<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic debug executables flagged as malware? in LabWindows/CVI</title>
    <link>https://ni.lithium.com/t5/LabWindows-CVI/debug-executables-flagged-as-malware/m-p/3971063#M81908</link>
    <description>&lt;P&gt;My company uses Symantec anti virus and this morning I was greeted with a bunch of my debug EXEs being flagged.&amp;nbsp; Is there anything I should know about here?&amp;nbsp; I doubt these are actually suspect files; most are from the example projects.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2019-09-19 08_58_13-Symantec Endpoint Protection Detection Results.png" style="width: 999px;"&gt;&lt;img src="https://ip1.i.lithium.com/ba0400f6857ffa498817b9fa7931ce3456c5131f/68747470733a2f2f6e692e6c69746869756d2e636f6d2f74352f696d6167652f736572766572706167652f696d6167652d69642f32353333333869304133433030463939313038444330462f696d6167652d73697a652f6c617267653f763d76322670783d393939" role="button" title="2019-09-19 08_58_13-Symantec Endpoint Protection Detection Results.png" alt="2019-09-19 08_58_13-Symantec Endpoint Protection Detection Results.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 19 Sep 2019 18:42:39 GMT</pubDate>
    <dc:creator>ElectroLund</dc:creator>
    <dc:date>2019-09-19T18:42:39Z</dc:date>
    <item>
      <title>debug executables flagged as malware?</title>
      <link>https://ni.lithium.com/t5/LabWindows-CVI/debug-executables-flagged-as-malware/m-p/3971063#M81908</link>
      <description>&lt;P&gt;My company uses Symantec anti virus and this morning I was greeted with a bunch of my debug EXEs being flagged.&amp;nbsp; Is there anything I should know about here?&amp;nbsp; I doubt these are actually suspect files; most are from the example projects.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2019-09-19 08_58_13-Symantec Endpoint Protection Detection Results.png" style="width: 999px;"&gt;&lt;img src="https://ip1.i.lithium.com/ba0400f6857ffa498817b9fa7931ce3456c5131f/68747470733a2f2f6e692e6c69746869756d2e636f6d2f74352f696d6167652f736572766572706167652f696d6167652d69642f32353333333869304133433030463939313038444330462f696d6167652d73697a652f6c617267653f763d76322670783d393939" role="button" title="2019-09-19 08_58_13-Symantec Endpoint Protection Detection Results.png" alt="2019-09-19 08_58_13-Symantec Endpoint Protection Detection Results.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2019 18:42:39 GMT</pubDate>
      <guid>https://ni.lithium.com/t5/LabWindows-CVI/debug-executables-flagged-as-malware/m-p/3971063#M81908</guid>
      <dc:creator>ElectroLund</dc:creator>
      <dc:date>2019-09-19T18:42:39Z</dc:date>
    </item>
    <item>
      <title>Re: debug executables flagged as malware?</title>
      <link>https://ni.lithium.com/t5/LabWindows-CVI/debug-executables-flagged-as-malware/m-p/3971087#M81909</link>
      <description>&lt;P&gt;I use virustotal.com to check files and URLs with dozens of AV engines in one shot.&amp;nbsp; Though it does not get those positives removed from your Symantec filter, it could help convince them that their engine is creating false positives.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2019 19:41:49 GMT</pubDate>
      <guid>https://ni.lithium.com/t5/LabWindows-CVI/debug-executables-flagged-as-malware/m-p/3971087#M81909</guid>
      <dc:creator>Ian.W</dc:creator>
      <dc:date>2019-09-19T19:41:49Z</dc:date>
    </item>
    <item>
      <title>Re: debug executables flagged as malware?</title>
      <link>https://ni.lithium.com/t5/LabWindows-CVI/debug-executables-flagged-as-malware/m-p/3984519#M82066</link>
      <description>&lt;P&gt;Hi, did you get any feedback from NI on this one?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2019 11:47:26 GMT</pubDate>
      <guid>https://ni.lithium.com/t5/LabWindows-CVI/debug-executables-flagged-as-malware/m-p/3984519#M82066</guid>
      <dc:creator>kjellor</dc:creator>
      <dc:date>2019-11-05T11:47:26Z</dc:date>
    </item>
    <item>
      <title>Re: debug executables flagged as malware?</title>
      <link>https://ni.lithium.com/t5/LabWindows-CVI/debug-executables-flagged-as-malware/m-p/3984580#M82067</link>
      <description>&lt;P&gt;No, I'm waiting on reply from my corporate IT.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2019 13:48:42 GMT</pubDate>
      <guid>https://ni.lithium.com/t5/LabWindows-CVI/debug-executables-flagged-as-malware/m-p/3984580#M82067</guid>
      <dc:creator>ElectroLund</dc:creator>
      <dc:date>2019-11-05T13:48:42Z</dc:date>
    </item>
    <item>
      <title>Re: debug executables flagged as malware?</title>
      <link>https://ni.lithium.com/t5/LabWindows-CVI/debug-executables-flagged-as-malware/m-p/3985387#M82077</link>
      <description>&lt;P&gt;The same issue sometimes happens with TrendMicro WorryFree Business Security used in my company.&lt;/P&gt;
&lt;P&gt;The false positive are usually fixed in a couple of days by TrendMicro, but I must reinstall the software previously deleted &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://ni.lithium.com/i/smilies/16x16_smiley-sad.gif" alt="Smiley Sad" title="Smiley Sad" /&gt;&lt;/P&gt;
&lt;P&gt;This happens both with CVI and LabVIEW applications.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2019 12:36:00 GMT</pubDate>
      <guid>https://ni.lithium.com/t5/LabWindows-CVI/debug-executables-flagged-as-malware/m-p/3985387#M82077</guid>
      <dc:creator>vix</dc:creator>
      <dc:date>2019-11-07T12:36:00Z</dc:date>
    </item>
    <item>
      <title>Re: debug executables flagged as malware?</title>
      <link>https://ni.lithium.com/t5/LabWindows-CVI/debug-executables-flagged-as-malware/m-p/3998900#M82151</link>
      <description>&lt;P&gt;They probably flag everything not present in their database as malware ! And charge you for it.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2019 09:10:38 GMT</pubDate>
      <guid>https://ni.lithium.com/t5/LabWindows-CVI/debug-executables-flagged-as-malware/m-p/3998900#M82151</guid>
      <dc:creator>gdargaud</dc:creator>
      <dc:date>2019-12-11T09:10:38Z</dc:date>
    </item>
    <item>
      <title>Re: debug executables flagged as malware?</title>
      <link>https://ni.lithium.com/t5/LabWindows-CVI/debug-executables-flagged-as-malware/m-p/4202797#M89719</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;I'm using LabWindows 2020 and Windows 10.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It seems that I get a similar error with the McAfee virus scanner:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tombom_0-1641808099938.png" style="width: 400px;"&gt;&lt;img src="https://ip1.i.lithium.com/d12d0519de11606462373533206c51ee377de6b2/68747470733a2f2f6e692e6c69746869756d2e636f6d2f74352f696d6167652f736572766572706167652f696d6167652d69642f32393730343269374445343434383332333145433143312f696d6167652d73697a652f6d656469756d3f763d76322670783d343030" role="button" title="tombom_0-1641808099938.png" alt="tombom_0-1641808099938.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The application consists of a single UIR with two command buttons ( a "Quit" and an "Inc A" button, which increments a variable A each time when the button is pressed. The application is cleaned, as the debug-exe obviously tries to connect to some cloud service. It is cleaned from the system and deleted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The examples, however, seem to work without any problems.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anybody an idea how to fix this?&lt;/P&gt;
&lt;P&gt;McAfee only gives me the option to disable the specific thread function. This might no be a good idea.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The project "IncA" is attached as zip file.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #3c3c3c; font-family: DefaultFont, Fallback, Arial, sans-serif, 'MS Gothic', Simsun, 'Malgun Gothic'; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; display: inline !important; float: none;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jan 2022 09:55:53 GMT</pubDate>
      <guid>https://ni.lithium.com/t5/LabWindows-CVI/debug-executables-flagged-as-malware/m-p/4202797#M89719</guid>
      <dc:creator>tombom</dc:creator>
      <dc:date>2022-01-10T09:55:53Z</dc:date>
    </item>
    <item>
      <title>Re: debug executables flagged as malware?</title>
      <link>https://ni.lithium.com/t5/LabWindows-CVI/debug-executables-flagged-as-malware/m-p/4202810#M89720</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;at least for McAfee I possibly found a solution:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tombom_0-1641811558368.png" style="width: 400px;"&gt;&lt;img src="https://ip1.i.lithium.com/2f6d72a2f4d9d366b511beb1708a7f18f8a554f2/68747470733a2f2f6e692e6c69746869756d2e636f6d2f74352f696d6167652f736572766572706167652f696d6167652d69642f32393730343669423239343534463046313230454145392f696d6167652d73697a652f6d656469756d3f763d76322670783d343030" role="button" title="tombom_0-1641811558368.png" alt="tombom_0-1641811558368.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;One needs to uncheck the Option "clean, if the recommended threshold is exceeded".&lt;/P&gt;
&lt;P&gt;I do not know, if it is wise to do so, but at least I can debug the program.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Adidtionally, if I do not uncheck this option, the files created as "release" exe files are also not executed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jan 2022 10:48:28 GMT</pubDate>
      <guid>https://ni.lithium.com/t5/LabWindows-CVI/debug-executables-flagged-as-malware/m-p/4202810#M89720</guid>
      <dc:creator>tombom</dc:creator>
      <dc:date>2022-01-10T10:48:28Z</dc:date>
    </item>
    <item>
      <title>Re: debug executables flagged as malware?</title>
      <link>https://ni.lithium.com/t5/LabWindows-CVI/debug-executables-flagged-as-malware/m-p/4202983#M89721</link>
      <description>&lt;P&gt;I had a similar problem using Avast.&lt;/P&gt;
&lt;P&gt;I was able to remedy the problem by 'signing' my application.&lt;/P&gt;
&lt;P&gt;I added a digital certificate I created, and no more problem.&lt;/P&gt;
&lt;P&gt;Had to do the same thing with the distribution package.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jan 2022 20:59:54 GMT</pubDate>
      <guid>https://ni.lithium.com/t5/LabWindows-CVI/debug-executables-flagged-as-malware/m-p/4202983#M89721</guid>
      <dc:creator>mlh5953</dc:creator>
      <dc:date>2022-01-10T20:59:54Z</dc:date>
    </item>
    <item>
      <title>Re: debug executables flagged as malware?</title>
      <link>https://ni.lithium.com/t5/LabWindows-CVI/debug-executables-flagged-as-malware/m-p/4353066#M91369</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://ni.lithium.com/t5/user/viewprofilepage/user-id/176868"&gt;@mlh5953&lt;/a&gt;&amp;nbsp; ha scritto:&lt;BR /&gt;
&lt;P&gt;I added a digital certificate I created, and no more problem.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Hello, I've got this malware problem too but not on every application... how did you create your own certificate?&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 15:33:30 GMT</pubDate>
      <guid>https://ni.lithium.com/t5/LabWindows-CVI/debug-executables-flagged-as-malware/m-p/4353066#M91369</guid>
      <dc:creator>holly7787</dc:creator>
      <dc:date>2024-02-06T15:33:30Z</dc:date>
    </item>
    <item>
      <title>Re: debug executables flagged as malware?</title>
      <link>https://ni.lithium.com/t5/LabWindows-CVI/debug-executables-flagged-as-malware/m-p/4353073#M91370</link>
      <description>&lt;P&gt;@holly7787: I used an older version of Acrobat Reader to create one. &lt;/P&gt;
&lt;P&gt;Unfortunately the new version doesn't seem to include it.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 15:45:07 GMT</pubDate>
      <guid>https://ni.lithium.com/t5/LabWindows-CVI/debug-executables-flagged-as-malware/m-p/4353073#M91370</guid>
      <dc:creator>mlh5953</dc:creator>
      <dc:date>2024-02-06T15:45:07Z</dc:date>
    </item>
    <item>
      <title>Re: debug executables flagged as malware?</title>
      <link>https://ni.lithium.com/t5/LabWindows-CVI/debug-executables-flagged-as-malware/m-p/4353091#M91371</link>
      <description>&lt;P&gt;Maybe this will be useful, i've followed &lt;A title="how do i create a self signed certificate for code signing on windows" href="https://stackoverflow.com/questions/84847/how-do-i-create-a-self-signed-certificate-for-code-signing-on-windows" target="_blank" rel="noopener"&gt;this&lt;/A&gt; guide from stackoverflow:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Microsoft recommends using the PowerShell Cmdlet New-SelfSignedCertificate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Generate the key:&lt;BR /&gt;&lt;LI-CODE lang="markup"&gt;New-SelfSignedCertificate -DnsName email@yourdomain.com -Type CodeSigning -CertStoreLocation cert:\CurrentUser\My​&lt;/LI-CODE&gt;&lt;/LI&gt;
&lt;LI&gt;Export the certificate without the private key:&lt;BR /&gt;&lt;LI-CODE lang="markup"&gt;Export-Certificate -Cert (Get-ChildItem Cert:\CurrentUser\My -CodeSigningCert)[0] -FilePath code_signing.crt​&lt;/LI-CODE&gt;&lt;BR /&gt;The [0] will make this work for cases when you have more than one certificate... Obviously make the index match the certificate you want to use... or use a way to filtrate (by thumprint or issuer).&lt;/LI&gt;
&lt;LI&gt;Import it as Trusted Publisher&lt;BR /&gt;&lt;LI-CODE lang="markup"&gt;Import-Certificate -FilePath .\code_signing.crt -Cert Cert:\CurrentUser\TrustedPublisher​&lt;/LI-CODE&gt;&lt;/LI&gt;
&lt;LI&gt;Import it as a Root certificate authority.&lt;BR /&gt;&lt;LI-CODE lang="markup"&gt;Import-Certificate -FilePath .\code_signing.crt -Cert Cert:\CurrentUser\Root​&lt;/LI-CODE&gt;&lt;/LI&gt;
&lt;LI&gt;Sign the script (assuming here it's named script.ps1, fix the path accordingly).&lt;BR /&gt;&lt;LI-CODE lang="markup"&gt;Set-AuthenticodeSignature .\script.ps1 -Certificate (Get-ChildItem Cert:\CurrentUser\My -CodeSigningCert)​&lt;/LI-CODE&gt;
&lt;P&gt;&lt;BR /&gt;Obviously once you have setup the key, you can simply sign any other scripts with it.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;in CVI i open "Build" -&amp;gt; "Target Settings..." -&amp;gt; "Signing Info..." and selected the new certificate&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 16:23:31 GMT</pubDate>
      <guid>https://ni.lithium.com/t5/LabWindows-CVI/debug-executables-flagged-as-malware/m-p/4353091#M91371</guid>
      <dc:creator>holly7787</dc:creator>
      <dc:date>2024-02-06T16:23:31Z</dc:date>
    </item>
    <item>
      <title>Re: debug executables flagged as malware?</title>
      <link>https://ni.lithium.com/t5/LabWindows-CVI/debug-executables-flagged-as-malware/m-p/4353496#M91374</link>
      <description>&lt;P&gt;Many of those virus scanners are similar to a virus too. And often a real resource hog too. Real viruses usually try to be mean and lean as it reduces the risk of detection but that’s about all the difference there is. &lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 07:35:04 GMT</pubDate>
      <guid>https://ni.lithium.com/t5/LabWindows-CVI/debug-executables-flagged-as-malware/m-p/4353496#M91374</guid>
      <dc:creator>rolfk</dc:creator>
      <dc:date>2024-02-08T07:35:04Z</dc:date>
    </item>
    <item>
      <title>Re: debug executables flagged as malware?</title>
      <link>https://ni.lithium.com/t5/LabWindows-CVI/debug-executables-flagged-as-malware/m-p/4354083#M91378</link>
      <description>&lt;P&gt;Several anti virus program work also on the reputation of the executables, and since our programs are normally working only in one or a few instances they are flagged as "possibly malicious" due to the reduce number of installations.&lt;/P&gt;
&lt;P&gt;This is particularly annoying when developing an application, since the debug executable the IDE creates when executing the program is different&amp;nbsp; every time and every time I have my antivirus complaining about it!&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":face_with_rolling_eyes:"&gt;🙄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Feb 2024 08:38:17 GMT</pubDate>
      <guid>https://ni.lithium.com/t5/LabWindows-CVI/debug-executables-flagged-as-malware/m-p/4354083#M91378</guid>
      <dc:creator>RobertoBozzolo</dc:creator>
      <dc:date>2024-02-12T08:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: debug executables flagged as malware?</title>
      <link>https://ni.lithium.com/t5/LabWindows-CVI/debug-executables-flagged-as-malware/m-p/4354543#M91380</link>
      <description>&lt;P&gt;Signing your executable definitely should increase its reputation score significantly and hopefully high enough that those virus scare programs don't complain anymore.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2024 08:47:43 GMT</pubDate>
      <guid>https://ni.lithium.com/t5/LabWindows-CVI/debug-executables-flagged-as-malware/m-p/4354543#M91380</guid>
      <dc:creator>rolfk</dc:creator>
      <dc:date>2024-02-14T08:47:43Z</dc:date>
    </item>
  </channel>
</rss>

