Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

VirusTotal #43

Open
Michal-Witwicki opened this issue Jan 19, 2021 · 3 comments
Open

VirusTotal #43

Michal-Witwicki opened this issue Jan 19, 2021 · 3 comments

Comments

@Michal-Witwicki
Copy link

Useful app, but I'm worried that one of your antivirus software reports it as malware https://www.virustotal.com/gui/file/df6de6df2ab6279b623b916e44dc242cad72b1730509a13dee04420bcff16b47/detection.

@Dijji
Copy link
Owner

Dijji commented Jan 19, 2021

Thanks for letting me know. I note that only one out of 70 antivirus engines reported that a virus had been found. And that one is Cynet, which, looking at their site claims to be a new AI- based approach capable of detecting zero day attacks. I have reported it as a false positive to them (Cynet support case 00626226).

I'm reassured by the 69 clean bills of health. I know I haven't put anything in there, but I can never rule out the possibility of something sneaky having got on my build machine. Do you get the same results if you build it yourself?

@Michal-Witwicki
Copy link
Author

It's good that you reported, it's worth eliminating false positive. Unfortunately, I don't know because I don't know how to build software :).

@Dijji
Copy link
Owner

Dijji commented Jan 20, 2021

Here is the response from Cyren:

Your case 00626226 has been closed.

The submitted content is not detected by Cyren. If at any point the content was detected by Cyren, this appears to be already corrected in the latest definition files version.

Please make sure to update to the latest AV definition files version.

So I asked VirusTotal to rescan the file, but Cyren still reports positive. The only thing to do seems to be to wait for VirusTotal to get some updated definitions.

The rescan also returned a second positive, this time from MaxSecure, for Trojan.Malware.300983.susgen. And all this without changing the file at all! MaxSecure makes rather harder work of submitting a false positive, and I notice after a quick web search that I'm not the only piece of open source software to have this virus detected by MaxSecure, so I'm inclined to ignore this one for now as a blip from a relatively minor provider.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants