Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

stupid bit defender STILL detects it. #4

Closed
Hardcore-fs opened this issue Jan 2, 2019 · 4 comments
Closed

stupid bit defender STILL detects it. #4

Hardcore-fs opened this issue Jan 2, 2019 · 4 comments
Labels
bug Something isn't working

Comments

@Hardcore-fs
Copy link

An infected file attempted to run on your device.
Threat name: Application.MAC.DirectHW.X
Path: /Users/comp_01/Downloads/DPCIManager.app/Contents/MacOS/DPCIManager
We quarantined the file to prevent malicious commands from being executed on your device.

@MuntashirAkon MuntashirAkon added the bug Something isn't working label Jan 2, 2019
@MuntashirAkon
Copy link
Owner

Interesting, previously they didn't detect anything. I'll try to remove any symbol related to DirectHW.

@MuntashirAkon
Copy link
Owner

Try this:
DPCIManager.app.zip

@Hardcore-fs
Copy link
Author

the new one passes...

I think maybe they are convinced the old one is mal ware because it writes to the hardware.

but they might update the virus defs once they see the same app with a different sig.
so it could be this one fails in the future.

@MuntashirAkon
Copy link
Owner

I think, previously, they didn't check for strings in Mach-O executables. But now they do. There was only one string in the app which referred to DirectHW. I simply removed it and it worked again.

Anyway, since there are no longer any references to DirectHW, I think the issue is finally solved.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants