www.BinaryAlchemy.de :: View topic - AVAST doesnt like RR anymore
 SearchSearch   RegisterRegister  ProfileProfile   UsergroupsUsergroups   Log inLog in 
If you create a new post, please use a topic that describes your problem
Documento sin título
 
AVAST doesnt like RR anymore

 
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.    www.BinaryAlchemy.de Forum Index -> old - RR Questions - v6.x
View previous topic :: View next topic  
Author Message

pbillet



Joined: 24 May 2012
Posts: 155
Location/Company/Country: Paris/CGEV Studio/France

PostPosted: Fri Jun 27, 2014 12:21 pm    Post subject: AVAST doesnt like RR anymore Reply with quote

Just to let you know, the latest avast! ( antvirus ) virus definition database update from yesterday (26 june) marks rrCheckexitcode.exe as "Win32:Evo-gen [Susp]" virus.
This is obviously a false positive but requires to put the file in the exception list, becuse avast will prevent access to the executable and make rr think all the jobs are constantly crashing.

I've already submitted avast with a sample of the file and asked them to remove it from their definitions, they usually do it very fast (within 24/48h).

For the story , last year they marked some Nuke system nodes (built in plugins) as viruses which prevented to use some tools in nuke ( 2 times..)

Smile
Back to top
View user's profile Send private message

schoenberger
Site Admin


Joined: 02 Mar 2005
Posts: 3785

PostPosted: Fri Jun 27, 2014 1:27 pm    Post subject: Reply with quote

Thanks for the informatioin.
But there is nothing in the executable that I could change. And it seems that EVO-Gen is not searching for special code:
"The Behavior Monitoring feature observes the behavior of processes as they run programs. If it observes a process behaving in a potentially malicious way, it reports the program the process is running as potentially malicious."
_________________
Holger Schönberger
Binary Alchemy - digital materialization
Back to top
View user's profile Send private message Send e-mail

pbillet



Joined: 24 May 2012
Posts: 155
Location/Company/Country: Paris/CGEV Studio/France

PostPosted: Fri Jun 27, 2014 7:56 pm    Post subject: Reply with quote

Yep I believe there is only 2 possibilities:
-the software is digitally signed as trusted
-the guys from avast create some exception because the customers report a flase positive
Back to top
View user's profile Send private message

pbillet



Joined: 24 May 2012
Posts: 155
Location/Company/Country: Paris/CGEV Studio/France

PostPosted: Mon Jun 30, 2014 9:07 am    Post subject: Reply with quote

update:
they seem to have whitelisted rrCheckexitcode in 140629-2 virus database

But i just noticed rrKillWait.exe is also marked as virus, so I reported it as a false positive too.

let's hope it will be whitelisted asap

rgds
Back to top
View user's profile Send private message

pbillet



Joined: 24 May 2012
Posts: 155
Location/Company/Country: Paris/CGEV Studio/France

PostPosted: Tue Jul 01, 2014 9:01 am    Post subject: Reply with quote

OK due to my request rrkillwait is now whitelisted in database 140630-1, i've had confirmation by avast analyst

rgds
Back to top
View user's profile Send private message
Display posts from previous:   
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.    www.BinaryAlchemy.de Forum Index -> old - RR Questions - v6.x All times are GMT + 1 Hour
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
 
Documento sin título
 



Powered by phpBB © 2001, 2002 phpBB Group



Number of shameful bots caught by Anti-Spam ACP: 1667