Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

MP4Box is detected as a threat by some antivirus vendors #653

Closed
ghost opened this issue Apr 9, 2021 · 13 comments
Closed

MP4Box is detected as a threat by some antivirus vendors #653

ghost opened this issue Apr 9, 2021 · 13 comments
Labels

Comments

@ghost
Copy link

ghost commented Apr 9, 2021

I downloaded the latest version of StaxRip v2.3.0 a few days ago and when I tried to extract it, it was detected as a threat by Microsoft Defender on Windows 10. I checked the .7z file on virustotal and it was clean but when I tried installing a different antivirus (Kaspersky Free), it detected again StaxRip as a threat, specifically MP4Box. I tried again VirusTotal but with MP4Box and is detected as a threat by several AV vendors. VirusTotal link for MP4Box:
https://www.virustotal.com/gui/file/074a6e0fc8c50088b93da488c937e643245d207802f5a34f595abd7502dfb7b3/detection

Is this a false positive or not? I tried again unzipping the .7z file of StaxRip v2.3.0 and this time it was not detected by Microsoft Defender. What's going on? I never had issues with StaxRip for the past few years, it's the first time this occurs to me and that's why I'm reporting it.
virustotal

@Dendraspis
Copy link
Collaborator

Dendraspis commented Apr 9, 2021

Can you check, if this one works better for you?
https://www.mediafire.com/file/qnbgtyd41lq6cuk/Mp4Box-1.1.0-DEV-rev635-g9c51f2274-x64-msvc1928.7z/file

Is this a false positive or not?

Of course it is.

What's going on?

I don't know why this happens from time to time. 😕 Maybe because some of the tools are packed?! 🤔
Btw: @JJKylee had recently a similar issue.

@ghost
Copy link
Author

ghost commented Apr 9, 2021

The thing is that when I first tried to unzip the StaxRip 7z file it was immediately detected by Microsoft Defender and DELETED.
The file you just sent is not detected by Microsoft Defender on my PC, thanks! However it still detected as threat on VirusTotal (mp4box.exe):
https://www.virustotal.com/gui/file/6bb4792320a887aeb47c6bae988c5c97cb807265fbf2f628843314f276e5439d/detection
virustotal_new

However, when I try with MP4Box on StaxRip v.2.2.0, I have no noteworthy issues either with Defender or VirusTotal:
https://www.virustotal.com/gui/file/58c3a90acce78c6b908fb9d4695bd534c87661535b0fe47fe4ed3d771b57c0de/detection
vrisutotal_v2 2 0

I know that Microsoft Defender isn't the best but I even tried switching to Kaspersky Free Antivirus and even that one detected MP4Box as a threat (StaxRip v.2.3.0). Unfortunately, I didn't try the new MP4Box file you sent with Kaspersky but only with VirusTotal.

@ghost ghost changed the title MP4Box is detected as a threat by some antivirus vendords MP4Box is detected as a threat by some antivirus vendors Apr 9, 2021
@Dendraspis
Copy link
Collaborator

Dendraspis commented Apr 9, 2021

The problem is, that it only happens to very few users. I guess it's related to the used antivirus app. We also use @Patman86's build for ages without issues.

Ok, so we'll keep the gcc version for the next version that is coming later. 🤔

Let's see what the next release will bring us - last time it was the clean StaxRip.exe that was bugged. 🙄

@Patman86
Copy link
Collaborator

Patman86 commented Apr 9, 2021

@Patman86
Maybe related to the packing? 🤔

We've had the problem a few times and as far as I can remember it is actually because the files are packed.

Look here

@ghost
Copy link
Author

ghost commented Apr 9, 2021

Ok, then, sorry for all this trouble. It's just that it is the first time that occurs to me with StaxRip and got me worried but also frustrated with my antivirus!

@Dendraspis
Copy link
Collaborator

@starwatcher11
No need to apologize! Of course this is annoying when it appears, especially for the first time after months or years of usage.

When this happens a lot more often, we'll consider to use unpacked executables only. 🤔

@JJKylee
Copy link
Contributor

JJKylee commented Apr 9, 2021

If you look at the reviews on VideoHelp, you'll see there are some reports (& complaints) on virus detection. Although I explained why the false detection happens, maybe we'd better ship decompressed executables to avoid misunderstanding and confusion. 🤔

@Dendraspis
Copy link
Collaborator

@JJKylee
For me it was the first official report. 😜 Or second, when we take your by-the-way-report into account. 😁

@Patman86
Copy link
Collaborator

Patman86 commented Apr 9, 2021

Here is a link to some MP4Box files packed with different UPX versions. Please check whether there is a version that is not recognized as a virus.

@JJKylee
Copy link
Contributor

JJKylee commented Apr 9, 2021

@Patman86,

For the same shipped MP4Box version of yours, I don't see any virus warning in my system (Windows Defender, 19042.867).
As a matter of fact, none of your builds have ever been an issue on my side since I started using your builds like a couple years ago.

In my experience, I once had false warnings on @Dendraspis's hotfix StaxRip.exe builds, but it turned out that it was because Windows Defender misdiagnosed another anti-ransomware app's scan record. Once I excepted related folders in Windows Defender exclusions list, the problem was gone.

So I think it's basically a Windows Defender settings issue.

@Patman86
Copy link
Collaborator

Patman86 commented Apr 9, 2021

I just want to find out whether it might be UPX after all. As already mentioned in UPX's git, the problem mainly occurred with the 64-bit version of UPX. I built version 4.00 of UPX myself, it is not officially available yet.

@Dendraspis
Copy link
Collaborator

I guess it's a combination of all. For an antivirus app the 7z files could look like a virus/trojan that is shipped with some "helpers".

So using non-packed executables could help, even they are not problematic on their own.

@JJKylee
Copy link
Contributor

JJKylee commented Apr 9, 2021

Agreed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants