AVG says my programs are viruses (2012)
cplusplus.com
cplusplus.com
IMHO AVs started becoming anti-user when they began detecting "hacking tools" and keygens/cracks/patches (there are certainly some which do have malware, but detecting software that does exactly what it claims to do is going beyond that.) That's acting in the interests of corporations, not users. It's rather authoritarian and I don't want that at all.
It probably is unwanted software.
I know very well what that means. These freaking AV flag my stuff all the time...
I think the context here is that a lot of this software contains malware (even the ones that also do what they say on the tin), and its a lot harder to separate since the deliberate intent is "modify the workings of other programs". It becomes nearly impossible to algorithmically decide if it is modifying other programs"in the way the user wanted rather than any undesired way.
SPECIALLY AVG and Avast.
Last time I tried to use them, they immediately deleted without asking if I allowed it, 80% of my tools and binaries.
It is clear that anti-viruses on Windows are usually more dangerous than the viruses themselves. (in the end, the virus I wanted to track down, was in my router, not on Windows :/)
This is especially true regarding the bad track record of antivirus software w.r.t vulnerabilities, allowing an attacker to elevate its privileges.
On the other hand, Microsoft's interests are less misaligned with mine. They want to keep Windows secure as do I. Around the edges of tracking and telemetry, we may disagree. Anyway, my life became much simpler when I adopted Microsoft's solution for my Windows boxes.
Since when did they start offering it? and is it Windows Defender you are talking about? - thanks.
The school antivirus had a false-positive and decided it was some particular virus. God knows how.
I know, I know, I am going to get downvoted to hell ...
But seriously, I am aware of one major IDS/IPS flags WSUS Offline Update and blocked me from downloading the zip. So that means they throw signature up there without even inspecting it I bet... to block a tool that streamlines updates on Winboxen? Thanks for protecting me!
http://download.wsusoffline.net/
This tool is open source and merely organizes different patches with common GNU and FLOSS utilties through AutoIt or some other wrappers. Many of us, who work in systems management for airgapped or systems way behind where Windows 7 updates now fail because of their recent infra changes and might even finish scanning for days[0], need this to keep updated. I get it is not a blessed tool, but I am so unqiue in this regard? I think these vendors impose their own idea of systems management, which is really variable as everyone does it their own way. Addressing that requires complexity, which is why we are here in the first place.
I handle a lot of end-user computers, so let me be clear, such behavior is atrocious. But how many of you have known/used Software Restriction Policies or AppLocker on Windows? This burning the whole forest for the trees thing is not only common, it is critical to the gimmicky heuristics nature of old school anti-virus.
Then again, Windows ships PowerShell, in a vain attempt to not be VBScript again, with Bypass features to a neat concept of signed script code, and we have things like state of the art system manipulation with blessed Microsoft tools and .NET code generation on the fly with PowerSploit, which no AV/IDS/IPS will catch without being properly tuned, since that is close enough to admin behavior (really any PowerShell) to be much harder to stop.
https://github.com/PowerShellMafia/PowerSploit/commits/maste...
[0] http://wu.krelay.de/en/ for the uninitiated
https://grack.com/blog/2010/03/17/the-sorry-state-of-avira-a...
Because then users of a binary need to trust that the compiler-user had an AV installed.