Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Newest download flagged as malware? #714

Open
theskiratta opened this issue Aug 15, 2024 · 3 comments
Open

Newest download flagged as malware? #714

theskiratta opened this issue Aug 15, 2024 · 3 comments

Comments

@theskiratta
Copy link

theskiratta commented Aug 15, 2024

When trying to use the newest version (3.0beta1), my Antivirus flagged the TypeTreeGenerator.exe as malware and removed it. A VirusTotal scan of the newest version yields a similar result.
What is up with this?

@ssokolow
Copy link

ssokolow commented Aug 27, 2024

If less than 10% of the scanners on VirusTotal (and especially if it's 6 or fewer) report a problem, it's 99% guaranteed to be the heuristic detection doing something like "The official download for NSIS looks like a virus because viruses do installer-y things and we haven't whitelisted that installer" or "You made a brand new self-extractor from known-clean data using a freshly installed copy of StuffIt for Windows off a professionally pressed CD-ROM on a known-clean system... but some virus used StuffIt compression with the "StuffIt Self-Extractor for Installers" mode to obfuscate itself at some point in the past, so your self-extractor must be a virus". (Both true stories.)

A single positive result out of VirusTotal's entire stable of scanners basically means "Ordinary file... but from someone without the clout to get it whitelisted".

Hell, when I was using the Kaspersky Rescue Disk on a PC a few days ago because I was concerned that someone might have run a version of the Unlocker installer that nearly half of VirusTotal claims installed adware, it found two results...

  1. A copy of either the the NSIS or Inno Setup (I forget which) build tooling which it defaulted to Skip (A.K.A. ignore) and flagged with green text saying "Has legitimate uses but can be abused by malicious people"
  2. A substitute dinput.dll in the folder for the Drakan: Order of the Flame level editor (probably from some compatibility patch for newer Windows) which, when fed into VirusTotal, gives two positives out of 66 scanners... from Cylance and Rising... neither of which is Kaspersky.

If enough scanners that actually tell you the name of the threat report a problem, you can confirm it's a heuristic false positive by looking for scanners reporting completely different threats for the same file with components like Gen or Heur in the threat names. See, for example, my StuffIt self-extractor link. (Is it adware? A trojan? Something else? ...yeah right. You're just freaking out because the StuffIt Self-Extractor Stub is compressed using UPX and you're too lazy to include an unpacker for it.)

@Kylix-Tyfurious
Copy link

Kylix-Tyfurious commented Sep 25, 2024

Chrome also blocked my download due to finding a virus as well as Windows Defender detecting it as a virus. Current as of 9/25/24

@Pysis868
Copy link

Pysis868 commented Jan 7, 2025

From AssetBundleExtractor_3.0beta1_64bit.zip, on 2022-04-25, commit hash 78ee37e.
Similar for AssetBundleExtractor_3.0beta1_32bit.zip.

URL: https://www.virustotal.com/gui/file/423f6774b299fad62d4f879a39671fc5c13c3245b682b647ed02cc568e1029a6
Filename: TypeTreeGenerator.exe
SHA256: 423f6774b299fad62d4f879a39671fc5c13c3245b682b647ed02cc568e1029a6
Size: 48.50 KB
Last Analysis Date: 14 days ago
Created: 2022-04-25

https://github.com/AhmedAhmedEG/Unity-Type-Tree-Generator/releases
Earliest v1.0.0.0 2023-10-09, too recent.

https://github.com/jrobinson3k1/typetree_unity
No releases.

https://github.com/mafaca/TypeTreeGenerator
No releases.

https://github.com/K0lb3/TypeTreeGenerator/releases
Only 2022-07-19, close.

Maybe most discussion in #479.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants