bt icon indicating copy to clipboard operation
bt copied to clipboard

AV False Positives (Malware, Riskware, Adware, Virus, Trojan and other BS)

Open neoOpus opened this issue 2 years ago • 66 comments

After reinstalling Windows and configuring Bluetooth, MS Defender removed it after identifying it as malware (I didn't have time to add it to a whitelist)

Please figure out why it's happening and get it signed now. Even if it's free, some people might not like using it because it might scare them or be taken off their computers.

Screenshot 2023-08-11 102854 image

neoOpus avatar Aug 11 '23 15:08 neoOpus

I am unable to download it unless, of course, if I disable MS Defender

image

neoOpus avatar Aug 11 '23 15:08 neoOpus

I can't afford a signing certificate so it's not going to happen. You are free to validate it's not dangerous as source code and build pipelines are completely open and transparent.

aloneguid avatar Aug 11 '23 22:08 aloneguid

I can't afford a signing certificate so it's not going to happen. You are free to validate it's not dangerous as source code and build pipelines are completely open and transparent.

What is the cost of a signing certificate?

corvus2606 avatar Aug 24 '23 13:08 corvus2606

It's about $1.5k for 3 years. Could be less if you shop around. But that won't solve false AV issues, you can still be banned and certificate revoked for no reason. I think realistically one needs a legal team to deal with AV false claims which I apparently don't have. I'd recommend having a read:

  • https://weblog.west-wind.com/posts/2016/Oct/05/Dealing-with-AntiVirus-False-Positives
  • https://www.autohotkey.com/boards/viewtopic.php?t=87322
  • https://steamcommunity.com/app/779590/discussions/0/2572002906839928114/
  • https://help.steampowered.com/en/faqs/view/5F3D-1477-AFF9-C4F3
  • https://www.linkedin.com/pulse/kaspersky-reasons-false-positives-amirabbas-mahdavi
  • https://www.gdatasoftware.com/blog/2022/06/37445-malware-detection-is-hard
  • https://medium.com/@airflow.matt/globalsign-will-revoke-your-codesign-certificate-no-questions-asked-f6ac2bca02c5

And by the way, the last BT version (3.5.0) has only a single AV's claim out of 90, unlike 29 out of 90 for version 3.4.0, so it's totally random trash. I've myself became very pessimistic about usefulness of AV software in general after dealing with this.

aloneguid avatar Aug 24 '23 13:08 aloneguid

Kaspersky and Sophos both left BT undetected for me, seems it might be a Microsoft specific issue.

paz avatar Sep 10 '23 04:09 paz

it's totally random and changes daily ;)

aloneguid avatar Sep 11 '23 14:09 aloneguid

Windows Defender (Win 11) just flagged bt-3.5.2 as "threats found" for me.

Detected: Program:Win32/Wacapew.C!ml

GavinFarrington avatar Sep 13 '23 18:09 GavinFarrington

Same thing here, BT 3.5.2 was flagged by Microsoft Defender as PUA. It's possible to send files to Microsoft for further analysis: https://www.microsoft.com/en-us/wdsi/filesubmission/ – I urge you to do it if you are affected.

jnv avatar Sep 15 '23 07:09 jnv

Same thing here, BT 3.5.2 was flagged by Microsoft Defender as PUA. It's possible to send files to Microsoft for further analysis: https://www.microsoft.com/en-us/wdsi/filesubmission/ – I urge you to do it if you are affected.

I have used this before, and just submitting for latest version as "incorrectly identified as malware". Will let you know on progress: image

aloneguid avatar Sep 15 '23 08:09 aloneguid

Analysis on above is still pending but some detections have already cleared out.

aloneguid avatar Sep 17 '23 18:09 aloneguid

It keeps getting deleted even when excluded from scans... I have to reinstall it every few days.

neoOpus avatar Sep 18 '23 01:09 neoOpus

There are 2 different .zip files. A pdb version which downloads fine and non-pdb version that doesn't. What's the difference between the 2?

