VTScan always shows "Trojan.Ransomware.Gen.b.0" for Tensent
2017-09-20, 09:37 PM,
#1
Guys, is this normal?

I made a bot this morning on Visual C#, and I really wanted to share it here, but when I made the VirusTotal scan 1 / 61.

AV: Tencent
Result: Trojan.Ransomware.Gen.b.0

I mean, wtf, a ransomware is for bounty hunting lol, is this normal or what?

I await an answer since I really want to share my bot to the forum.

Regards,
Amoneymus.
Reply
2017-09-20, 11:08 PM,
#2
i guess Quobi might be able to help you.
Latest Thanks - View all

Quobi(2017-09-20 11:56 PM) 

If You Think That Any Of The Staff Team Is Using Their Privileges In A Wrong Manner
You Can Always Contact The Admin → HawkEye
Reply
2017-09-20, 11:56 PM, (This post was last modified: 2017-09-20, 11:58 PM by Quobi.)
#3
You don't have to worry about it, just make sure people will understand the problem if you'll get asked.
Such results for innocent codes are called false-positive results, it is due massive open source bots/hack that are being used by multiple programmers under a different software name and small change of code/variables/properties to don't look like a copy/paste thing, even if it is... or because the antivirus itself is just a crappy no name program that has a stupid functionability. I mean, what the heck is that Tencent antivirus? I smell fake results so people could buy this shitty antivirus as it detects "more", "possible" viruses than the others. What a stupid joke.

If your .net app is not obfuscated an antivirus could easily decompile it and check its strings. You can try it yourself, I remember that I created a simple alert box app with the text blackshades RAT and it nearly got 10 false positive detections on VirusTotal. So I'd avoid using words as hack, bot, automation, and all that.

Unfortunately you cannot do anything about it. Only if you could register a company (I think it works as an individual person too, it depends) and talk to the team behind the antivirus to whitelist your software. Or use a crypter, thing which I don't support. An alternative is to write your own obfuscator or modify open source ones. Also, try modifying your code a little... remove some parts of the code and re-scan it to see where the problem belongs.

Sometimes, it's the icon's fault too. Change the form icons, the app icon and also make sure to change the assembly informations. That's all I suggest, and know. Unfortunately, we programmers can't do much about it. That's the way it is and we should accept it.
Latest Thanks - View all

Amoneymus(2017-09-21 05:26 AM)  LB'Decoy(2017-09-21 12:15 AM)  EnChanter(2017-09-20 11:58 PM) 

Reply
2017-09-21, 05:27 AM,
#4
Thanks Quobi, I really appreciate your answer.
Latest Thanks - View all

Quobi(2017-09-21 04:31 PM) 
Reply


Possibly Related Threads...
Thread Author Replies Views Last Post
  cpalead offers shows blank page mobo12 5 309 2017-03-07, 02:48 AM
Last Post: chalice
  Founded Trojan - Insomniac Share oldnewuser 2 557 2016-08-02, 04:46 AM
Last Post: ronjeremy
  Total VPN has Trojan-Ransom.JigSaw (w/ virus total scan) Vrasquedrach 10 1,296 2016-06-22, 09:29 PM
Last Post: charlez
  Looking for someone to Make Proof Videos for Online Gen's wackiin 0 229 2014-06-09, 09:10 AM
Last Post: wackiin
  App Exe Or Online Gen what converts best for you wackiin 3 398 2014-05-25, 10:42 AM
Last Post: davain





About Us | Contact Us | CPA Elites | Advertise | Stats | Staff Team

© 2013-2017 CPA Elites Ltd
Enhanced by MyBB and WallBB
Return to top