Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Windows Defender Threat Detected Win32/Wacatac.D1!ml #16

Closed
Ugenx opened this issue Aug 30, 2020 · 6 comments
Closed

Windows Defender Threat Detected Win32/Wacatac.D1!ml #16

Ugenx opened this issue Aug 30, 2020 · 6 comments
Labels
wontfix This will not be worked on

Comments

@Ugenx
Copy link

Ugenx commented Aug 30, 2020

I am assuming this is a false positive having to do with dotnet core as I found references to a similar situation happening with the dotnet sdk itself when people are building it from source (dotnet/runtime#35167) but just figured I'd let you know that this is happening:

image

@flyingpie
Copy link
Owner

Hello @Ugenx!

Thank you for reporting this. Though it's common for lesser-known apps to be flagged by virus scanners, the app doesn't actually run on .Net Core.

I'm not sure if there's anything I can do to prevent this. Maybe signing the app with a paid-for certificate, or submitting to Virus Total and hoping tons of people will use it :)

@Ugenx
Copy link
Author

Ugenx commented Aug 30, 2020

Woops, silly me for assuming! I'm sure it has to do with the way you hook into/call the process; I too am not sure what can be done to prevent it. FWIW, I just clean installed my operating system last night as I had been dealing with some game performance issues since upgrading to Windows 10 2004 and it has yet to flag the program again. The previous installation also took a few days of running it before it detected/quarantined the executable as well which is curious.

@pnuzhdin
Copy link

I can confirm, I have the same issue.

@shashank-shekhar
Copy link

I built the latest and submitted the .exe to VirusTotal and got one detection
Qihoo-360 HEUR/QVM03.0.9D9B.Malware.Gen
Quick Googling suggests that it is possibly a false positive because it's an .exe without a signed certificate.

@metya
Copy link

metya commented Sep 3, 2020

Confirm that. Now it is not working even after grant permission and whitelisted app in windows defender.
And even after redownload app.

@flyingpie
Copy link
Owner

So I assume that the only way to not be flagged by virus scanners would be to sign the app, which I'm not intending to do (these are fairly pricey).

Unless this otherwise impacts usability of the app, I'm gonna close this issue. The app is open source, small and easy-to-build, so I'm not too interested in the trust-factor here.

@flyingpie flyingpie added the wontfix This will not be worked on label Sep 8, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
wontfix This will not be worked on
Projects
None yet
Development

No branches or pull requests

5 participants