Interactive PowerBasic Forum

IT-Consultant: Charles Pegge => OxygenBasic => Topic started by: Zlatko Vid on January 01, 2022, 10:54:54 AM

Title: OxIDE on VirusTotal
Post by: Zlatko Vid on January 01, 2022, 10:54:54 AM
this program is made by Charles
and again similar crap on VirusTotal

QuoteDetection ratio: 7/72
Security vendor    Result    Update
eGambit    confirmed-timeout    20220101
SymantecMobileInsight    failure    20211119
Cynet    malicious    20220101
APEX    malicious    20220101
Avira    malicious    20211231
VBA32    malicious    20211231
Cylance    malicious    20220101
Rising    malicious    20211231
BitDefenderTheta    malicious    20211223

i really don't know what to say
Title: Re: OxIDE on VirusTotal
Post by: Chris Chancellor on January 01, 2022, 10:19:39 PM
You need code signing certificate

https://www.ksoftware.net/code-signing-certificates/

Code Signing Certificates
A code signing certificate allows you to digitally
sign your files, securing them against tampering
while providing reputation with Microsoft's SmartScreen
filter and completely eliminating the Unknown Publisher
warnings that might be scaring off your customers.
Title: Re: OxIDE on VirusTotal
Post by: Chris Chancellor on January 01, 2022, 10:25:09 PM
all exe and dll must be code signed otherwise AV software will detect them as viruss
Title: Re: OxIDE on VirusTotal
Post by: Chris Chancellor on January 01, 2022, 10:27:36 PM
Theo can help with the code signing process?
Title: Re: OxIDE on VirusTotal
Post by: Zlatko Vid on January 02, 2022, 08:26:12 AM
I am not sure about that :

Quoteall exe and dll must be code signed otherwise AV software will detect them as viruss

i have some really old software ( free and open-source )  i don't know for all in what is
compiled but don't trigger VirusTotal av-s

in the past only Avira and Avira-based AV complain about malware
some programs created with FreeBasic are also under suspect  including FBC -free basic compiler.
for example CSED editor coded in PowerBasic is 0/71...????
Title: Re: OxIDE on VirusTotal
Post by: Zlatko Vid on January 02, 2022, 05:57:34 PM
I decompressed
both gxo2.exe and oxygen.dll
then i check on VirusTotal
i get 6/70 warnings ...still large amount of them
Title: Re: OxIDE on VirusTotal
Post by: Zlatko Vid on January 03, 2022, 08:19:25 PM
hi
I compiled myself version A043... both gxo2.exe
and
oxygen.dll

with FreeBasic 1.0.7
and get same alerts from VTotal
for gxo2 i get 2/70
which is fine BUT when compiled o2 program with this new compiler and dll
i get same bad results 9/64
just to note...i checked this fb 107 on VT which results in 0 alerts
so as conclusion and to stop bothering ,it is not problem in fb compiler
it is also not problem in includes no mather which one u use then in gxo2 or in rtl32/64 include file 
Title: Re: OxIDE on VirusTotal
Post by: Charles Pegge on January 05, 2022, 04:55:45 PM

You have to submit false-positive binaries to your antivirus provider. Avira is notorious.
Title: Re: OxIDE on VirusTotal
Post by: Zlatko Vid on January 05, 2022, 11:42:43 PM
Well it is not just Avira
it is well known McAfee,VBA32 and some others
Title: Re: OxIDE on VirusTotal
Post by: Nicola on January 07, 2022, 02:54:21 PM
Quote from: Charles Pegge on January 05, 2022, 04:55:45 PM

You have to submit false-positive binaries to your antivirus provider. Avira is notorious.

I did this with a program made with another compiler. Trend saw it as infected, but after the report I no longer had the problem.
Title: Re: OxIDE on VirusTotal
Post by: Zlatko Vid on January 07, 2022, 04:57:16 PM
nicola

QuoteI did this with a program made with another compiler

if you know how please send to

McAffe
VBA32
Malwarebytes

those 3 are critical
Title: Re: OxIDE on VirusTotal
Post by: Nicola on January 07, 2022, 11:43:47 PM
Aurel, I'm sending you a link that I found for mcAfee. Explain how to submit a false positive.
Surely all antiviruses have this type of service.
The link is in Italian ...
Hello.


https://service.mcafee.com/?locale=it-IT&articleId=TS102053&fromSearch=true&page=shell&shell=article-view
Title: Re: OxIDE on VirusTotal
Post by: Charles Pegge on January 08, 2022, 10:55:50 AM
Anti-Viruses all have different ways of reporting false positives, unfortunately.
Title: Re: OxIDE on VirusTotal
Post by: Zlatko Vid on January 08, 2022, 06:47:19 PM
Unfortunately that is true .
Unfortunately is not good for potential users and also for us
like me who is long time user of OxygenBasic

nicola...
your link you give me not work for me

Some AV delete some compiled exes
for example McAfee delete every o2 compiled program
how i know that ...i send source to my internet  friend EdDavis
on the contra side my Kaspersky
delete some compiled programs compiled with freeBasic

on the other side for example transpiler like qb64 is totaly clean according
to virustotal report  :o
and what to say more ?
Title: Re: OxIDE on VirusTotal
Post by: Zlatko Vid on January 08, 2022, 07:11:57 PM
nicola
i tried with another browser and found email
then i sand link on file compiled with oxygen basic
so we will see
Title: Re: OxIDE on VirusTotal
Post by: Eduardo Jorge on January 09, 2022, 07:12:36 PM
I use AVAST anti viruses, and it takes the executable to test on their servers, after some time it tells you if the file is clean or not, sometimes it seems to run in a virtual machine and then release the execution
Title: Re: OxIDE on VirusTotal
Post by: Zlatko Vid on January 10, 2022, 08:53:09 AM
still nothing from mcafee and i doubt that i will receive anything
because i don't use his comercial product ,i use Kapsersky which
work well with o2
Title: Re: OxIDE on VirusTotal
Post by: Nicola on January 12, 2022, 02:11:19 PM
Hi.
I use trend micro and it has no problem with o2.
Title: Re: OxIDE on VirusTotal
Post by: Zlatko Vid on January 12, 2022, 03:29:36 PM
just compile program and then test it on virusTotal
then you will see