-
-
Notifications
You must be signed in to change notification settings - Fork 61
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
EverythingPT installer flagged by anti-virus #110
Comments
Exe or zip? Nothing I can do about the exe file. |
really? idk just letting you know.
Sent from Proton Mail Android
…-------- Original Message --------
On 5/26/24 1:11 AM, Lin Yu-Chieh (Victor) wrote:
Exe or zip? Nothing I can do about the exe file.
—
Reply to this email directly, [view it on GitHub](#110 (comment)), or [unsubscribe](https://github.com/notifications/unsubscribe-auth/ADY3GN74KTPF6AEZRXGQF6LZEGKJVAVCNFSM6AAAAABIJR2JJOVHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDCMZSGEZDIMRSGE).
You are receiving this because you authored the thread.Message ID: ***@***.***>
|
this happens after you press yes on the update dialog correct? that's the exe file. There's nothing I can do about this, the main issue is that I don't have a digital certificate to sign the exe file, as certs costs hundreds of dollars per year. For EPT both cases are true, so many will flag it as dangerous. |
Just as a note, yesterday's installer for v0.86.0 is now also flagged by Microsoft Defender (definition No doubt, the |
Detailed report from Hybrid-Analysis |
@f22raptorroland
Summary: basically most of the triggers are things from NSIS or Everything's dll file, neither of which I have control over. |
And here is the Virus Total report: https://www.virustotal.com/gui/file/52d303fe985ce2bc3476c56234236588cf1b17c2d28352d2ce39761fd39b637a/detection |
The biggest joke in this Hybrid-Analysis report is that it has only a few spurious, very unsuspicious indicators for malicious behaviour, and only 1 in 25 virus scanners complaining about it, yet somehow it has a threat score of 100%. You'll find the explanation in the "runtime notifications" all the way at the bottom: "Enforcing malicious verdict, as a reliable source indicates high confidence". In other words: we looked at this file in depth and don't think there's anything particularly suspicious about it, but Microsoft's ML model says it's malware, so this must be the most dangerous file ever! The entire security software industry is made up of clowns. |
Chiming in I got this notification from Defender as well, the Wacatac.h!ml thing. So the consensus is that this is a false positive detected by AI/heuristics? Okay, that does make me feel better. I couldn't imagine not having Everything at a moment's notice :) Thank you for this plugin - I do appreciate it greatly! |
@lin-ycv You could potentially look into Azure Trusted Signing. It's pretty new, but it provides signing certificates for only $9.99 per month. https://azure.microsoft.com/en-us/products/trusted-signing |
Yes; also, it only applies to the installer, not any of the files it installs. If you're worried, as lin-ycv mentioned earlier, you can extract the ZIP file into the PowerToys Run plugin directory to get the same effect without any warning. |
Hey this is off topic but do you guys have anything that gives you search results within the flow window? I had the Google search Plus extension and that used to work but I don't want to search through Google and it stopped working. Looking for something that returns web results within the flow window |
Also I had a wacatac infection and it was no joke lol. Freaking pain in the beehive |
Malwarebytes is quarantining EverythingPT in the temp folder🐛 xx
To Reproduce
Start machine
Expected behavior
Nothing?
Screenshots
The text was updated successfully, but these errors were encountered: