Jump to content
UBot Underground

Recommended Posts

I know this probably has been done to death, so apologies if you're bored with the topic.

 

My point is that I think it's past time the persistent warnings about viruses and trojans in compiled bots received some serious attention by the Ubot team and the problem fixed once and for all.

 

We've probably all read the thread here

http://network.ubotstudio.com/blog/why-your-bot-is-showing-up-as-a-virus-and-what-to-do-about-it/

 

While that might work for some people, there are plenty more who just get scared when a virus alert pops up.

We have paid a decent amount of money for Ubot software, on promises of being able to sell bots, but the reality is that some kinds of users will (and do) just run away when they see scary warnings. Don't blame the customer - it's our problem, not theirs.

 

And it's no good blaming the AV industry either - rightly or wrongly, they are trusted, so we need a better solution. After the latest Windows update my PC started quarantining my own bots -something it's never done before, so I'm thinking this is not going to get any better.

 

I'm sure this can be sorted because there are commercial products that employ Ubot that don't trigger AV alerts. So how do they do it?

If anyone knows a foolproof way of compiling that doesn't trigger AV alerts maybe they could explain how, and this could be made into a sticky post so we can find it easily. Or even better, Ubot sorts the problem out at source.

Link to post
Share on other sites

Simple fast solution: explain to customers and users that there's no virus in your bots, they trust you if you have a good reputation.

 

Another solution is to digitally sign your bots which is not cheap, and you need to know, to cover Windows Smart Screen warning you have to purchase EV code signing, even more expensive.
 
Does it take care of false positives? they claim it does, I haven't tried yet. but that's the thing I must do, after reading and talking to a few cert providers support staff.
 
Macster in a thread explained Smart packer Pro in addition to the cert (he's absolutely trying to help), contacting to the support staff of smart packer, they said: Signing packed executable will probably prevent most of such warnings. so using the trial version I gave it a shot and packed one of my bots. the result...
 
I use Virustotal to see how AVs treat the bots. before packing I got around 3 alerts by VT (just alerts like "unknown"), after packing, it became double and became Backdoor and Trojan...!!!
 
So this tool does not work for me.
 
Wrapping it up, signing bots would definitely help. have plans to do it in the future and make sure to contact the provider to get a better help prior to spend money!

  • Like 2
Link to post
Share on other sites

i have what may be a simple question, but it maybe a simple answer.

can the file that win-def reads for white listed files be written to directly?

Link to post
Share on other sites

@Marani - thanks for taking time to answer. "Simple fast solution: explain to customers and users that there's no virus in your bots, they trust you if you have a good reputation." It's no solution because for them to trust you they need to know you. If they don't know you why should they trust you?

 

No response from Seth here: presumably because he knows there is an issue but sees no mileage in addressing it beyond what he's said already. Which as I, and others, have pointed out, is inadequate.

 

Maybe getting the software signed is the answer: is there a step-by-step guide anywhere?

Link to post
Share on other sites
  • 2 weeks later...

You can not use certain plugins that have licensing. They are encrypted and so is ubot to a point.

 

Send your bots to AV's to run through, should help.

 

Regards,

 

CD

 

Well I have ran a test with all 3rd party plugins disabled and compiled an empty bot with no code in it. Still Virus total came back alerting me that it contains a virus. So yeah, it's not just the plugins that triggers the warnings.

Link to post
Share on other sites
  • 2 years later...
On 4/21/2018 at 5:16 PM, Marani said:

Simple fast solution: explain to customers and users that there's no virus in your bots, they trust you if you have a good reputation.

 

Another solution is to digitally sign your bots which is not cheap, and you need to know, to cover Windows Smart Screen warning you have to purchase EV code signing, even more expensive.
 
Does it take care of false positives? they claim it does, I haven't tried yet. but that's the thing I must do, after reading and talking to a few cert providers support staff.
 
Macster in a thread explained Smart packer Pro in addition to the cert (he's absolutely trying to help), contacting to the support staff of smart packer, they said: Signing packed executable will probably prevent most of such warnings. so using the trial version I gave it a shot and packed one of my bots. the result...
 
I use Virustotal to see how AVs treat the bots. before packing I got around 3 alerts by VT (just alerts like "unknown"), after packing, it became double and became Backdoor and Trojan...!!!
 
So this tool does not work for me.
 
Wrapping it up, signing bots would definitely help. have plans to do it in the future and make sure to contact the provider to get a better help prior to spend money!

I have tried digitally signing ubot compiled bots... but after signing the .exe doesnt open . 

Link to post
Share on other sites
  • 5 months later...
  • 4 weeks later...

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
×
×
  • Create New...