adoxa / ansicon

Process ANSI escape sequences for Windows console programs.
http://ansicon.adoxa.vze.com/
Other
1.23k stars 130 forks source link

McAfee reports Trojan in ansi183.zip and ansi 182.zip (other not tested) #115

Open dhieronymus opened 6 years ago

lukewatts commented 6 years ago

Encountered this also

blackcrack commented 6 years ago

i guess this is the loading algoryghm why different AV report it as trojan, it should be uploaded to the whole AV Manufacturer as probefile and therewith can be unlistet this loader of the dll files i guess it is the exefile where load the dll "https://github.com/adoxa/ansicon/blob/master/injdll.c", isn't it ? Please mail the AV Manufacturer and give them this ansicon github adress for Comparison and Unlisting it in whitelist.

this supports ansicon

best regards Blacky

layanto commented 6 years ago

Windows 10 Defender Security also reports ansi183.zip as trojan: Trojan:Win32/Triggre!rfn

blackcrack commented 6 years ago

it's the fail on the Antivirus Manufacturer, if he accused the programmer to have a v-code inside.. if the wrong report of the user @layanto , so Jeffrey , maybe try he make there a mobbing...

so, mail the AV-Manufacturer and say them, this there is open source .. and this program must be whitelisting ..

or i can report Jeffrey to github for a Virus attack .. it's the same.. so, mail the AV Manufacturer and give them feedback, this here it is the wrong place ..

best Blacky

lukewatts commented 6 years ago

It's not up to those who want to install this to contact every single AV manufacturer. It's the maintainers role to do that. We're not a maintainer of this package so how do we know your not just lying to get us to whiteboard a Trojan. I'm tempted to flag this report as a virus to github and get it removed

blackcrack commented 6 years ago

well, if you want kill this nice software where was supportet by others.. do it, maybe be you own later in anytime infected with a bad user who want kill your soft.. or maybe tell an AV-Manufacturer, you be infected.. lol so, then should you delete you by itself maybe .. if you not trust this Programmer, don't use this software and let him his peace .. an announcing because it's a Virus-notification/alert , in all honor, but if you not trust, don't use it.. and don't nerve

best regards Blacky

lukewatts commented 6 years ago

I didn't install it. I instead came here to log the issue do a maintainer could look into the issue and fix it. If 2 AV software packages are flagging this then I don't trust it.

adoxa commented 6 years ago

I'll revisit it after 1.84, which I hope to release in the next week or so.

zezont4 commented 6 years ago

I am now using 1.82 and waiting for 1.84

Thank you for your good program

blackcrack commented 6 years ago

:+1: This Ansicon should install at any windows computers for have the possibility to priming coat with colours, like it was/is in Dos with ansi.sys and in Linux. (And the design in W10 is bullshit, my opinion..)

Ansicon small, efficient, helpful in WinNT :100:% :1st_place_medal:

best regards Blacky

enigma9o7 commented 6 years ago

180 and 181 also saying same trojan from win10 defender. I found this thread when I searched about this issue in google to figure out if it's safe enough to use. I've now wasted 30 minutes and still unclear, I'll find another solution. As far as I can tell, the author hasn't confirmed if there's a trojan or not but isn't even concerned enough to look into it until the next version. He may be himself infected and infecting downloaders for long time but doesn't seem to care, or worse yet purposely spreading this.

Just FYI, I woulda much preferred a response like "there's no trojan, false positive, just ignore it" or "Uh oh, I am infected, DONT DOWNLOAD until I release new version, I'm doing everything I can to stop downloads of all the infected versions (;maybe compile yourself?)"

