I’m getting Avast antivirus detecting my script as false positive virus threat.
my config used to be:
rotateUnicodeArray: true
,
compact: true,
controlFlowFlattening: false,
deadCodeInjection: false,
debugProtection: false,
debugProtectionInterval: false,
disableConsoleOutput: true,
rotateStringArray: true,
selfDefending: true,
stringArray: true,
stringArrayEncoding: 'base64',
stringArrayThreshold: 0.75,
unicodeEscapeSequence: false
I also tried “lowest” settings, but it still detected as false positive. Forgone the obfuscation altogether and it stopped complaining.
Issue Analytics
- State:
- Created 6 years ago
- Reactions:6
- Comments:40 (24 by maintainers)
Top Results From Across the Web
Avast | Download Free Antivirus & VPN | 100% Free & Easy
Free antivirus ; Avast will help keep you safe online from over one billion threats each month ; Over 400 million users worldwide...
Read more >Avast Antivirus & Security - Apps on Google Play
Protect against viruses & other types of malware with Avast Mobile Security, our free antivirus app for Android. Trusted by over 435 million...
Read more >Avast Software - Home - Facebook
Avast is part of Gen™—a global company dedicated to powering Digital Freedom through a family of trusted consumer brands. (NortonLifeLoc ...
Read more >Avast - Wikipedia
Avast Software s.r.o. is a Czech multinational cybersecurity software company headquartered in Prague, Czech Republic that researches and develops computer ...
Read more >Avast - YouTube
Avast One is the free, integrated all-in-one service that combines antivirus, VPN, performance, and security tools to help you stay as private and...
Read more >Top Related Medium Post
No results found
Top Related StackOverflow Question
No results found
Troubleshoot Live Code
Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start FreeTop Related Reddit Thread
No results found
Top Related Hackernoon Post
No results found
Top Related Tweet
No results found
Top Related Dev.to Post
No results found
Top Related Hashnode Post
No results found
Top GitHub Comments
Hi. After some tests i noticed that
Avast
triggered when string literals are moving to the string array from objects keys that hadcomputed
property withfalse
value.Obfuscator doing transformation of object keys:
into this form:
And then moving this string literal ‘bar’ to the string array. So, on your code after moving object keys to string array - avast will detect your code as the threat.
Solution - enable
stringArrayEncoding: 'base64'
With this option enabled - all antivirus checks are negative. Tested on0.10.2
version.Also i wrote letter to
Avast
about false positive alerts. Will waiting for response.