Jump to content

Dale M

Members
  • Content Count

    5
  • Joined

  • Last visited

Posts posted by Dale M


  1. 9 hours ago, stan rydzewski said:

    Now, do I think there is a virus?  No.  Avast and windows both think my machine is clean and I've added nothing to delphi itself.  I literally just downloaded it from embarcadero and made this file with it.  So I guess my question is more, can I control the make process in such as way as to remove the threatening behavior, which seems to involved stopping a windows process.  (Which sounds dodgy, I suppose, but maybe it's something Delphi does for debugging?)  You can read about why it is being flagged  on the evaluation linked to above.)

     

    I'd love to hear any thoughts on this.  Thanks for reading.

    This thread may be of interest to you - 

     


  2. @Kas Ob. @Clément Thanks for this discussion. 🙂 Adding {$DYNAMICBASE ON} appears to please CrowdStrike also.

     

    Delphi 10.4.2, New Windows VCL application (that's it...just an empty form), 32-bit, Release config

    https://www.hybrid-analysis.com/sample/e8a4cdfe94031025baafff9924d82210bd74b4088607fa369b30deeb83e72480

    image.png.007adeea2fb1eabddf2bdc3994728008.png

     

    Same as above but with {$DYNAMICBASE ON}

    https://www.hybrid-analysis.com/sample/86e9c1fe77dbe5cfc962dce19e79e7a7930b92dd1ba90cba60395d5998995c1b

    image.png.f2225c52933e6e743e72f10781b6d897.png

    • Like 1

  3. FWIW, I've had issues with CrowdStrike flagging any 32-bit application compiled with recent versions (10.x) of Delphi as malicious. Just an empty form will do it, does not matter if it is signed or not. 64-bit applications are fine. I've emailed and submitted as false positive with no response. My employer uses CrowdStrike and if a 32-bit app is deployed or updated (very rare; all 64-bit these days) then I have to provide the hash of the exe to our system guy so he can add it to the list of approved/excluded apps. 

     

    Site to run a check against your exe if anyone is interested:

    https://www.hybrid-analysis.com/

     

     

×