Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Trojan detected for Ventoy2Disk.exe #31

Closed
luketanti opened this issue Apr 30, 2020 · 14 comments
Closed

Trojan detected for Ventoy2Disk.exe #31

luketanti opened this issue Apr 30, 2020 · 14 comments

Comments

@luketanti
Copy link

DeepinScreenshot_select-area_20200430123122

When extracting on windows, the Ventoy2Disk.exe is getting flagged and deleted by McAfee

Is this false positive?

I have also checked on VirusTotal and attached a screenshot

@JinGWme
Copy link

JinGWme commented Apr 30, 2020

I second this.
McAfee delete main exe file upon download finishes.

@HarmVeenstra
Copy link

Same goes for Sophos Endpoint Protection

@boomschtick
Copy link

boomschtick commented May 5, 2020

The detections on VirusTotal is up to 19. I ran the app in Windows Sandbox and didn't see anything wrong, but the detection rate is concerning for people who care to look.

image

https://www.virustotal.com/gui/file/231711f3b7c6adc5567b154dcc480c204cd8116808bbe10512729d0be68b57f0/detection

@xfrankbx
Copy link

xfrankbx commented May 6, 2020

Same for Bitdefender. Says it found Trojan.GenericKD.33781261 in the zip file.

@luketanti
Copy link
Author

@ventoy can you please have a look about this please?

@luketanti luketanti reopened this May 6, 2020
@ventoy
Copy link
Owner

ventoy commented May 6, 2020

@luketanti

Currently I have no idea about this.
Ventoy2Disk.exe is open source. You can compile it from the source by VisualStudio.
So I don't known why it is denied by these antivirus software.

Any suggestions?

@boomschtick
Copy link

There has to be some kind of behavior in the code that the AV's don't like to see. Either that or you have used source code that was used previously in some kind of malware.

That's my best guess.

@RudiKlein
Copy link

Hi,
Maybe the message I got from Acronis Active Protection (module of Acronis True Image 2020) could shine some light on this. It blocks the Ventoy2Disk.exe with the message: Possibe ransomware detected. Acronis Active Protection paused the program that tried to modify your Master Boot Record". That might be a hint.

@jsamr
Copy link

jsamr commented Jun 4, 2020

@ventoy I dig into support channels. Here is a list, you could submit reports to be whitelisted! I picked all false positive vendors from Virus Total.

EDIT1: I removed the false positives reported by older VT submissions
EDIT2: Only two anti-virus solutions flag the 1.0.12 version as malware

@Riz-waan
Copy link

Hi, what about for windows defender?

@tonyd85
Copy link

tonyd85 commented Jun 7, 2021

Acronis claims it modifies the Master Boor Record. Of which disk, Acronis is yet to say. However, Acronis is kind enough to bug out for 30 minutes before finally blocking it. Edit: Then Acronis actually failed to block it. Better look up my build number before I post on their forums...

@ventoy ventoy closed this as completed Oct 18, 2021
@tonyd85
Copy link

tonyd85 commented Oct 18, 2021

yeah the behavior is not using DLL injection to get past AV. lmao

@jimmihenry
Copy link

Windows Defender found and kicked the Ventoy.exe, pointing out Trojan:Win32/Phonzy.C!ml. Ver.1.0.58
Cheers

@petrus9
Copy link

petrus9 commented Nov 9, 2022

Just tested ventoy-1.0.81-windows.zip on virus total and got one flag: Trojan.Malware.300983.susgen by MaxSecure
image

image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests