[go: nahoru, domu]

Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dozens of AVs detect the wrapper as malware #7

Closed
jyrkive opened this issue Nov 19, 2017 · 4 comments
Closed

Dozens of AVs detect the wrapper as malware #7

jyrkive opened this issue Nov 19, 2017 · 4 comments
Assignees

Comments

@jyrkive
Copy link
jyrkive commented Nov 19, 2017

https://www.virustotal.com/#/file/bb5e59d432cb3d06521c60ec3d877f2841664a39445e735d43859c131b4b5d3f/detection

32 AVs is so many that I'm rather going to believe that the latest version really is infected, rather than going to run it on my PC.

@crazy-max
Copy link
Member

Hi @jyrkive,

It's the same issue as #3, every detections found by VirusTotal scan are generic. Most likely based on a heuristic detection. Heuristics are more prone to false-positive detections.

This happens quite often with programs written in Golang. The best you can do is to report this to your Antivirus software vendor.

And since the wrapper discord-portable.exe is open source, you can verify that it does not include any malware.

Of course i will try to find dependencies and system calls to avoid heuristic detection like this. I also think that the architecture of the executable (ia32) is also a consequence of the problem encountered. I'll analyze that and let you know.

@crazy-max
Copy link
Member

@jyrkive, can you try the latest release ? Thx

@crazy-max
Copy link
Member

I have submit discord-portable.exe to Kaspersky for example and here is their response :

Hello,

Sorry, it was a false detection. It will be fixed.
Thank you for your help.

Sincerely yours,
Alexander Kolesnikov, Malware Analyst, Kaspersky Lab

39A/3 Leningradskoe Shosse, Moscow, 125212, Russia Tel./Fax: + 7 (495) 797 8700 http://www.kaspersky.com https://securelist.com

@jyrkive
Copy link
Author
jyrkive commented Nov 20, 2017

Thanks, it's much better now. :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Development

No branches or pull requests

2 participants