sluciani wrote:For whatever reason, Panda Free Antivirus won't let me run the Beta 11 installer. Had to disable it first. It quarantined the installer as "suspicious".
"Suspicious" sounds like a heuristic hit, all modern AVs have heuristics analysis to supplement the pure signature based hits because many modern viruses are encrypted to the point that there is no signature until after it's already triggered. Exactly what goes in to the heuristics and how it's weighted varies wildly and there's no documentation. There may well be other ways to override heuristics hits in it but your solution works.
It's increasingly common for AVs to include things like "how many times have I seen this before" in their heuristics. While seeing a file for the first time is usually! not enough in itself to trigger a flat out denial but it can make them ultra-suspicious and deny things they would normally accept.
Panda calls themselves "Cloud" anti-virus for a reason, they were one of the pioneers and they still consider it their "main advantage" over some of the others. So it's probably the AV most likely to throw a hissy fit over a file that is rare or ultra-rate! Any NBPro beta builds may well put it in "can I find ANYTHING even remotely suspicious about this executable" mode. Also, the "specimen" may well be uploaded to them for further, much slower but better analysis off-line.
This also means that the behavior may well change over time, it's quite possible that the same B11 installer will now pass Panda AV, it may have seen more examples now and/or have done a deep analysis offline that has moved it to the "safe" category.
You can scan your B11 installer at
https://www.virustotal.com/I get 0/57 on it at VirusTotal right now and that count includes Panda AV...
Jotti virus scan has a different list of AVs and shows 1 hit of 22, but that one is utterly bogus, ClamAV lists PUA.Win32.Packer.BorlandDelphi-1, that one is just ClamAV being silly.