ansicon icon indicating copy to clipboard operation
ansicon copied to clipboard

McAfee reports Trojan in ansi183.zip and ansi 182.zip (other not tested)

Open dhieronymus opened this issue 7 years ago • 26 comments
trafficstars

dhieronymus avatar Mar 27 '18 11:03 dhieronymus

Encountered this also

lukewatts avatar Apr 09 '18 07:04 lukewatts

i guess this is the loading algoryghm why different AV report it as trojan, it should be uploaded to the whole AV Manufacturer as probefile and therewith can be unlistet this loader of the dll files i guess it is the exefile where load the dll "https://github.com/adoxa/ansicon/blob/master/injdll.c", isn't it ? Please mail the AV Manufacturer and give them this ansicon github adress for Comparison and Unlisting it in whitelist.

this supports ansicon

best regards Blacky

blackcrack avatar Apr 09 '18 10:04 blackcrack

Windows 10 Defender Security also reports ansi183.zip as trojan: Trojan:Win32/Triggre!rfn

layanto avatar Apr 14 '18 00:04 layanto

it's the fail on the Antivirus Manufacturer, if he accused the programmer to have a v-code inside.. if the wrong report of the user @layanto , so Jeffrey , maybe try he make there a mobbing...

so, mail the AV-Manufacturer and say them, this there is open source .. and this program must be whitelisting ..

or i can report Jeffrey to github for a Virus attack .. it's the same.. so, mail the AV Manufacturer and give them feedback, this here it is the wrong place ..

best Blacky

blackcrack avatar Apr 14 '18 06:04 blackcrack

It's not up to those who want to install this to contact every single AV manufacturer. It's the maintainers role to do that. We're not a maintainer of this package so how do we know your not just lying to get us to whiteboard a Trojan. I'm tempted to flag this report as a virus to github and get it removed

lukewatts avatar Apr 14 '18 13:04 lukewatts

well, if you want kill this nice software where was supportet by others.. do it, maybe be you own later in anytime infected with a bad user who want kill your soft.. or maybe tell an AV-Manufacturer, you be infected.. lol so, then should you delete you by itself maybe .. if you not trust this Programmer, don't use this software and let him his peace .. an announcing because it's a Virus-notification/alert , in all honor, but if you not trust, don't use it.. and don't nerve

best regards Blacky

blackcrack avatar Apr 14 '18 17:04 blackcrack

I didn't install it. I instead came here to log the issue do a maintainer could look into the issue and fix it. If 2 AV software packages are flagging this then I don't trust it.

lukewatts avatar Apr 15 '18 19:04 lukewatts

I'll revisit it after 1.84, which I hope to release in the next week or so.

adoxa avatar Apr 16 '18 02:04 adoxa

I am now using 1.82 and waiting for 1.84

Thank you for your good program

zezont4 avatar Apr 16 '18 02:04 zezont4

:+1: This Ansicon should install at any windows computers for have the possibility to priming coat with colours, like it was/is in Dos with ansi.sys and in Linux. (And the design in W10 is bullshit, my opinion..)

Ansicon small, efficient, helpful in WinNT :100:% :1st_place_medal:

best regards Blacky

blackcrack avatar Apr 16 '18 04:04 blackcrack

180 and 181 also saying same trojan from win10 defender. I found this thread when I searched about this issue in google to figure out if it's safe enough to use. I've now wasted 30 minutes and still unclear, I'll find another solution. As far as I can tell, the author hasn't confirmed if there's a trojan or not but isn't even concerned enough to look into it until the next version. He may be himself infected and infecting downloaders for long time but doesn't seem to care, or worse yet purposely spreading this.

Just FYI, I woulda much preferred a response like "there's no trojan, false positive, just ignore it" or "Uh oh, I am infected, DONT DOWNLOAD until I release new version, I'm doing everything I can to stop downloads of all the infected versions (;maybe compile yourself?)"

enigma9o7 avatar Apr 24 '18 23:04 enigma9o7

[strike]Simon[/strike] Microsoft say's .. no ! Defender say's the user, this is a bad finger.. So cut it up !, you have 10 of it .. @enigma9o7 [strike]Simon[/strike] Microsoft say's .. it's a baaad Software, don't use Linux.. so, kick your computer out of the Window !, you can Buy a Microsoft Computer.. or maybe an apple.. [strike]Simon[/strike] Microsoft say's .. Go in Facebook and make selfi's and move up all you private movies .. you have a Camera from Microsoft.. you don't need it .. and Alexa tell you if you need to go in your Facebook.. and she giggle.. why, nope it's not a Programmer fail, she's know all of you ! hi..hiiii.hii.hihihihihihi.... Is this a Virus ? nope it's a programmer fail.. oh, Is Defender a Virus, nope, it's a programmer fail .. hihihihihihihi...

have a good day ..

blackcrack avatar Apr 24 '18 23:04 blackcrack

Honestly, I have no idea what that means. It kinda sounds like someone wrote something in Chinese then used machine translation to Inupiaq Eskimo, then Klingon, then finally English and that spat out.

I dunno [/strike]. Maybe on some other forum in does something. Not everyone is a forum junkie. I agree I don't need a camera, although I don't think any of the cameras I own are made by Microsoft, I thought they did software? I am certainly familiar with Linux, Facebook, cameras (even selfies, although they don't belong to Selfi), private movies, etc - I even once made a private movie with my wife ;) But as it is private, by definition we certainly never uploaded it anywhere. But how is this relevant? You use words that have meaning, but no meaning is made from what you wrote when you put the words together.

But I like the good day bit! Love it! You have a good day too! And everyone! Everyone have a GREAT day! Please! ;)

edit: it's after 5 O'clock when I replied. And I just realized you posted all the other incomprehensible posts in this thread, which I basically ignored cuz they were also words put together that don't make sense. If you actually have a point and are actually super smart (which maybe you are, honestly) then I dunno what to say.... it would be rude to say you should study english or get an english fluent friend to help, so I won't say that. But if you're using machine translation and think people understand, let's take a poll. If anyone actually understands what he's been writing, say so. if anyone else is confused, say so. l'm curious. (and three sheets....)

enigma9o7 avatar Apr 24 '18 23:04 enigma9o7

Well, if it helps... There's no trojan, false positive, just ignore it.

I didn't want to submit 1.83 for whitelisting when I thought 1.84 was imminent, but I got sidetracked. Real Soon Now!

adoxa avatar Apr 25 '18 00:04 adoxa

Oh god, that last @blackcrack comment and @enigma9o7 reply made me laugh so hard! This whole thread was worth it just for that. His comment reminds me of those bad lip reading videos on YouTube

lukewatts avatar Apr 25 '18 08:04 lukewatts

@lukewatts : *lol* hehehehe.. :+1: give me the url of the u'tube Video, i want see :grin: and ... @enigma9o7 : it's old school enigma BBS encrypted, if you have not understood, it's nothing for u ;) https://en.wikipedia.org/wiki/Enigma_machine

blackcrack avatar Apr 25 '18 08:04 blackcrack

@blackcrack I guess we're getting off topic but...ah what the hell...here

https://youtu.be/d5i3F0YnkP0

lukewatts avatar Apr 25 '18 09:04 lukewatts

thank you very much !

blackcrack avatar Apr 25 '18 09:04 blackcrack

Windows 10 1803 (10.0.17134.48 with Defender updated just now) didn't complain about 1.84.

adoxa avatar May 11 '18 06:05 adoxa

OfficeScan just reported 1.85 as trojan, whereas it allowed to download and install 1.84.

OwnerOfThisIsle avatar Oct 17 '18 10:10 OwnerOfThisIsle

anti virus reported the zip file contains. but does not complain about the extracted dll and exe, maybe pack it into rar or 7z

eslym avatar Jan 11 '19 03:01 eslym

Same issue here. McAffee.

vargalas avatar Mar 27 '19 13:03 vargalas

image

Trend Micro also doesn't like this and blocks (ansi189). On a corporate system so can't just ignore it.

kendonB avatar Jun 13 '19 02:06 kendonB

It looks like you need to sign in to Trend Micro support to report a false positive. If you're on 10 here's (source) an alternative program which enables terminal processing before running a program. If you do termon cmd every program started by CMD will have escapes (unless they explicitly turn terminal processing off).

adoxa avatar Jun 13 '19 06:06 adoxa

I hate to resurrect such an old thread, but I just got a notification from Windows Defender for v1.89. ansicon

mviens avatar Apr 16 '20 21:04 mviens

@mviens so then go to MS and report it as false positive.. this is not the fail from the Programmer, but his baby is accused .. and you support it .. go to the guilty speaker.. and support Adoxa therewith..

blackcrack avatar Apr 17 '20 04:04 blackcrack