It is a never ending story, a continue fight.
But I always insist doing something to improve thinBasic security and credibility.
In the company I work for we use a mix of Windows Defender (on premise and in Azure) + Cynet ( https://www.cynet.com/ ) + a remote company that monitor H24 7/7 our systems in real-time.
Cynet is very suspicious because its scanners scan deeply on application behaves and other things (that are secret to us).
The nice part is that Cynet support is that they are very responsive when there are false positive.
When I bundle some .EXE and they do not pass Cynet scan, they get informed almost immediately.
Sometimes they contact us to have more info.
In general after few hours problem is solved.
Most of the time thinBudle gives error during bundling just because AV scanner can takes longer to release bundled EXE
Thant's why thinBundle ha 2 options inside "UPX" tab in which indicates how many seconds to wait before considering passed the AV scan.
Also thinBundle checks for final executable size: most of the time when there are AV problems, final executable is much smaller than the final expected size because AV scan process interrupted thinBundle process in the middle.
So ... it's a daily fight ... that I'm also happy to fight because I always learn something new.
Bookmarks