CityguyUSA avatar Sep 18 '23 05:09 CityguyUSA

There are 2 different .zip files. A pdb version which downloads fine and non-pdb version that doesn't. What's the difference between the 2?

.pdb version is debug symbols to investigate crashes, you don't need that.

aloneguid avatar Sep 18 '23 11:09 aloneguid

It keeps getting deleted even when excluded from scans... I have to reinstall it every few days.

You can permanently allow the "threat" until MS investigates. There are instructions available here.

aloneguid avatar Sep 18 '23 11:09 aloneguid

Windows Defender should now be fine, just got analysis results from Microsoft:

image

aloneguid avatar Sep 19 '23 07:09 aloneguid

Also VirusTotal before and after (Microsoft AV is OK now). Hopefully others will follow the suit.

image

image

aloneguid avatar Sep 19 '23 07:09 aloneguid

It keeps getting deleted even when excluded from scans... I have to reinstall it every few days.

You can permanently allow the "threat" until MS investigates. There are instructions available here.

I have been doing that since the start, but it doesn't stick. That's why I notified you that currently it is allowed and working properly, but it crashes when trying to find updates... I am simply informing you of this, but it is alright if you are unable to resolve these.

neoOpus avatar Sep 19 '23 16:09 neoOpus

@neoOpus thanks. Update checks are already fixed and will be out in v3.6. Defender does not block it anymore.

aloneguid avatar Sep 19 '23 16:09 aloneguid

By the way, I reported the false positive to Avast (which also includes AVG), so VT now reports only 11 false positives.

According to their reply, they reclassified BT from malware to PUA, since apparently it doesn't match their "clean software policy" (which, surprisingly, claims signing is preferred but not required):

Thank you for contacting Avast and reporting a false positive detection. We're happy to help.

Along with the Avast virus specialist, we’ve checked the reported file and changed the threat detection to PUP (potentially unwanted program). The PUP detection is due to lack of compliance with Avast’s clean software policy.

For more information, refer to this article: Avast Threat Labs - Clean guidelines

If you are the owner of the reported file and want to change the detection to clean, feel free to contact us again for a new analysis as soon as the file matches the Avast guidelines.

jnv avatar Sep 20 '23 09:09 jnv

@jnv thanks for that, I also raised request with ESET which has reclassified as clean.

aloneguid avatar Sep 20 '23 10:09 aloneguid

@jnv I have raised Avast issue separately yesterday, and classification is cleared completely.

image

aloneguid avatar Sep 20 '23 11:09 aloneguid

Also submitted a dispute to McAfee now.

aloneguid avatar Sep 20 '23 11:09 aloneguid

And just for fun to Malwarebytes.

aloneguid avatar Sep 20 '23 11:09 aloneguid

So far, it worked and I didn't have any issue :)

neoOpus avatar Sep 23 '23 03:09 neoOpus

Unfortunately we're back to 24 false positives for the v3.6.2 installer. Today even Microsoft Defender took down my locally compiled version.

jnv avatar Oct 31 '23 08:10 jnv

Microsoft seems to be happy, but others are not. It will help in long term to vote on VirusTotal community webpage: https://www.virustotal.com/gui/file/7273f03b70a07ab0e1cf96aa4702587ea850b72efbdeef4690bf44bb3edd295b/community

aloneguid avatar Oct 31 '23 09:10 aloneguid

AVG and Avast were great help in whitelistimg 3.6.2, we are -2 now.

aloneguid avatar Nov 02 '23 21:11 aloneguid

Unfortunately we're back to 18/64

cheTesta avatar Nov 06 '23 09:11 cheTesta

14/61 today!

image

aloneguid avatar Nov 06 '23 09:11 aloneguid

image 18 on the .zip version

cheTesta avatar Nov 06 '23 09:11 cheTesta