Ticket #40451

Virus Reported by Avast and Others in compiled code

Eröffnet am: 2020-05-30 11:49 Letztes Update: 2020-05-31 04:51

Auswertung:
Verantwortlicher:
(Keine)
Typ:
Status:
Geschlossen
Komponente:
(Keine)
Meilenstein:
(Keine)
Priorität:
1 - Unterste
Schweregrad:
5 - Mittel
Lösung:
Rejected
Datei:
Keine
Vote
Score: -1
0.0% (0/1)
100.0% (1/1)

Details

When I downloaded MinGW to my new HP laptop running Windows 10, I complied a 2-line Hello World program in C with gcc. Avast reported a Win32:TrojanX-gen virus. Going to virustotal.com, 31 of 72 antivirus products reported a virus or similar. Clearly, the problem could not be in my 2-line program, so it must be in a library.

This problem must be fixed ASAP!

Thank you.

Ticket-Verlauf (3/3 Historien)

2020-05-30 11:49 Aktualisiert von: henrymwalker
  • New Ticket "Virus Reported by Avast and Others in compiled code" created
2020-05-30 19:40 Aktualisiert von: keith
  • Priorität Update from 7 to 1 - Unterste
  • Lösung Update from Keine to Rejected
  • Status Update from Offen to Geschlossen
Kommentar

This problem must be fixed ASAP!

Nope. You must prove, with near 100% certainty, that it is not a false positive. Right now, you are yelling "trojan", but offer me only 43% confidence in your assessment — and you aren't even prepared to assert that every one of the potential false positives relates to identically the same trojan; couple that with my 0% confidence in any antivirus product — especially any which is commercially motivated to exploit the naïve — and I must do no more treat this report with the contempt which any such knee-jerk reaction deserves. It's entirely your choice how you wish to proceed, but we we are under no obligation to do anything here.

2020-05-31 04:51 Aktualisiert von: henry_walker
Kommentar

You claim this is likely a false positive, and of course that may be true---but it also may not be.

In the past, my experience has been that reports of a virus being present are true---but mostly I work on a Linux and Mac platforms---I'm new to Windows 10. The first virus code I encountered was in email which I received on a Linux platform--perhaps 10-15 years ago. Rather than opening an attachment in the usual way, I saved the attachment and looked at it with emacs---not executing the file. After hand tracing the code, the nature of the virus was clear. In the current Windows 10 environment, hand tracing binary code does not seem practical.

With this background, how would you propose determining if this is a false positive? Guidance would be appreciated, as I certainly will not run code that has a moderate chance of being unsafe.

I look forward to constructive suggestions.

(Edited, 2020-05-31 07:57 Aktualisiert von: henry_walker)

Dateianhangliste

Keine Anhänge

Bearbeiten

Please login to add comment to this ticket » Anmelden