blackcrack commented 6 years ago

[strike]Simon[/strike] Microsoft say's .. no ! Defender say's the user, this is a bad finger.. So cut it up !, you have 10 of it .. @enigma9o7 [strike]Simon[/strike] Microsoft say's .. it's a baaad Software, don't use Linux.. so, kick your computer out of the Window !, you can Buy a Microsoft Computer.. or maybe an apple.. [strike]Simon[/strike] Microsoft say's .. Go in Facebook and make selfi's and move up all you private movies .. you have a Camera from Microsoft.. you don't need it .. and Alexa tell you if you need to go in your Facebook.. and she giggle.. why, nope it's not a Programmer fail, she's know all of you ! hi..hiiii.hii.hihihihihihi.... Is this a Virus ? nope it's a programmer fail.. oh, Is Defender a Virus, nope, it's a programmer fail .. hihihihihihihi...

have a good day ..

enigma9o7 commented 6 years ago

Honestly, I have no idea what that means. It kinda sounds like someone wrote something in Chinese then used machine translation to Inupiaq Eskimo, then Klingon, then finally English and that spat out.

I dunno [/strike]. Maybe on some other forum in does something. Not everyone is a forum junkie. I agree I don't need a camera, although I don't think any of the cameras I own are made by Microsoft, I thought they did software? I am certainly familiar with Linux, Facebook, cameras (even selfies, although they don't belong to Selfi), private movies, etc - I even once made a private movie with my wife ;) But as it is private, by definition we certainly never uploaded it anywhere. But how is this relevant? You use words that have meaning, but no meaning is made from what you wrote when you put the words together.

But I like the good day bit! Love it! You have a good day too! And everyone! Everyone have a GREAT day! Please! ;)

edit: it's after 5 O'clock when I replied. And I just realized you posted all the other incomprehensible posts in this thread, which I basically ignored cuz they were also words put together that don't make sense. If you actually have a point and are actually super smart (which maybe you are, honestly) then I dunno what to say.... it would be rude to say you should study english or get an english fluent friend to help, so I won't say that. But if you're using machine translation and think people understand, let's take a poll. If anyone actually understands what he's been writing, say so. if anyone else is confused, say so. l'm curious. (and three sheets....)

adoxa commented 6 years ago

Well, if it helps... There's no trojan, false positive, just ignore it.

I didn't want to submit 1.83 for whitelisting when I thought 1.84 was imminent, but I got sidetracked. Real Soon Now!

lukewatts commented 6 years ago

Oh god, that last @blackcrack comment and @enigma9o7 reply made me laugh so hard! This whole thread was worth it just for that. His comment reminds me of those bad lip reading videos on YouTube

blackcrack commented 6 years ago

@lukewatts : *lol* hehehehe.. :+1: give me the url of the u'tube Video, i want see :grin: and ... @enigma9o7 : it's old school enigma BBS encrypted, if you have not understood, it's nothing for u ;) https://en.wikipedia.org/wiki/Enigma_machine

lukewatts commented 6 years ago

@blackcrack I guess we're getting off topic but...ah what the hell...here

https://youtu.be/d5i3F0YnkP0

blackcrack commented 6 years ago

thank you very much !

adoxa commented 6 years ago

Windows 10 1803 (10.0.17134.48 with Defender updated just now) didn't complain about 1.84.

OwnerOfThisIsle commented 6 years ago

OfficeScan just reported 1.85 as trojan, whereas it allowed to download and install 1.84.

eslym commented 5 years ago

anti virus reported the zip file contains. but does not complain about the extracted dll and exe, maybe pack it into rar or 7z

vargalas commented 5 years ago

Same issue here. McAffee.

kendonB commented 5 years ago

image

Trend Micro also doesn't like this and blocks (ansi189). On a corporate system so can't just ignore it.

adoxa commented 5 years ago

It looks like you need to sign in to Trend Micro support to report a false positive. If you're on 10 here's (source) an alternative program which enables terminal processing before running a program. If you do termon cmd every program started by CMD will have escapes (unless they explicitly turn terminal processing off).

mviens commented 4 years ago

I hate to resurrect such an old thread, but I just got a notification from Windows Defender for v1.89.

ansicon
blackcrack commented 4 years ago

@mviens so then go to MS and report it as false positive.. this is not the fail from the Programmer, but his baby is accused .. and you support it .. go to the guilty speaker.. and support Adoxa therewith..