<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<title type="html"><![CDATA[Серый форум &mdash; SAMP: ESET Nod32 принимает код за вредоносный]]></title>
	<link rel="self" href="http://forum.script-coding.com/extern.php?action=feed&amp;tid=12498&amp;type=atom" />
	<updated>2017-02-25T11:51:21Z</updated>
	<generator>PunBB</generator>
	<id>http://forum.script-coding.com/viewtopic.php?id=12498</id>
		<entry>
			<title type="html"><![CDATA[Re: SAMP: ESET Nod32 принимает код за вредоносный]]></title>
			<link rel="alternate" href="http://forum.script-coding.com/viewtopic.php?pid=113246#p113246" />
			<content type="html"><![CDATA[<p><span style="color: green">Тема перенесена по принадлежности. Заголовок отредактирован.</span></p>]]></content>
			<author>
				<name><![CDATA[Flasher]]></name>
				<uri>http://forum.script-coding.com/profile.php?id=27593</uri>
			</author>
			<updated>2017-02-25T11:51:21Z</updated>
			<id>http://forum.script-coding.com/viewtopic.php?pid=113246#p113246</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: SAMP: ESET Nod32 принимает код за вредоносный]]></title>
			<link rel="alternate" href="http://forum.script-coding.com/viewtopic.php?pid=113244#p113244" />
			<content type="html"><![CDATA[<div class="quotebox"><blockquote><p>Для проверки использовал сайт virustotal</p></blockquote></div><p> Надо полагать, на сайт был загружен скомпилированный скрипт.</p>]]></content>
			<author>
				<name><![CDATA[ypppu]]></name>
				<uri>http://forum.script-coding.com/profile.php?id=5974</uri>
			</author>
			<updated>2017-02-25T11:44:55Z</updated>
			<id>http://forum.script-coding.com/viewtopic.php?pid=113244#p113244</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: SAMP: ESET Nod32 принимает код за вредоносный]]></title>
			<link rel="alternate" href="http://forum.script-coding.com/viewtopic.php?pid=113242#p113242" />
			<content type="html"><![CDATA[<p><strong>YMP</strong>, <strong>teadrinker</strong> антивирус при сканировании &quot;запускает&quot; исп.файл в своей вирт.машине.<br />Окружающие файлы в вирт.машину скорее всего не попадают (если мы говорим про одноименный с интерпретатором файл в той же директории).<br />Очевидно, что интерпретатор ahk при запуске всего лишь открывает справку.<br />К тому же, его сигнатуры(хеш) уже есть в БД а-ля VirusTotal.</p>]]></content>
			<author>
				<name><![CDATA[stealzy]]></name>
				<uri>http://forum.script-coding.com/profile.php?id=31937</uri>
			</author>
			<updated>2017-02-25T10:12:19Z</updated>
			<id>http://forum.script-coding.com/viewtopic.php?pid=113242#p113242</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: SAMP: ESET Nod32 принимает код за вредоносный]]></title>
			<link rel="alternate" href="http://forum.script-coding.com/viewtopic.php?pid=113241#p113241" />
			<content type="html"><![CDATA[<p>У меня drWeb аналогично на подобный код срабатывает только в скомпилированном скрипте.</p>]]></content>
			<author>
				<name><![CDATA[teadrinker]]></name>
				<uri>http://forum.script-coding.com/profile.php?id=24515</uri>
			</author>
			<updated>2017-02-25T10:00:45Z</updated>
			<id>http://forum.script-coding.com/viewtopic.php?pid=113241#p113241</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: SAMP: ESET Nod32 принимает код за вредоносный]]></title>
			<link rel="alternate" href="http://forum.script-coding.com/viewtopic.php?pid=113240#p113240" />
			<content type="html"><![CDATA[<p>Интересно, при чём тут скомпилированность скрипта. Код ведь всё равно в виде текста.</p>]]></content>
			<author>
				<name><![CDATA[YMP]]></name>
				<uri>http://forum.script-coding.com/profile.php?id=81</uri>
			</author>
			<updated>2017-02-25T09:46:06Z</updated>
			<id>http://forum.script-coding.com/viewtopic.php?pid=113240#p113240</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: SAMP: ESET Nod32 принимает код за вредоносный]]></title>
			<link rel="alternate" href="http://forum.script-coding.com/viewtopic.php?pid=113239#p113239" />
			<content type="html"><![CDATA[<p>Код, по всей видимости, используется для внедрения dll в чужой процесс, так что реакция антивируса не удивительна.</p>]]></content>
			<author>
				<name><![CDATA[teadrinker]]></name>
				<uri>http://forum.script-coding.com/profile.php?id=24515</uri>
			</author>
			<updated>2017-02-25T09:38:57Z</updated>
			<id>http://forum.script-coding.com/viewtopic.php?pid=113239#p113239</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: SAMP: ESET Nod32 принимает код за вредоносный]]></title>
			<link rel="alternate" href="http://forum.script-coding.com/viewtopic.php?pid=113238#p113238" />
			<content type="html"><![CDATA[<p>Ну, тогда вы ошиблись веткой форума — вам в Games.<br />И вообще, проблемы антивирусов - это проблемы антивирусов,<br />почему вы на нашем форуме пишете, а не eset-овском, не понимаю.</p>]]></content>
			<author>
				<name><![CDATA[stealzy]]></name>
				<uri>http://forum.script-coding.com/profile.php?id=31937</uri>
			</author>
			<updated>2017-02-25T09:29:23Z</updated>
			<id>http://forum.script-coding.com/viewtopic.php?pid=113238#p113238</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: SAMP: ESET Nod32 принимает код за вредоносный]]></title>
			<link rel="alternate" href="http://forum.script-coding.com/viewtopic.php?pid=113237#p113237" />
			<content type="html"><![CDATA[<p><strong>stealzy</strong>, данный код - часть SAMP.ahk, используется в качестве инклуда для gta sa-mp</p>]]></content>
			<author>
				<name><![CDATA[sanny0112]]></name>
				<uri>http://forum.script-coding.com/profile.php?id=34083</uri>
			</author>
			<updated>2017-02-25T09:27:07Z</updated>
			<id>http://forum.script-coding.com/viewtopic.php?pid=113237#p113237</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: SAMP: ESET Nod32 принимает код за вредоносный]]></title>
			<link rel="alternate" href="http://forum.script-coding.com/viewtopic.php?pid=113236#p113236" />
			<content type="html"><![CDATA[<p>Любопытный код, неясно для каких целей вы его используете?<br />Возможно это можно сделать другим путем.<br />По теме вопроса - удалить антивирус, конечно. Уже лет пять без антивируса сам и года три человек, которому один раз настроил и забыл — ни разу ничего не ловили.</p>]]></content>
			<author>
				<name><![CDATA[stealzy]]></name>
				<uri>http://forum.script-coding.com/profile.php?id=31937</uri>
			</author>
			<updated>2017-02-25T09:23:56Z</updated>
			<id>http://forum.script-coding.com/viewtopic.php?pid=113236#p113236</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[SAMP: ESET Nod32 принимает код за вредоносный]]></title>
			<link rel="alternate" href="http://forum.script-coding.com/viewtopic.php?pid=113235#p113235" />
			<content type="html"><![CDATA[<p>По мнению антивируса ESET Nod32 следующий участок кода содержит угрозу &quot;Win32/AHK.BX&quot;.<br /></p><div class="codebox"><pre><code>waitForSingleObject(hThread, dwMilliseconds) {
    if(!hThread) {
        ErrorLevel := ERROR_INVALID_HANDLE
        return 0
    }
    
    dwRet := DllCall(    &quot;WaitForSingleObject&quot;
                        , &quot;UInt&quot;, hThread
                        , &quot;UInt&quot;, dwMilliseconds
                        , &quot;UInt&quot;)
    if(dwRet == 0xFFFFFFFF) {
        ErrorLEvel := ERROR_WAIT_FOR_OBJECT
        return 0
    }
    
    ErrorLevel := ERROR_OK
    return dwRet
}

readMem(hProcess, dwAddress, dwLen=4, type=&quot;UInt&quot;) {
    if(!hProcess) {
        ErrorLevel := ERROR_INVALID_HANDLE
        return 0
    }
    
    VarSetCapacity(dwRead, dwLen)
    dwRet := DllCall(    &quot;ReadProcessMemory&quot;
                        , &quot;UInt&quot;,  hProcess
                        , &quot;UInt&quot;,  dwAddress
                        , &quot;Str&quot;,   dwRead
                        , &quot;UInt&quot;,  dwLen
                        , &quot;UInt*&quot;, 0)
    if(dwRet == 0) {
        ErrorLevel := ERROR_READ_MEMORY
        return 0
    }
    
    ErrorLevel := ERROR_OK
    return NumGet(dwRead, 0, type)
}

callWithParams(hProcess, dwFunc, aParams, bCleanupStack = true) {
    if(!hProcess) {
        ErrorLevel := ERROR_INVALID_HANDLE
        return false
    }
    validParams := 0
    
    i := aParams.MaxIndex()
    
