Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Trojan:Script/Oneeva.A!ml #18

Closed
gyetger opened this issue Jun 12, 2021 · 18 comments
Closed

Trojan:Script/Oneeva.A!ml #18

gyetger opened this issue Jun 12, 2021 · 18 comments

Comments

@gyetger
Copy link

gyetger commented Jun 12, 2021

Windows Security reports Trojan:Script/Oneeva.A!ml in MicMute.zip v0.0.7 on download.
It doesn't happen with v0.0.6.

@Anc813
Copy link
Owner

Anc813 commented Jun 12, 2021

@roughnecks
Copy link

True. The strange thing is that I already have v0.0.7 running and Defender doesn't say a thing, but downloading the zip triggers it.

@Anc813
Copy link
Owner

Anc813 commented Jun 12, 2021

I tried to recompile project. Still have the same situation on virustotal (3/69 still flagged exe file as malicious)

@roughnecks
Copy link

True. The strange thing is that I already have v0.0.7 running and Defender doesn't say a thing, but downloading the zip triggers it.

Oh, I believe that's because I have whitelisted my "Portable" folder.

@gyetger
https://www.virustotal.com/gui/url/1293f6714d695aff2748228fa7b91c04523f017703c5dc51d406537c0f76b2ed/detection

I'm sure it's a false positive, but in VirusTotal I can't seem to find Windows Defender..

@Anc813
Copy link
Owner

Anc813 commented Jun 12, 2021

I have submitted request to microsoft, need wait up to 30 days for answer

@Anc813
Copy link
Owner

Anc813 commented Jun 12, 2021

I received answer
изображение

Analyst comments:

We have removed the detection.  Please follow the steps below to clear cached detection and obtain the latest malware definitions.

 1. Open command prompt as administrator and change directory to c:\Program Files\Windows Defender 
 2. Run “MpCmdRun.exe -removedefinitions -dynamicsignatures”
 3. Run "MpCmdRun.exe -SignatureUpdate"

 Alternatively, the latest definition is available for download here: https://www.microsoft.com/en-us/wdsi/definitions

 Thank you for contacting Microsoft.

@gyetger
Copy link
Author

gyetger commented Jun 12, 2021

  1. Open command prompt as administrator and change directory to c:\Program Files\Windows Defender
  2. Run “MpCmdRun.exe -removedefinitions -dynamicsignatures”
  3. Run "MpCmdRun.exe -SignatureUpdate"

These commands didn't work for me... it removed then re-downloaded version 1.341.574.0.
Using the GUI, it updated to 1.341.612.0
https://www.microsoft.com/en-us/wdsi/defenderupdates says that the latest version is 1.341.601.0.
Microsoft... -.-
But.. it still "founds" the Trojan.
I will try again tomorrow.

@roughnecks
Copy link

Sadly I'm still getting warned about it..

@Anc813
Copy link
Owner

Anc813 commented Jun 16, 2021

@roughnecks sadly I don't know what to do.

My fried told me, that is takes week or two to update and deliver windows defender definition updates.
But from the microsoft email it follows that it should be much faster (I initially thought that windows defender definition were updated at that moment)

I have submitted request here:
https://www.microsoft.com/en-us/wdsi/filesubmission

@roughnecks
Copy link

I see, well, we can wait :)

@Anc813
Copy link
Owner

Anc813 commented Jun 16, 2021

@roughnecks could You please try to submit "Incorrectly detected as malware/malicious" with Your exact file version?
I tried "MicMute.exe" (0.0.7), unarchived

@roughnecks
Copy link

@roughnecks could You please try to submit "Incorrectly detected as malware/malicious" with Your exact file version?
I tried "MicMute.exe" (0.0.7), unarchived

I tried just now and the form asks for malware name but when I downloaded the zip again, Defender sent a toast message about it being malicious and to click the toast for more details.. When I did that, Defender told me there were no threats.

Will try again tomorrow because right now I'm exausted.

@roughnecks
Copy link

Just tried again, same result, Defender blocks the download but doesn't tell me which malware is supposed to be.

@roughnecks
Copy link

Alright, I was able to find the history of malware and get the malware name, download the zip after adding an exception to it and submit my report to MS.

Hope this will help.

@roughnecks
Copy link

@roughnecks
Copy link

Hey guys, MS fixed this at last.. It doesn't trigger for me anymore.

@Anc813
Copy link
Owner

Anc813 commented Jun 24, 2021

@roughnecks it's an excellent news! Thank You!

@dwettstein
Copy link
Contributor

This issue could be closed. 😇

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants