FanControl.Releases icon indicating copy to clipboard operation
FanControl.Releases copied to clipboard

Updater.exe Blocked by Windows Defender

Open hl2guide opened this issue 1 year ago • 24 comments

Describe the bug Updater.exe Blocked by Windows Defender

ex

hl2guide avatar Nov 22 '23 00:11 hl2guide

Same but it thought it was another trojan image

bczegeny avatar Nov 22 '23 00:11 bczegeny

got this message too Screenshot (7)

ungkal96 avatar Nov 22 '23 00:11 ungkal96

I get the exact same as the above....

CIsxxc avatar Nov 22 '23 00:11 CIsxxc

same

jilherme avatar Nov 22 '23 01:11 jilherme

same Wacatac.B!ml

Sad to have to find an alternative as I don't think this is a false positive. End of an era.

agarrandosenal avatar Nov 22 '23 01:11 agarrandosenal

Trojan:Script/Wacatac.B!ml

well damn

ErisaFirehawk avatar Nov 22 '23 01:11 ErisaFirehawk

Wait, he does mention false positives here, but can @Rem0o comment on this?

image

CIsxxc avatar Nov 22 '23 01:11 CIsxxc

Whenever I recompile the updater, it triggers Microsoft Defender. I send a false positive submission, it gets scanned, then the false positive stops.

image

Rem0o avatar Nov 22 '23 01:11 Rem0o

Same here, got the threat quarantined. @Rem0o should I restore the updater or delete and reinstall FC after some time?

ad0x00 avatar Nov 22 '23 01:11 ad0x00

Whenever I recompile the updater, it triggers Microsoft Defender. I send a false positive submission, it gets scanned, then the false positive stops.

image

Thank you so much for your time and the effort you put into this project.

I'll be donating to you this payday after having used the app for a couple months very happily!

Have a lovely day/evening :)

CIsxxc avatar Nov 22 '23 01:11 CIsxxc

Windows Defender is a misunderstanding.

Spuner avatar Nov 22 '23 02:11 Spuner

Importantly if you're here because your FanControl isn't running now, and hangs on launch. the update process hasn't fully completed. redownload fancontrol and reinstall all the files as a replacement, preserving your config and plugins folder.

unfortunately because they are binaries you cannot confirm there isn't actually a trojan here. @Rem0o could be a compromised account encouraging us to download.

a-zndr avatar Nov 22 '23 03:11 a-zndr

Importantly if you're here because your FanControl isn't running now, and hangs on launch. the update process hasn't fully completed. redownload fancontrol and reinstall all the files as a replacement, preserving your config and plugins folder.

unfortunately because they are binaries you cannot confirm there isn't actually a trojan here. @Rem0o could be a compromised account encouraging us to download.

I have tried to download the newest and it still tells me "threat detected". unless maybe I download the version before?

marrok657 avatar Nov 22 '23 03:11 marrok657

I had the same issue as everyone else. I finally got it working after I ran "Updater.exe". The first time it was run is shown in the attached screenshot. After deleting the .dll file that is mentioned, I ran Updater.exe again and the program runs as usual. Screenshot (368)

tullahstackz avatar Nov 22 '23 04:11 tullahstackz

Until Windows Defender Sorts out its detection of the new updater, save your configurations, download 174 directly from the site.

csandazoltan avatar Nov 22 '23 05:11 csandazoltan

Until Windows Defender Sorts out its detection of the new updater, save your configurations, download 174 directly from the site.

Thats what worked for me although I didnt try the poster above's recommendation of deleting the file, mainly because I didnt see the update.exe file referred to in their post. I copied the json and plugin folder from old install into new downloaded one from the website and all good.

Trae132 avatar Nov 22 '23 05:11 Trae132

Yup same with me tried to update and just install straight from website and defender grabs it as well.

AussieGomez avatar Nov 22 '23 06:11 AussieGomez

I had the same problem and now fan control won't start at all.

Khanivore avatar Nov 22 '23 08:11 Khanivore

I had the same issue as everyone else. I finally got it working after I ran "Updater.exe". The first time it was run is shown in the attached screenshot. After deleting the .dll file that is mentioned, I ran Updater.exe again and the program runs as usual. Screenshot (368)

this solved it, thanks

yvesfouquet4 avatar Nov 22 '23 08:11 yvesfouquet4

It quarantined it for me, but after downloading the new update, unzipping it, deleting everything but the "Config" folder in the old folder and copy pasting the update into it, everything seems to work again. If the Trojan is still doing stuff in the background, I can't tell.

danielbr93 avatar Nov 22 '23 09:11 danielbr93

I had the same issue as everyone else. I finally got it working after I ran "Updater.exe". The first time it was run is shown in the attached screenshot. After deleting the .dll file that is mentioned, I ran Updater.exe again and the program runs as usual. Screenshot (368)

Worked for me too : had to delete Autofac.dll & Newtonxxxx.dll. After running the update, those dll didn't reappear...

supabibz avatar Nov 22 '23 11:11 supabibz

There`s some news about this update is false positive or an hacked false update that bring virus?

Chicora470 avatar Nov 23 '23 15:11 Chicora470

Importantly if you're here because your FanControl isn't running now, and hangs on launch. the update process hasn't fully completed. redownload fancontrol and reinstall all the files as a replacement, preserving your config and plugins folder.

unfortunately because they are binaries you cannot confirm there isn't actually a trojan here. @Rem0o could be a compromised account encouraging us to download.

No response from @Rem0o about this?

Chicora470 avatar Nov 25 '23 19:11 Chicora470

Not had any issues with Windows Defender here. Remi already addressed why this can happen above: https://github.com/Rem0o/FanControl.Releases/issues/2133#issuecomment-1821942006

Defender (and most AV products) will flag a program that tries to modify itself (ie, update) if the signature is not known. When FC is re-compiled, the signature is changed, and there will always be a delay between release and Defender being up to date.

AtA3301 avatar Nov 28 '23 12:11 AtA3301