language for a lot of things, I cant start having them not work. You cant block an entire scripting language because someone has made malware with it. I can honestly say that we will be dropping eset if this isn't fixed.

WayneP
July 27th, 2009, 01:33 PM
I have just tried the newest version of autoit and compiled a few scripts into executable files. They are not being detected by the ESET software with the latest definitions. What version of autoit are you running? Do you have the latest ESET updates?

Marcos
July 27th, 2009, 02:12 PM
Of course, not every Autoit script is detected. Even if some are detected due to malware-like obfuscation, they are detected as potentially unwanted applications which cover legit tools that MAY be unwanted.

ChronoStriker1
July 27th, 2009, 02:48 PM
Most of the scripts are using v3.2.12.0 of autoit. None of them use obfuscation. I'm looking for the non compiled scripts now to see if a newer version of autoit fixes the problem.

Marcos
July 27th, 2009, 03:08 PM
The best would be to submit some examples to samples[at]eset.com with "Probable false positive" in the subject. Under what name were the files detected? Did you scan them with the most current signature db. version 4284?