Перейти из форума на сайт.

НовостиФайловые архивы
ПоискАктивные темыТоп лист
ПравилаКто в on-line?
Вход Забыли пароль? Первый раз на этом сайте? Регистрация
Компьютерный форум Ru.Board » Компьютеры » Программы » FAR Manager (часть 6)

Модерирует : gyra, Maz

Maz (26-09-2022 12:52): FAR Manager (часть 7)  Версия для печати • ПодписатьсяДобавить в закладки
На первую страницук этому сообщениюк последнему сообщению

   

Victor_VG



Tracker Mod
Редактировать | Профиль | Сообщение | Цитировать | Сообщить модератору
The zip file currently has 36 detections that are all completely different... I haven't been able to get a sensible response from anyone about it and nobody seems to know what's happening.
 
Half of the detections are:
Win32:MalwareX
Win32.Troj.Generic_a.a
Artemis!81B884FCC970
PUP/Win32.RL_Generic.R359108
Gen:Variant.Mikey.118476
Riskware/ProcHack
not-a-virus:HEUR:RiskTool.Win32.Proc
Malware.AI.1270165517
 
It's all over the place with every vendor detecting something completely different:
https://www.virustotal.com/gui/file/6104dca0af58911a9d0835c15b849754bbbe23f1c9eaf01c7ea41d50afd007a1/detection
 
The setup - which has an embedded copy of the exact same zip file - has only 9 detections but they're all different yet again:
https://www.virustotal.com/gui/file/d2dcdca30553dc0a99e541fb19d4af6735ac165be8a0becbf20f9a1df023372b/detection
 
AV software is definitely broken right now... I've discovered the "Gen:Variant.Mikey" detections are because we're using the MessageBoxW function... the others I have no idea.
 
An educated guess is that vendors updated their sandboxes/scanners with the latest Windows patches released the other day but then haven't bothered to account for internal API changes introduced by Microsoft and are now detecting those internal changes as modifications by the process being scanned man_shrugging
 
I'm going to replace MessageBoxW as a workaround for the "Gen:Variant.Mikey" detections but that might cause issues with the warning dialogs/error prompts... I'll try get some sense from vendors why their software is broken and when they're releasing fixes.
 
dmex
commented 1 hour ago
 
Microsoft and Malwarebytes have removed their detections for the latest nightly... I've also removed MessageBoxW and MessageBeep from the IAT.
 
That's 5 detections removed right there, 30 more vendors making excuses and arguments yet to go.
 
What an absolute fucking joke of an industry.

Всего записей: 33217 | Зарегистр. 31-07-2002 | Отправлено: 20:54 11-02-2021 | Исправлено: Victor_VG, 21:00 11-02-2021
   

На первую страницук этому сообщениюк последнему сообщению

Компьютерный форум Ru.Board » Компьютеры » Программы » FAR Manager (часть 6)
Maz (26-09-2022 12:52): FAR Manager (часть 7)


Реклама на форуме Ru.Board.

Powered by Ikonboard "v2.1.7b" © 2000 Ikonboard.com
Modified by Ru.B0ard
© Ru.B0ard 2000-2024

BitCoin: 1NGG1chHtUvrtEqjeerQCKDMUi6S6CG4iC

Рейтинг.ru