    ;         i * PUSH + CALL + RETN
    dwLen := i * 5    + 5    + 1
    if(bCleanupStack)
        dwLen += 3
    VarSetCapacity(injectData, i * 5    + 5       + 3       + 1, 0)
    
    i_ := 1
    while(i &gt; 0) {
        if(aParams[i][1] != &quot;&quot;) {
            dwMemAddress := 0x0
            if(aParams[i][1] == &quot;p&quot;) {
                dwMemAddress := aParams[i][2]
            } else if(aParams[i][1] == &quot;s&quot;) {
                if(i_&gt;3)
                    return false
                dwMemAddress := pParam%i_%
                writeString(hProcess, dwMemAddress, aParams[i][2])
                if(ErrorLevel)
                    return false
                i_ += 1
            } else if(aParams[i][1] == &quot;i&quot;) {
                dwMemAddress := aParams[i][2]
            } else {
                return false
            }
            NumPut(0x68, injectData, validParams * 5, &quot;UChar&quot;)
            NumPut(dwMemAddress, injectData, validParams * 5 + 1, &quot;UInt&quot;)
            validParams += 1
        }
        i -= 1
    }
    
    offset := dwFunc - ( pInjectFunc + validParams * 5 + 5 )
    NumPut(0xE8, injectData, validParams * 5, &quot;UChar&quot;)
    NumPut(offset, injectData, validParams * 5 + 1, &quot;Int&quot;)
    
    if(bCleanupStack) {
        NumPut(0xC483, injectData, validParams * 5 + 5, &quot;UShort&quot;)
        NumPut(validParams*4, injectData, validParams * 5 + 7, &quot;UChar&quot;)
        
        NumPut(0xC3, injectData, validParams * 5 + 8, &quot;UChar&quot;)
    } else {
        NumPut(0xC3, injectData, validParams * 5 + 5, &quot;UChar&quot;)
    }
    
    writeRaw(hGTA, pInjectFunc, &amp;injectData, dwLen)
    if(ErrorLevel)
        return false
    
    hThread := createRemoteThread(hGTA, 0, 0, pInjectFunc, 0, 0, 0)
    if(ErrorLevel)
        return false
    
    waitForSingleObject(hThread, 0xFFFFFFFF)
    
    closeProcess(hThread)
    
    return true
}

virtualAllocEx(hProcess, dwSize, flAllocationType, flProtect) {
    if(!hProcess) {
        ErrorLevel := ERROR_INVALID_HANDLE
        return 0
    }
    
    dwRet := DllCall(    &quot;VirtualAllocEx&quot;
                        , &quot;UInt&quot;, hProcess
                        , &quot;UInt&quot;, 0
                        , &quot;UInt&quot;, dwSize
                        , &quot;UInt&quot;, flAllocationType
                        , &quot;UInt&quot;, flProtect
                        , &quot;UInt&quot;)
    if(dwRet == 0) {
        ErrorLEvel := ERROR_ALLOC_MEMORY
        return 0
    }
    
    ErrorLevel := ERROR_OK
    return dwRet
}

createRemoteThread(hProcess, lpThreadAttributes, dwStackSize, lpStartAddress, lpParameter, dwCreationFlags, lpThreadId) {
    if(!hProcess) {
        ErrorLevel := ERROR_INVALID_HANDLE
        return 0
    }
    
    dwRet := DllCall(    &quot;CreateRemoteThread&quot;
                        , &quot;UInt&quot;, hProcess
                        , &quot;UInt&quot;, lpThreadAttributes
                        , &quot;UInt&quot;, dwStackSize
                        , &quot;UInt&quot;, lpStartAddress
                        , &quot;UInt&quot;, lpParameter
                        , &quot;UInt&quot;, dwCreationFlags
                        , &quot;UInt&quot;, lpThreadId
                        , &quot;UInt&quot;)
    if(dwRet == 0) {
        ErrorLEvel := ERROR_ALLOC_MEMORY
        return 0
    }
    
    ErrorLevel := ERROR_OK
    return dwRet
}</code></pre></div><p>Все это приводит к удалению всех скриптов, содержащих данный участок кода. Как не прибегая к удалению/выведению из работоспособности данного кода устранить проблему?<br />P.S. Для проверки использовал сайт virustotal</p>]]></content>
			<author>
				<name><![CDATA[sanny0112]]></name>
				<uri>http://forum.script-coding.com/profile.php?id=34083</uri>
			</author>
			<updated>2017-02-25T09:14:05Z</updated>
			<id>http://forum.script-coding.com/viewtopic.php?pid=113235#p113235</id>
		</entry>
</feed>
