Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

EverythingPT installer flagged by anti-virus #110

Closed
tristansly opened this issue May 26, 2024 · 14 comments
Closed

EverythingPT installer flagged by anti-virus #110

tristansly opened this issue May 26, 2024 · 14 comments

Comments

@tristansly
Copy link

Malwarebytes is quarantining EverythingPT in the temp folder🐛 xx

To Reproduce
Start machine

Expected behavior
Nothing?

Screenshots
ZbchW8d6tM

@tristansly tristansly added the bug Something isn't working label May 26, 2024
@lin-ycv
Copy link
Owner

lin-ycv commented May 26, 2024

Exe or zip? Nothing I can do about the exe file.

@lin-ycv lin-ycv removed the bug Something isn't working label May 26, 2024
@tristansly
Copy link
Author

tristansly commented May 27, 2024 via email

@lin-ycv
Copy link
Owner

lin-ycv commented May 27, 2024

this happens after you press yes on the update dialog correct? that's the exe file.

There's nothing I can do about this, the main issue is that I don't have a digital certificate to sign the exe file, as certs costs hundreds of dollars per year.
Most AV will flag exe files as potentially dangerous if:
A) it's not commonly downloaded
B) it's not digitally signed

For EPT both cases are true, so many will flag it as dangerous.
Either you trust it and press allow, or you use the ZIP file instead.

@lin-ycv lin-ycv closed this as completed May 27, 2024
@lin-ycv lin-ycv changed the title Malwarebytes is quarantining EverythingPT in the temp folder🐛 xx EverythingPT installer flagged by anti-virus May 27, 2024
@lin-ycv lin-ycv pinned this issue May 27, 2024
@lin-ycv lin-ycv closed this as not planned Won't fix, can't repro, duplicate, stale May 27, 2024
@Anamon
Copy link

Anamon commented Nov 12, 2024

Just as a note, yesterday's installer for v0.86.0 is now also flagged by Microsoft Defender (definition Trojan:Script/Wacatac.H!ml).

No doubt, the ml means this was "detected" by an "AI". I wonder if these snake oil vendors realise what kind of damage they're doing to the security awareness of the public at large. This GenAI nonsense in security software has led to such an unfathomable torrent of bogus detections, that most people have reached the point where any alert is considered to be a false positive by default… </rant>

@f22raptorroland
Copy link

Detailed report from Hybrid-Analysis
@lin-ycv

@lin-ycv
Copy link
Owner

lin-ycv commented Nov 14, 2024

@f22raptorroland
Like I said before, there's not much I can do, addressing the suspicious indicators with higher relevnace:

  • Dropped file has high entropy: compressed png images
  • Drops executable files || Writes a PE file header to disc: extracting EPT and everything dll files to disk
  • Calls an API typically used for keylogging: not sure why the installer is monitoring shift, 1, 2 and 4 keys, NSIS is probably using it for when there's a popup window.
  • Marks file for deletion || Opens file with deletion access rights: I don't know what nszFF45.tmp is, probably something NSIS needs for extraction
  • CRC value set in PE header does not match actual value: Everything64.dll is from Everything's SDK, I have no control other it.
  • Timestamp in PE header is very old or in the future: have no idea why that date is from the future, these files are compiled by VS

Summary: basically most of the triggers are things from NSIS or Everything's dll file, neither of which I have control over.

@gabriel-vanca
Copy link

I'm also getting a virus alert from Microsoft Defender, but it's a different signature.
I wasn't getting any errors with the previous versions.

image

@gabriel-vanca
Copy link

@Anamon
Copy link

Anamon commented Nov 14, 2024

The biggest joke in this Hybrid-Analysis report is that it has only a few spurious, very unsuspicious indicators for malicious behaviour, and only 1 in 25 virus scanners complaining about it, yet somehow it has a threat score of 100%. You'll find the explanation in the "runtime notifications" all the way at the bottom: "Enforcing malicious verdict, as a reliable source indicates high confidence".

In other words: we looked at this file in depth and don't think there's anything particularly suspicious about it, but Microsoft's ML model says it's malware, so this must be the most dangerous file ever!

The entire security software industry is made up of clowns.

@EazyCheeze1978
Copy link

Chiming in I got this notification from Defender as well, the Wacatac.h!ml thing. So the consensus is that this is a false positive detected by AI/heuristics? Okay, that does make me feel better. I couldn't imagine not having Everything at a moment's notice :) Thank you for this plugin - I do appreciate it greatly!

@SoCuul
Copy link

SoCuul commented Nov 16, 2024

@lin-ycv You could potentially look into Azure Trusted Signing. It's pretty new, but it provides signing certificates for only $9.99 per month. https://azure.microsoft.com/en-us/products/trusted-signing

@Anamon
Copy link

Anamon commented Nov 19, 2024

Chiming in I got this notification from Defender as well, the Wacatac.h!ml thing. So the consensus is that this is a false positive detected by AI/heuristics? Okay, that does make me feel better. I couldn't imagine not having Everything at a moment's notice :) Thank you for this plugin - I do appreciate it greatly!

Yes; also, it only applies to the installer, not any of the files it installs. If you're worried, as lin-ycv mentioned earlier, you can extract the ZIP file into the PowerToys Run plugin directory to get the same effect without any warning.

@tristansly
Copy link
Author

Hey this is off topic but do you guys have anything that gives you search results within the flow window? I had the Google search Plus extension and that used to work but I don't want to search through Google and it stopped working. Looking for something that returns web results within the flow window

@tristansly
Copy link
Author

Also I had a wacatac infection and it was no joke lol. Freaking pain in the beehive

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

7 participants