USBHelperLauncher icon indicating copy to clipboard operation
USBHelperLauncher copied to clipboard

Remote access trojan detected by windows after updating to 1.0; Trojan:Script/Sabsik.FL.A!ml

Open Jawzper opened this issue 1 year ago • 9 comments

@ USBHelperInjector.dll

Jawzper avatar Mar 29 '23 09:03 Jawzper

Same problem seen today on the code that was updated 2 days ago.

tonyjobson avatar Mar 29 '23 09:03 tonyjobson

image

tonyjobson avatar Mar 29 '23 09:03 tonyjobson

And just like on that comment, I seem to have to say this again. Its a false positive, if there was actual malware, more than just a couple people every once in a while would be screaming about it. Open source programs constantly have to deal with AV's throwing false positives every time a new build is released, its a side effect to how modern heuristic based AV solutions work.

Masamune3210 avatar Mar 29 '23 10:03 Masamune3210

Sorry found the closed issue from a few days ago a little late @Masamune3210 ran the update for defender and now it's not complaining anymore. For refference and resolution: https://github.com/FailedShack/USBHelperLauncher/issues/91

tonyjobson avatar Mar 29 '23 10:03 tonyjobson

If you want to know more about why it's being detected as possibly malicious, it's because of heuristics like I said previously and the fact that it injects code into another process. This is fine if you trust the program, plenty of other programs do it as well. The problem is that malware does it too and av companies would rather err on the side of caution and flag everything and generate false positives to make sure they catch as much as they can.

Masamune3210 avatar Mar 29 '23 10:03 Masamune3210

@Masamune3210 I'm now getting alerts against the dll file as well

image

is there anyway to revert back?

tonyjobson avatar Mar 29 '23 11:03 tonyjobson

You don't need to, and probably don't want to. Just add an exception to tell Defender to stop whining

Masamune3210 avatar Mar 29 '23 11:03 Masamune3210

You can add a whole folder as an exception btw Turn defenders real time protection off temporarily, move the files where they go, add a folder exception, and turn it back on

Masamune3210 avatar Mar 29 '23 11:03 Masamune3210

Please let me know of the versions listed here so I can report these issues to Microsoft: https://www.bleepingcomputer.com/tutorials/how-to-find-the-microsoft-defender-version-installed-in-windows-10/

FailedShack avatar Mar 29 '23 16:03 FailedShack