The MASM Forum Archive 2004 to 2012

Project Support Forums => MASM32 => AV Software sh*t list. => Topic started by: AceSnoopy on May 23, 2009, 05:33:33 PM

Title: McAfee and MASM32 v10
Post by: AceSnoopy on May 23, 2009, 05:33:33 PM
A heads-up, and question:

I've always found that using McAfee security software yields a good balance of safety and cost on my WinXP machine - and it's saved me from my own stupidity many a time :P

However, i came to reinstall MASM10 today for the first time after recieving the major McAfee update due to a hardware failure and subsequent total system mess-up - and its "Artemis" heuristic system seems to give positives on files:


At first i was unconcerned as i had experienced some issues with version 9. However, when i decided on a full system scan to complement my initial scan only of the masm32 directory in order to check if any other locations had been written to with files that may have been mistaken for malware, i was shocked to find that McAfee recorded a series of executable files in a totally unrelated and long archived backup directory as being "infected" with similar artemis variations.

These files (about 5 ancient versions of the Frostwire self extraction installation executable in case it matters to anyone - no im not sure why i still keep them around haha) were never recorded as threats before masm installation - and the system is reported as otherwise clean. It would be really helpful if anyone could confirm the masm files in question as known to cause false positives? And also if anyone could suggest why scanning of these unrelated but specifically grouped files may be affected?

Thanks in advance

(And also boooo to mcafee - would it be so hard to name your heuristic detections something that made it clear they were made by heuristic analysis! artemis indeed...)
Title: Re: McAfee and MASM32 v10
Post by: BlackVortex on May 23, 2009, 07:09:46 PM
Tone down or disable the heuristics.

Not sure what answer you expect. Also, McAfee sucks   :dance:
Title: Re: McAfee and MASM32 v10
Post by: dedndave on May 23, 2009, 07:18:40 PM
yah - norton and mcafee both pains
there are free ones out there that are better
the one i use is free - none at all
but - i assure you, those are false positives
you should be able to enter them into an "ignore list" of some kind

it is probably getting those positives from the pe headers - a common av mistake with assembler exe's
Title: Re: McAfee and MASM32 v10
Post by: AceSnoopy on May 23, 2009, 07:37:09 PM
Oh well, after clicking on two "Advanced..." buttons and going into like the third level of configuration menu i just about get the option to turn off heuristics altogether - no tolerance settings :(

Dumbed down? nooooo not at all... Then why do i need to open an advanced pane to even view the logs?  :lol

I can de-quarantine the files as it finds them and it looks like that's about as good as its gonna get - looks like i'll be looking through the freeware A/Vs before renewal time comes around! Still concerned about false positives on other files due to the presence of masm though - il check it out further but it takes a couple of hours to run a full scan. How exciting...
Title: Re: McAfee and MASM32 v10
Post by: Mark Jones on May 24, 2009, 04:24:48 PM
It is unfortunate that AV products sometimes make false positives, but this behavior has been increasing non-llinearly for some time now. It can be guaranteed, that the official MASM32 releases are clean, and these errors lie in the fault of the particular AV scanner used.

Many here have struggled with free AV's marking their executables as bad when in fact the AV scanners are not parsing the PE file specification correctly (or otherwise assuming things about the executable.) The only thing that can be done is a notice sent to the AV companies that some aspect of their scanning engine is making a mistake. They usually update their definitions, but eventually some new "variant" appears or a blanket heuristic pattern released, and the process repeats.
Title: Re: McAfee and MASM32 v10
Post by: dedndave on May 24, 2009, 04:37:00 PM
i think it is simpler than that, Mark
the AV programmers are lazy
they see the PE and ID it as assembly language code and dump on it
Title: Re: McAfee and MASM32 v10
Post by: Vortex on May 24, 2009, 06:19:01 PM
Hi AceSnoopy,

Add this link below to your favorites, it can be useful :

http://virusscan.jotti.org/en
Title: Re: McAfee and MASM32 v10
Post by: Kruesty on November 16, 2009, 11:16:02 AM
Quote from: Vortex on May 24, 2009, 06:19:01 PM
Add this link below to your favorites, it can be useful :

http://virusscan.jotti.org/en

Hey that a good site! Thanks for this!
Title: Re: McAfee and MASM32 v10
Post by: hutch-- on November 16, 2009, 12:46:17 PM
Hi Steve,

Welcome on board. Good to hear from the folks at codingcrew again.  :U
Title: Re: McAfee and MASM32 v10
Post by: zs8861 on November 20, 2010, 05:16:18 AM
I think if I install the masm32,I will close the antiAirus product in my computer. :bg