Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

False positive for Windows Defender #9

Closed
markski1 opened this issue Sep 11, 2023 · 2 comments
Closed

False positive for Windows Defender #9

markski1 opened this issue Sep 11, 2023 · 2 comments

Comments

@markski1
Copy link
Contributor

Unfortunately, on my local machine, Windows Defender has begun to detect version.dll as a trojan by the signature "Trojan:Win32/Wacatac.B!ml".

This might be related to the fact the masterlist fix fundamentally works through memory hacking, and I'm not sure if it can be fixed, but I'm opening this issue to make light of the problem.

For now, VirusTotal continues to agree that the file is safe, so that is good news at least.

@spmn
Copy link
Owner

spmn commented Sep 11, 2023

That’s how Microsoft treats new binaries that are rarely downloaded and are not digitally signed. Many hobbyist Windows devs are complaining that their files get flagged as malware. Eventually, as more users install and whitelist the mod, the warning should go away. The downside is that any new version will have to go through the same vetting process.

Once I get some time to build a new dll with the updated endpoint, I will also submit the new file to MSFT for additional analysis, hoping that they would vet it faster.

@spmn
Copy link
Owner

spmn commented Sep 12, 2023

I've submitted v2.0.1 to Microsoft and their automatic analysis did not find anything suspicious. Now I am waiting for the manual analysis, which should say the same thing.

image

I'm closing this now since there is nothing else I can do to "fix" the false positives.

@spmn spmn closed this as completed Sep 12, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants