Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Virustotal detected "MachineLearning/Anomalous" #340

Closed
olegkovtun opened this issue Jan 25, 2021 · 8 comments
Closed

Virustotal detected "MachineLearning/Anomalous" #340

olegkovtun opened this issue Jan 25, 2021 · 8 comments

Comments

@olegkovtun
Copy link

Virustotal detected "MachineLearning/Anomalous" for SharpKeys.exe
https://www.virustotal.com/gui/file/bac9862933012c90065fd031b2896761be8173b1620316c85fd702beb88536ea/detection
Is it safe?

@randyrants
Copy link
Owner

My releases here are malware and virus free. I cannot make the same claim if someone takes the source, modifies it, and releases elsewhere.

@olegkovtun
Copy link
Author

But this exe-file from your site: https://www.randyrants.com/sharpkeys39.zip
You can scan this file via Virustotal by yourself and make sure.

@olegkovtun
Copy link
Author

I've just scanned the 3.5 version: https://www.randyrants.com/sharpkeys35.zip
And virustotal said that this file is clean.

@randyrants
Copy link
Owner

randyrants commented Jan 25, 2021

...which is a zip of what is posted here - in the Releases section - which contains two files: an EXE and HTML file for FAQ. The app is compiled using the .NET Framework with no external libraries. So, that either means that a) the .NET Framework has that malware, b) a virus corrupted my uploaded ZIP file after it was hosted on the web server, or c) the scanner is off in it's findings?

FWIW, I just pulled the file down and scanned it: reported no issues here.

@olegkovtun
Copy link
Author

Of course, it is an EXE file (as I mentioned in the initial comment).

FWIW, I just pulled the file down and scanned it: reported no issues here.

Hmm... It is strange. I've downloaded EXE the file again from https://www.randyrants.com/sharpkeys39.zip and scanned it - the result is the same - "MachineLearning/Anomalous.100%".
But EXE from this link https://www.randyrants.com/sharpkeys35.zip - reported no issues here.
I don't have an idea, what is the reason.
Tomorrow I'll try to scan on another laptop and see the result.

@olegkovtun
Copy link
Author

It is reproduced as initially described on another laptop.

@randyrants
Copy link
Owner

randyrants commented Feb 4, 2021

Can't help you out much here: the same binary in the ZIP is the same as the MSI which is the same that I scanned. Also the same EXE that's available here from the Releases section.

No idea why one virus scanner is throwing a fit but none of the other scanners are.

@olegkovtun
Copy link
Author

This is very strange, that the result of scanning EXE file from the same source is different on your and my sides. It should not be.
I also no idea why.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants