Jump to content

Antivirus activity upon opening osbot


Recommended Posts

Posted (edited)

I'm curious what people think about this.  I opened osbot and my anti-virus quarantine and removed this: Behavior:Win32/Atosev.A!sms.

It appears to be a trojan. 

It was through the java.exe through program files.   

I have only official scripts

Thoughts?

False positive? Actual malicious malware?

Edited by Count me in
Posted
12 minutes ago, Count me in said:

I'm curious what people think about this.  I opened osbot and my anti-virus quarantine and removed this: Behavior:Win32/Atosev.A!sms.

It appears to be a trojan. 

It was through the java.exe through program files.   

I have only official scripts

Thoughts?

False positive? Actual malicious malware?

It's a false positive 

Some A/V software will look for code that injects into other programs, and since osbot is literally injecting a payload into the osrs client to bot, your A/V thinks it's doing something malicious 

Posted
1 minute ago, Protoprize said:

It's a false positive 

Some A/V software will look for code that injects into other programs, and since osbot is literally injecting a payload into the osrs client to bot, your A/V thinks it's doing something malicious 

Thanks for the fast response.  Why would it happen at random when I've opened scripts/clients hundreds of times? Why THAT time?

Posted
2 hours ago, Count me in said:

Thanks for the fast response.  Why would it happen at random when I've opened scripts/clients hundreds of times? Why THAT time?

Because osbot needs to download files for the scripts, and if the program already suspects the client itself to be malicious, it will react the same when it tries to download anything. 

Just add it to your exception list and you should be fine 

Posted
On 7/23/2020 at 7:55 AM, Count me in said:

I'm curious what people think about this.  I opened osbot and my anti-virus quarantine and removed this: Behavior:Win32/Atosev.A!sms.

It appears to be a trojan. 

It was through the java.exe through program files.   

I have only official scripts

Thoughts?

False positive? Actual malicious malware?

As others have stated, completely normal to get false positives. Especially if using just windows defender etc.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...