Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Loki.exe removed by window defender #85

Closed
justNik101 opened this issue Oct 11, 2017 · 8 comments
Closed

Loki.exe removed by window defender #85

justNik101 opened this issue Oct 11, 2017 · 8 comments

Comments

@justNik101
Copy link
Contributor

Why window defender is removing a Simple scanner?

@justNik101
Copy link
Contributor Author

window defender detected Trojan:Win32/Azden.A!cl in loki.exe and Trojan:Java/Micuh in test\yara\JFolder.jsp

@vwhissell
Copy link

False Positive. Just create an exception in Windows Defender for: File -> Loki.exe

@justNik101
Copy link
Contributor Author

Thanks man but i Am looking for a way to make it undetectable - as the same functionality can be legitimately mirrored by any other executable file , but one thing why it is getting caught by antivirus as it only traverses directories and processes - scans for regular expressions match (simple search) and Loki.exe is just executable of Loki.py it needs other python and signature file to function. If window defender is detecting by hash signature then just minor changes can change the hash.

@vwhissell
Copy link

And Now, Microsoft Endpoint Protection Reports it as infected.

Seriously, Microsoft is sooooooooo crap. Are they doing this on purpose? Worst "IT Security" Team Ever. Who is the CISO of Microsoft? I would, ANYTIME, fire that guy. Windows Subsystem for Linux = no security, their AV Product sucks ass, Windows is not secure (Can't follow best practices with Sandboxing and stuff? Is it that hard?), Azure, very bad security, ... and many many many more.

Yep, this morning, I'm pissed. At least, because or their suits, we got a job. Continue being crap Windows, you will give us jobs! :)

@Hodgegoblin
Copy link

Sophos is now reporting loki.exe as Troj/Agent-AXXR. Details here: https://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/Troj~Agent-AXXR/detailed-analysis.aspx

@Hodgegoblin
Copy link

Release 0.26.0 was not identified by Sophos as a threat.

@axence
Copy link

axence commented Feb 14, 2018

Release 0.26.1 was not identified by Microsoft Windows Defender as a threat.

@Neo23x0
Copy link
Owner

Neo23x0 commented Feb 14, 2018

Thanks for the updates 👍

@Neo23x0 Neo23x0 closed this as completed Mar 22, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants