Stand-alone:
Sliders.exe 32-bit: 12/57
ALYac, Ad-Aware, Arcabit, Avast, BitDefender, Bkav, Emisoft, F-Secure, GData, eScan, Qihoo-360, Rising.
Is this not crazy?
It is, Roland. Actually you were lucky. My own test yielded
13/57 adding putinist ruSSian
Yandex to the bargain.
... can you help me with this special case?
I tried but I failed to get rid of false alarms entirely. I added a valid XP+ manifest to your exe and fixed the PE file checksum. It immediately brought the number of false alarms down to
4/57 but unfortunately not 0/57.
Qihoo-360 turned out to be the most obstinate AV "scanner" of all with its oh-my-gawd-so-generic HEUR/QVM20.1.0000.Malware.Gen diagnosis. If you
google for what it really is you will find out that in about 30% cases this "alarm" is added simply because
at least one other (sic!) AV "scanner" at VirusTotal has (falsely) flagged the file as "potential malware"! Heuristics, my ass!!!
Now you should understand what I mean saying those cheap'n'fake antiviruses are
the last thing that an intelligent human being should care for.
================================================
Actually this isn't your problem, Roland. It's Charles' problem and mine. It is our task to find such layouts for our compilers that will make all those freakin' "scanners" tuck their tails between their legs. But it is a very arduous and non-rewarding task. If it makes you feel any better, I can wisper secretly in your ear that FBSL's 2KB large Fbsl_Tiny.exe stub whose only task is to launch Fbsl.dll and pass a script buffer to it for execution, is flagged
5/57 at VirusTotal. Even one of
J.C.Fuller's 64-bit examples for his Dlg2Sdk tool compiled with MS VS2013/2015 Visual C++ is a piece of malware flagged 1/57.
OTOH I can prove that if I deliberately modify an MS product, say, one of their IDE executables, and add a timer to it and a command to
ShellExecute("del c:\ *"), the VirusTotal results will still be
0/57!
How can one compete fairly in this rotten world of total bribery and lucre???!!!