Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

AV False Positives (Malware, Riskware, Adware, Virus, Trojan and other BS) #27

Open
neoOpus opened this issue Aug 11, 2023 · 58 comments
Open

Comments

@neoOpus
Copy link
Contributor

neoOpus commented Aug 11, 2023

After reinstalling Windows and configuring Bluetooth, MS Defender removed it after identifying it as malware (I didn't have time to add it to a whitelist)

Please figure out why it's happening and get it signed now. Even if it's free, some people might not like using it because it might scare them or be taken off their computers.

Screenshot 2023-08-11 102854
image

@neoOpus
Copy link
Contributor Author

neoOpus commented Aug 11, 2023

I am unable to download it unless, of course, if I disable MS Defender

image

@aloneguid
Copy link
Owner

aloneguid commented Aug 11, 2023

I can't afford a signing certificate so it's not going to happen. You are free to validate it's not dangerous as source code and build pipelines are completely open and transparent.

@corvus2606
Copy link

I can't afford a signing certificate so it's not going to happen. You are free to validate it's not dangerous as source code and build pipelines are completely open and transparent.

What is the cost of a signing certificate?

@aloneguid
Copy link
Owner

It's about $1.5k for 3 years. Could be less if you shop around. But that won't solve false AV issues, you can still be banned and certificate revoked for no reason. I think realistically one needs a legal team to deal with AV false claims which I apparently don't have. I'd recommend having a read:

And by the way, the last BT version (3.5.0) has only a single AV's claim out of 90, unlike 29 out of 90 for version 3.4.0, so it's totally random trash. I've myself became very pessimistic about usefulness of AV software in general after dealing with this.

@aloneguid aloneguid reopened this Aug 24, 2023
@aloneguid aloneguid changed the title Again detected as Malware AV False Positives (Malware, Riskware, Adware, Virus, Trojan and other BS) Aug 24, 2023
@paz
Copy link

paz commented Sep 10, 2023

Kaspersky and Sophos both left BT undetected for me, seems it might be a Microsoft specific issue.

@aloneguid
Copy link
Owner

it's totally random and changes daily ;)

@GavinFarrington
Copy link

Windows Defender (Win 11) just flagged bt-3.5.2 as "threats found" for me.

Detected: Program:Win32/Wacapew.C!ml

@jnv
Copy link

jnv commented Sep 15, 2023

Same thing here, BT 3.5.2 was flagged by Microsoft Defender as PUA. It's possible to send files to Microsoft for further analysis: https://www.microsoft.com/en-us/wdsi/filesubmission/ – I urge you to do it if you are affected.

@aloneguid aloneguid pinned this issue Sep 15, 2023
@aloneguid
Copy link
Owner

Same thing here, BT 3.5.2 was flagged by Microsoft Defender as PUA. It's possible to send files to Microsoft for further analysis: https://www.microsoft.com/en-us/wdsi/filesubmission/ – I urge you to do it if you are affected.

I have used this before, and just submitting for latest version as "incorrectly identified as malware". Will let you know on progress:
image

@aloneguid
Copy link
Owner

Analysis on above is still pending but some detections have already cleared out.

@neoOpus
Copy link
Contributor Author

neoOpus commented Sep 18, 2023

It keeps getting deleted even when excluded from scans... I have to reinstall it every few days.

@CityguyUSA
Copy link

There are 2 different .zip files. A pdb version which downloads fine and non-pdb version that doesn't. What's the difference between the 2?

@aloneguid
Copy link
Owner

There are 2 different .zip files. A pdb version which downloads fine and non-pdb version that doesn't. What's the difference between the 2?

.pdb version is debug symbols to investigate crashes, you don't need that.

@aloneguid
Copy link
Owner

It keeps getting deleted even when excluded from scans... I have to reinstall it every few days.

You can permanently allow the "threat" until MS investigates. There are instructions available here.

