Page 1 of 1

AV false-positive issues: try this site

Posted: Sat Dec 28, 2019 6:58 am
by BarryG
Just submitted my exe to https://www.hybrid-analysis.com to see what's triggering false-positives for it, and the results are insane.

Here's just some of the reasons that it says my app is "malware":

Contains ability to register hotkeys (duh!).
Contains ability to open the clipboard (come on, the user has to have some convenience!).
Contains ability to query the machine version (have to make sure my app is not on Win XP or lower).
Creates a writable file in a temporary directory (what's wrong with writing to %TEMP%?).
Scanning for window names (I was checking for "Progman" and "Shell_TrayWnd"; so what?).
Queries volume information (of a hard disk; I need its free space before doing a file copy!).
Found potential URL in binary/memory (it saw my PayPal link when the user wants to buy).

And many more things. This has convinced me that no matter what I do, my app will classed as malware by VirusTotal and the like. Not much I can do except stop coding.

Anyway, throw your exes at this URL to see what it reports. It's pretty shocking.

Re: AV false-positive issues: try this site

Posted: Sat Dec 28, 2019 9:03 am
by Little John
BarryG wrote:Anyway, throw your exes at this URL to see what it reports.
Why should I do so? According to what you wrote, that seems just to be waste of time.

Re: AV false-positive issues: try this site

Posted: Sat Dec 28, 2019 9:12 am
by DarkDragon
I guess it just lists possible reasons for detecting a virus, as the heuristics usually base on a combination of these things. It is not the actual reason.

Re: AV false-positive issues: try this site

Posted: Sat Dec 28, 2019 9:47 am
by BarryG
Little John wrote:Why should I do so? According to what you wrote, that seems just to be waste of time.
If you're curious about why your exe gets flagged by false-positives, is obviously what I mean.

Re: AV false-positive issues: try this site

Posted: Sat Dec 28, 2019 11:46 am
by Mindphazer
The only and unique solution is : buy a Mac ! :mrgreen:

(if you're searching for me, i'm already out !!)

Re: AV false-positive issues: try this site

Posted: Sat Dec 28, 2019 12:23 pm
by Little John
BarryG wrote:
Little John wrote:Why should I do so? According to what you wrote, that seems just to be waste of time.
If you're curious about why your exe gets flagged by false-positives, is obviously what I mean.
That site obviously just tells complete nonsense.
And I don't see how this can help solving the problem about false virus alerts.

Re: AV false-positive issues: try this site

Posted: Sat Dec 28, 2019 12:59 pm
by BarryG
Little John wrote:I don't see how this can help solving the problem about false virus alerts.
It seemed to me that removing some of what it detects might reduce my false-positives... but then I realised half my code would be gone.