TinyNvidiaUpdateChecker icon indicating copy to clipboard operation
TinyNvidiaUpdateChecker copied to clipboard

Marked as malware by anti malware (false positive)

Open Dantasstic opened this issue 2 years ago • 45 comments

As per the title, the latest update is being flagged by Window Defender as a severe trojan. The previous version (1.15.1) was not flagged, and no previous version has either.

You may want to look into this and change whatever you did that made it start to flag on this version only.

Win32/Bearfoos.B!ml

2022-11-27 - 0153-08

Dantasstic avatar Nov 27 '22 08:11 Dantasstic

Yea each freaking update keeps having false positives #124 it started happening after I added an extension that made so I don't have to also ship dll files. They are inside the executable instead.

Feels like this is going to keep happen I might have to remove this and readd all the dll files

ElPumpo avatar Nov 27 '22 17:11 ElPumpo

Interesting, I went back to 1.15.1 because it was not being false detected. I wonder why some people get detections on certain versions but others don't. I also never got a detection on 1.15.0 as listed in that posted.

Dantasstic avatar Nov 28 '22 02:11 Dantasstic

No both 1.15.1 and 1.15.0 were also false positives

ElPumpo avatar Nov 29 '22 09:11 ElPumpo

How about having CI to get VirusTotal results on release?

Technetium1 avatar Nov 29 '22 16:11 Technetium1

Well would that help that defender keeps flagging it positive?

ElPumpo avatar Nov 29 '22 17:11 ElPumpo

No both 1.15.1 and 1.15.0 were also false positives

Strange, they aren't flagged on my system. I just re-scanned them both specifically and Defender didn't make a peep.

Dantasstic avatar Nov 30 '22 01:11 Dantasstic

Well they were on release

ElPumpo avatar Nov 30 '22 08:11 ElPumpo

No both 1.15.1 and 1.15.0 were also false positives

Strange, they aren't flagged on my system. I just re-scanned them both specifically and Defender didn't make a peep.

same here. only latest update gets detected

DMT4all avatar Nov 30 '22 09:11 DMT4all

Same issue with 1.15.3

Dantasstic avatar Dec 16 '22 14:12 Dantasstic

Well would that help that defender keeps flagging it positive?

@ElPumpo Probably not, BUT it would hopefully stop people from opening issues about false positives when they can click to see the scan results. Maybe consider using their Monitor service that's intended to catch false positives early: https://developers.virustotal.com/reference/monitor

Technetium1 avatar Dec 16 '22 17:12 Technetium1

Interesting. I will take a look into this and implement some auto upload thing

ElPumpo avatar Dec 21 '22 18:12 ElPumpo

Possibly fixed with new .NET single file thing.

ElPumpo avatar Dec 31 '22 18:12 ElPumpo

Hi and happy new years. I have migrated from .NET Framework to .NET now which has a "Produce single file" feature. I am just guessing that it will solve the false positives that Costura.Fody previously introduced.

TinyNvidiaUpdateChecker 1.15.5 beta 1.zip

Please try this new version out I am thankful for the feedback

ElPumpo avatar Jan 03 '23 22:01 ElPumpo

Hi and happy new years. I have migrated from .NET Framework to .NET now which has a "Produce single file" feature. I am just guessing that it will solve the false positives that Costura.Fody previously introduced.

TinyNvidiaUpdateChecker 1.15.5 beta 1.zip

Please try this new version out I am thankful for the feedback

Hmm, it just flashes momentarily on the screen and then is gone for me.

Dantasstic avatar Jan 05 '23 05:01 Dantasstic

Yea this beta requires .NET Runtime 7. Try running the tool in a command prompt such as CMD to see the error

ElPumpo avatar Jan 05 '23 09:01 ElPumpo

I installed 7.0.1 .NET Runtime and still just a flash pops up. I can't get the app to run in CMD or Powershell either, it doesn't like it.

Dantasstic avatar Jan 05 '23 09:01 Dantasstic

Yes but did you install both x86 and amd64 Runtime?

ElPumpo avatar Jan 05 '23 10:01 ElPumpo

Ummm no, you didn't mention that XD. Do you mean x86 and x64? I installed x64.

Are you sure you don't mean the full SDK? Now it's freaking out about framework, which runtime doesn't come with hahahaha

Best to link to the exact installer you think I should run, since we are having some miscommunication here.

Dantasstic avatar Jan 05 '23 10:01 Dantasstic

No dont install the SDK just the runtime I belive haha. I will probably publish framework independent..

Yes install both x64 and x86. The tool is built for x86 but you prob need both

ElPumpo avatar Jan 05 '23 11:01 ElPumpo

No dont install the SDK just the runtime I belive haha.

I tried that, but it still doesn't run. Like I said, it then mentions a missing framework.

Dantasstic avatar Jan 05 '23 13:01 Dantasstic

Okay yea I messed up there. Will release a new beta that is framework independent. But no false positives right?

ElPumpo avatar Jan 05 '23 13:01 ElPumpo

No, no false positives! :)

Dantasstic avatar Jan 05 '23 13:01 Dantasstic

Good!

ElPumpo avatar Jan 05 '23 13:01 ElPumpo

I got it to run by installing the full SDK, which includes 3 runtimes (.NET Runtime 7.0.1, ASP.NET Core Runtime 7.0.1 and .NET Desktop Runtime 7.0.1), although the one it seemed to actually want was the ASP.NET Core and not the .NET Runtime.

I just installed only .NET SDK x86 version 7.0.1, so no need for the x64 currently.

Dantasstic avatar Jan 05 '23 13:01 Dantasstic

🙏😂 good. I will see about releasing framework independent. Good thing this beta was shared so this wouldnt appear later

ElPumpo avatar Jan 05 '23 14:01 ElPumpo

Good but I belive this issue now can be closed as it no longer is an issue.

ElPumpo avatar Jan 05 '23 15:01 ElPumpo

Still an issue...

ElPumpo avatar Jan 26 '23 21:01 ElPumpo

This is now being flagged for v1.16.3 too.

Virond avatar Feb 01 '23 13:02 Virond

Can you show me

ElPumpo avatar Feb 01 '23 14:02 ElPumpo

Can you show me

image

Virond avatar Feb 01 '23 14:02 Virond