Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[issue]: still detecting viruses #1300

Closed
1 task done
InfoLibre opened this issue Dec 4, 2021 · 24 comments
Closed
1 task done

[issue]: still detecting viruses #1300

InfoLibre opened this issue Dec 4, 2021 · 24 comments

Comments

@InfoLibre
Copy link

Official FAQ

  • I have checked the official FAQ.

Ventoy Version

1.0.62

What about latest release

Yes. I have tried the latest release, but the bug still exist.

BIOS Mode

Legacy BIOS Mode

Partition Style

MBR

Disk Capacity

1000

Disk Manufacturer

No response

Image file checksum (if applicable)

No response

Image file download link (if applicable)

No response

What happened?

https://www.virustotal.com/gui/file/7895fcd68559e7afbf2a8f9445bf2d55abbfbeefe0ac3bc40991801f34bcfd6c
https://www.virustotal.com/gui/file/f9dd10bd20b56cba3f963cde06874d5a2ee8d267c85060d26f1cefb691b304bd
https://www.virustotal.com/gui/file/fece97f4d5c67cfce808b14472287210147b9344005024539e4580ce0bea3c25

@ventoy
Copy link
Owner

ventoy commented Dec 4, 2021

It's false positive.
There is such false positive when I update Ventoy2Disk.exe, but after some time it will be added to the whitelist.
This happened too many times.
#1217
#1204
#1203
#1194
#660
#468
#371
#31

@ventoy ventoy closed this as completed Dec 4, 2021
@thetuxinator
Copy link

What about asking the AV-Vendors what they found or why they whitelist later always?

@InfoLibre
Copy link
Author

InfoLibre commented Jan 4, 2022

I'm sure it isn't false positive. Old versions of Ventoy for Linux were distributing these infected files, not intentionally:
https://www.virustotal.com/gui/file/0410043931953e7805fdb747f2a25c409ad0b6ed85807e222f30e995ab7352c4
https://www.virustotal.com/gui/file/dfdbc0e785a7c8e44da626eb6cf299b3a0b34b92c21e97654ad73eb909cd3062
https://www.virustotal.com/gui/file/cda64cc6c7344b6b7470de727c936479b08b313025faffdde6b9c620f0993f4a
https://www.virustotal.com/gui/file/e1b5c93d1dc30f50b2ab7e57facbcf93af709f069bbf2c057eb4868dd7650f48
https://www.virustotal.com/gui/file/aaa6878a39788e3a385918c4e1a5cd35ab276795f2325a09e4dba2f6a8d03d17
https://www.virustotal.com/gui/file/c2ea92a5011482a8c654df42e48dceb78cfcd4d5e4d59d68ab340e756be3d284
https://www.virustotal.com/gui/file/e3686c960bd29a830c81a5c0396638b73bb7949b3f707fe029d4fbbff9ebe1d4
https://www.virustotal.com/gui/file/31fa518ddf1a2a66459670f085980339429e65039676dc4202ed289b5ddb0362
These infected binaries were difficult to find in Ventoy because they each were archived and compressed one to 5 times in different zip, tar, img... files. They were removed after my issue: #660
Now, there are other alerts in new Ventoy files for Windows. I'm sure they will be recognized by all antivirus in a few years and all people who are saying "it's false positive" or "it's impossible because everybody is using Ventoy" will continue to say the same things.

@thetuxinator
Copy link

Well to be honest, you can guess whatever you want, guessing is bad, as long as there are no facts thats actually worse than everything else. the only way to get rid of all this guessing etc. is to get a feedback from AV-Vendors, so if nobody else does, i will already ask Bitdefender for their opinion/analysis.

@thetuxinator
Copy link

I asked Bitdefender, will write the Results here, maybe others can Contact their Antivirus-Vendors.

@InfoLibre
Copy link
Author

InfoLibre commented Jan 5, 2022

@thetuxinator The only right ways are as you say, asking antivirus vendors for their analysis (not their opinion) or analyzing yourself the binaries.

@thetuxinator
Copy link

An idea for @ventoy what if your machine is somehow infected? So who can ask other AV-Vendors? I have a Bitdefender Subscription thats why i asked them.

@BigmenPixel0
Copy link

@ventoy
I think it's better to just remove the binaries from the sources than spread viruses

@ventoy
Copy link
Owner

ventoy commented Jan 16, 2022

You can build the 3 exe files from source with VisualStudio easily.
So you build it and then upload for test and then they told you that it has viruses.
You can ask the AV-Vendor that "please tell me why you say it has viruses and which code is viruse?"

@InfoLibre
Copy link
Author

@ventoy Are you using VisualStudio under Windows to compile?

@BigmenPixel0
Copy link

@ventoy What about other blobs in sources?

@ventoy
Copy link
Owner

ventoy commented Jan 17, 2022

The links in the topic involve VentoyPlugson.exe Ventoy2Disk.exe files which were built with VisualStudio in Windows.

@ventoy
Copy link
Owner

ventoy commented Jan 17, 2022

@ventoy What about other blobs in sources?

The blobs in sources are descripted in https://github.com/ventoy/Ventoy/blob/master/DOC/BuildVentoyFromSource.txt
They are either built from source or directly downloaded from other open source project.

@InfoLibre
Copy link
Author

InfoLibre commented Jan 17, 2022

You perhaps caught something bad in your Windows. If someone could compile with same version of VisualStudio on same version of Windows, it would be interesting to compare binaries.
Do you still use https://busybox.net/downloads/binaries/ binaries too? Could you use more recent version 1.35.0 and compile from sources, not use binaries?

@thetuxinator
Copy link

@ventoy why the hell has this been closed?

@InfoLibre
Copy link
Author

InfoLibre commented Feb 15, 2022

9 antivirus are flagging last version 1.0.67: https://www.virustotal.com/gui/file/90eb3c4365547a2bd6bbd001dba23c0a9fcde1c59bfe90f3758f204eeda44045
Windows files seem to contain something bad.

@thetuxinator
Copy link

Bitdefender (my only remaining AV Subscription) was not willing to provide Info on why they detected it. As of now i stop recommending Ventoy and Stop using it, especially as @ventoy refuses to care about and to scan his machine or do anything in the right direction! thats irresponsible and unacceptable! You distribute software and you may distribute a Malware/Virus/Trojan with it and you don't even seem to care that your own machine may be infected!

@ventoy
Copy link
Owner

ventoy commented Feb 21, 2022

My machine is not infected.
You can download the code and install VisualStudio and build the exe by yourself and then scan the exe, and they will report a Virus to you.
Someone else has did such test.

@steve6375
Copy link

The detection of false positives in files is common. AV and antimalware programs use a combination of identifying specific byte sequences, near matches, black list signatures (and white list signatures) and analyse of portions as well as identifying common delivery sequences/packages that are often used by virus (but also used by legitimate products).
Many use heuristic analysis and these often report the likelihood of malware (rather than 100% positively identify malware).

  • BitDefenderTheta AI:Packer.6E7A2EA71F
  • Cybereason Malicious.ee0176
  • Malwarebytes MachineLearning/Anomalous.94%
  • MaxSecure Trojan.Malware.300983.susgen
  • SecureAge APEX Malicious
  • ViRobot Trojan.Win32.Z.Agent.119296.AAF

The scan results show that 63 AV programs PASSED VentoyVlnk.exe (including many of the top AV products).
The list of 6 positives comprise mainly of less well known AV products (except Malwarebytes which shows a 94% heuristic likelihood of a POSSIBLE match.)

You need to be aware that most AV s/w simply have a 'whitelist' of hashes - when you report a false positive to the AV developer, they simply add the hash of your product into their AV whitelist table so it is not reported as a virus.

As the developer says, you can simply build the exe yourself from a 'clean' system (e.g. fresh VM) and source files and the .exe produced will probably also give approx 6 false positives (even though the exe may have a slightly different hash).

That is why VirusTotal also allows people to 'vote' on how bad or clean they think it is and comment on the results in the 'Community' tab, because you cannot just look at 6 fails and say 'Oh - it has a virus!'. If many of the 'better' AV products flagged it as a virus (e.g. Avira, Acronis, Avast, BitDefender, DrWebb, EMSiSoft, FSecure, Eset, GDta, Mcafee, Microsoft, Symantec, etc.) then you should worry but not when a few obscure AV products fail it.

@InfoLibre
Copy link
Author

InfoLibre commented Feb 21, 2022

@steve6375
Copy link

steve6375 commented Feb 21, 2022

So you are saying that Avira, Acronis, Avast, BitDefender, DrWebb, EMSiSoft, FSecure, Eset, GData, Mcafee, Microsoft and Symantec, are not professionals, even though their livelihood and reputation depends on detecting malicious software?
P.S. If packaged files fail (.xz, .gz, etc), then simply unpack the files and re-zip them - you will see they will give a completely different results when they contain the same files!

@RobbeDren
Copy link

RobbeDren commented Mar 7, 2022

Found this discussion helpful. I used VirusTotal earlier to scan ventoy-1.0.70-windows.zip and it reported only one security vendor (Ad-Aware MaxSecure) that flagged the file as Trojan.Malware.300983.susgen.

https://www.virustotal.com/gui/file/b5425c40a737bd39134584f34d841ef51f13405db89446431a5fb47b65ddc4f7/detection

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

6 participants