PDA

View Full Version : Fixed (Heuristics): Is AutoIt flagged or not?



czardas
2011-12-01, 22:46
Hi this is my first post.

I'm not certain if the AutoIt user who posted the following thread on autoitscript.com forum has infected files or not. I have not been able to confirm this as a false positive since my detection rules are out of date. I don't intend to update Spybot S&D to confirm the result, since that has the potential to make my life very complicated. I have very many au3 scripts on my system and if SpyBot S&D is throwing false positives on AutoIt, or compiled au3 scripts, many people including myself will have problems with that.

http://www.autoitscript.com/forum/topic/135250-spybot-sd-sees-autoit3-as-yobdamait/

I have used Spybot for many years and it is what I consider to be an industry standard. I joined to ask for assurances that AutoIt is not being flagged as malware. Saying AutoIt is malware would be like saying javascript or ruby is malware. :confused:

Thanks in advance to anyone who can throw light on this.
---------------------------------
It appears I posted this in the wrong forum. If it could be moved to False Positives.

Thank you.
---------------------------------
I posted a topic in the wrong forum and have had no reply. I should have posted the following topic here. Please could someone look into this, since I would like to update my detection rules, but I am too afraid to do so.

Is this a false positive? If nobody can answer this question, does anyone know who to ask?
---------------------------------
It seems I'm not the only concerned user:

http://forums.spybot.info/showpost.php?p=417162&postcount=1

tashi
2011-12-03, 15:18
Hello czardas,

Please see this topic: How to report possible False Positives (http://forums.spybot.info/showthread.php?t=19117)

The office is closed on the weekend but please post the information and a detective will respond when on-line. :)

Best regards.

czardas
2011-12-04, 12:27
Hi tashi, and thanks for your responce. I'll send some of my personal compiled scripts along with the source code in a zip file for testing, after I have read the proceedure. It's not the first time AutoIt has thrown false positives, but never with Spybot as far as I know. It is also possible that the actual report itself is a false positive. I would like to find out before I attempt to update my detection rules.

On a side note, it saddens me that some people have used my favourite scripting language to create malware. Although it is a powerful tool, AutoIt is not so widely used as some other scripting languages. On the other hand it's nice to know that companies such as Microsoft and Toshiba, have on accasion, bundled compiled AutoIt scripts to automate installation proceedures for some of there products. :)

Yodama
2011-12-05, 09:07
Hello,
thanks for reporting.
I can confirm this false positive. It will be fixed with our next detection update scheduled for Wednesday 2011-12-07.

czardas
2011-12-06, 13:22
Thank you very much. Spybot S&D is such an excellent program. :)