Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

A lot of aniviruses detect latest kitty.exe as a Trojan #115

Closed
inliquid opened this issue Feb 15, 2020 · 14 comments
Closed

A lot of aniviruses detect latest kitty.exe as a Trojan #115

inliquid opened this issue Feb 15, 2020 · 14 comments

Comments

@inliquid
Copy link

Here is result for kitty.exe (0.73.2.3) downloaded from github:
https://www.virustotal.com/gui/file/dd6bb61464beee6787ff01b0eb35505b1aead6fa8aa910fe67a179435158109c/detection

@inliquid
Copy link
Author

This is actually very first time from the YEARS of usage of kitty when some (actually Microsoft) antivirus silently killed application so I had to spend some time investigating where is it gone.

@BirdDev
Copy link

BirdDev commented Feb 15, 2020

My Windows Defender also reports this version (0.73.2.3) as trojan Win32/Wacatac

Is it save to use, though?

@lars18th
Copy link
Contributor

Hi to all,

Please, STOP to open new issues based on the same premise: "An antivirus is detecting incorrectly KiTTY as trojan/virus". A lot if issues comment the same: #91, #105, #111 and @cyd01 knows it...

So if you want helping to fix this issue, then COMMENT HOW TO CHANGE THE COMPILATION TO OVERCOME THIS PROBLEM.

Regards.

@inliquid
Copy link
Author

This is issue is not about some particular a/v. It's regarding the fact that many of them are now treating kitty as a virus.

@lars18th
Copy link
Contributor

Hi @inliquid ,

This is issue is not about some particular a/v. It's regarding the fact that many of them are now treating kitty as a virus.

Yes. And I repeat: we know it, and @cyd01 knows it. So no more posts about this are helping here.

Futhermore please note that this problem will not be resolved because a lot of people open multiple issues. However, if someone can HELP explaining how to overcome it fixing the compilation procedure, then perhaps a solution will appear.

I only comment this to be positive and polite. Personally I don't know how to fix this problem. 😞
Regards.

@AntonOks
Copy link

Hi @inliquid ,

This is issue is not about some particular a/v. It's regarding the fact that many of them are now treating kitty as a virus.

Yes. And I repeat: we know it, and @cyd01 knows it. So no more posts about this are helping here.

Futhermore please note that this problem will not be resolved because a lot of people open multiple issues. However, if someone can HELP explaining how to overcome it fixing the compilation procedure, then perhaps a solution will appear.

I only comment this to be positive and polite. Personally I don't know how to fix this problem. 😞
Regards.

I have no idea what and how to fix... but obviously something must have been changed since the last "ok" KiTTY version 0.73.2.2, which now triggers all the virus scanners... right? Maybe worth a thought?!

@lars18th
Copy link
Contributor

I have no idea what and how to fix...

And the same is true for the rest. For this reason it not useful to open more issues about the same thing.

but obviously something must have been changed since the last "ok" KiTTY version 0.73.2.2, which now triggers all the virus scanners... right?

No. It's not obvious. It's the opposite: nothing relevant is changed in the compilation toolchain. No one here knows the root cause.

Regards.

@BirdDev
Copy link

BirdDev commented Feb 16, 2020

I have no idea what and how to fix...

And the same is true for the rest. For this reason it not useful to open more issues about the same thing.

but obviously something must have been changed since the last "ok" KiTTY version 0.73.2.2, which now triggers all the virus scanners... right?

No. It's not obvious. It's the opposite: nothing relevant is changed in the compilation toolchain. No one here knows the root cause.

Regards.

I also took a quick look on the recent changes made to kitty and I also saw nothing I could imagine causing this Problem.
But I noticed when checking the VirtusTotal analysis yesterday that the number of analyzers that marked this as a virus decreased from the first check to the second check the same day from 15 to 1. Currently, it's still one analyzer.

Could it possibly be that ( I haven't checked myself yet) this is actually not an issue of KiTTY but rather

  • an issue of PuTTY?
  • an issue of the virus scanner manufacturers?

@AntonOks
Copy link

I also took a quick look on the recent changes made to kitty and I also saw nothing I could imagine causing this Problem.
But I noticed when checking the VirtusTotal analysis yesterday that the number of analyzers that marked this as a virus decreased from the first check to the second check the same day from 15 to 1. Currently, it's still one analyzer.

Could it possibly be that ( I haven't checked myself yet) this is actually not an issue of KiTTY but rather

* an issue of PuTTY?

* an issue of the virus scanner manufacturers?
  1. Can confirm, I could "scoop update" KiTTY to 0.73.2 again
  2. Had no issue with PuTTY in many months

Anyhow, big thanks to all KiTTY helpers and makers ;)

@lars18th
Copy link
Contributor

Hi,

After reading this old thread from another opensource github project: mozilla/geckodriver#671
I feel that different antivirus developers are sharing some information about malware.
For example, today when downloading the last version of KiTTY the Google Chrome has identified the kitty_portable.exe as a malware.

So, I suggest to @cyd01 to send a report using this link: https://submit.symantec.com/false_positive/
I feel that after that the KiTTY will be then included in the whitelist of all scanners.

I hope it helps.
Regards.

@cyd01
Copy link
Owner

cyd01 commented Mar 13, 2020 via email

@lars18th
Copy link
Contributor

It is difficult to fill the false positive form since it never occurs on my side (on any of my personal PC or working PC). Le ven. 13 mars 2020 à 09:28, Lars The notifications@github.com a écrit :

Please, try to download the kitty_portable.exe with updated Chrome: https://github.com/cyd01/KiTTY/releases/download/v0.73.2.6/kitty_portable.exe

@cyd01
Copy link
Owner

cyd01 commented Sep 19, 2020

It seems false positives appear after compression process. I use UPX.
So that I chose to add a non compressed version to official CDN (on fosshub website).
Uncompressed build seems to be never detected. See Virustotal scan.
I'll see with Scoop team if they could include this version rather than the regular one.

@cyd01 cyd01 closed this as completed Sep 19, 2020
@DumbJoe
Copy link

DumbJoe commented Aug 26, 2022

So the reason kitty is being detected is because you used UPX for compression? Is there any way to use another program for compression? or get UPX to fix their false positives with all antivirus and antimalware programs?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

6 participants