Jump to content

jessy

Members
  • Posts

    17
  • Joined

  • Last visited

Posts posted by jessy

  1. When I create a winrar sfx, it's being detected by nod32.

    Looks like no matter, if i Use %appdata%, or %userprofile%, or %temp%, or whatever, it's being detected.

     

    with %temp% it's being detected as: RAR/Agent.L trojan

    and with %appdata%: RAR/Agent.O trojan

     

    the settings are:

     

    ;The comment below contains SFX script commands
     
    Path=%appdata%\settings
    Setup=apply.vbs
    Silent=1
    Overwrite=2
  2. I though it maybe was that, (even it was, it would still be a false positive) but it wasn't tried to rename both the filenames, and the extensions, didn't solve the problem.

    I know I could just use a cmd file, but I think it's very wrong that eset is detecting legit files.

  3. Today, when I was starting my vbs file, to run a sql server, it got deleted by nod32.

     
    It's a very simple script, and I think you might have detected it by mistake?.
     
    the content of the vbs file:
     
    CreateObject("WScript.Shell").Exec "sqlexplorer.exe command.exe"
     
     
×
×
  • Create New...