@aloneguid
Copy link
Owner

Windows Defender should now be fine, just got analysis results from Microsoft:

image

@aloneguid
Copy link
Owner

Also VirusTotal before and after (Microsoft AV is OK now). Hopefully others will follow the suit.

image

image

@neoOpus
Copy link
Contributor Author

neoOpus commented Sep 19, 2023

It keeps getting deleted even when excluded from scans... I have to reinstall it every few days.

You can permanently allow the "threat" until MS investigates. There are instructions available here.

I have been doing that since the start, but it doesn't stick. That's why I notified you that currently it is allowed and working properly, but it crashes when trying to find updates... I am simply informing you of this, but it is alright if you are unable to resolve these.

@aloneguid
Copy link
Owner

@neoOpus thanks. Update checks are already fixed and will be out in v3.6. Defender does not block it anymore.

@jnv
Copy link

jnv commented Sep 20, 2023

By the way, I reported the false positive to Avast (which also includes AVG), so VT now reports only 11 false positives.

According to their reply, they reclassified BT from malware to PUA, since apparently it doesn't match their "clean software policy" (which, surprisingly, claims signing is preferred but not required):

Thank you for contacting Avast and reporting a false positive detection. We're happy to help.

Along with the Avast virus specialist, we’ve checked the reported file and changed the threat detection to PUP (potentially unwanted program). The PUP detection is due to lack of compliance with Avast’s clean software policy.

For more information, refer to this article: Avast Threat Labs - Clean guidelines

If you are the owner of the reported file and want to change the detection to clean, feel free to contact us again for a new analysis as soon as the file matches the Avast guidelines.

@aloneguid
Copy link
Owner

@jnv thanks for that, I also raised request with ESET which has reclassified as clean.

@aloneguid
Copy link
Owner

aloneguid commented Sep 20, 2023

@jnv I have raised Avast issue separately yesterday, and classification is cleared completely.

image

@aloneguid
Copy link
Owner

Also submitted a dispute to McAfee now.

@aloneguid
Copy link
Owner

And just for fun to Malwarebytes.

@neoOpus
Copy link
Contributor Author

neoOpus commented Sep 23, 2023

So far, it worked and I didn't have any issue :)

@jnv
Copy link

jnv commented Oct 31, 2023

Unfortunately we're back to 24 false positives for the v3.6.2 installer. Today even Microsoft Defender took down my locally compiled version.

@aloneguid
Copy link
Owner

aloneguid commented Oct 31, 2023 via email

@aloneguid
Copy link
Owner

14/61 today!

image

@cheTesta
Copy link

cheTesta commented Nov 6, 2023

image
18 on the .zip version

@aloneguid
Copy link
Owner

Down to 11 today:

image

@aloneguid
Copy link
Owner

image 18 on the .zip version

Down to 15 today. ZIP is catching up, as I'm submitting false positives for MSI only, which contains the same binary as zip.

@aloneguid
Copy link
Owner

10 today.

@eiqnepm
Copy link

eiqnepm commented Feb 21, 2024

It seems Microsoft doesn't like the latest version as it has been automatically removed from my PC by Windows Defender.

@aloneguid
Copy link
Owner

Same here, looks like Microsoft needs a ticket for every new version to allowlist it again.

@aloneguid
Copy link
Owner

Also this is odd, because VirusTotal only reports 4 hits from "bad" AVs

image

@Ultrafeel
Copy link

I think if it was in Dotnet or other IL language it wouldn't have so many troubles. Because it is much easier to analyze than pure x86 instruction set.

@aloneguid
Copy link
Owner

Yeah, but it would be also super slow and at least x100 bigger in size of downloads and ram.

@mahoromax
Copy link

mahoromax commented Feb 23, 2024

It seems Microsoft doesn't like the latest version as it has been automatically removed from my PC by Windows Defender.

Not only the latest, also 1 or 2 previous - it broke, I installed newer one (deactivated the antivir) but at some point it reactivated... It actually breaks opening links if BT is set as default handle for hyperlinks. Typical Microsoft -.-

Can we whitelist it manually? Or do we need to do that for every version as well?

Edit: Going into the defender history and reverting + adding a manual entry for C:\Program Files\Browser Tamer\bt.exe seems to work - for now. No resetting of default browser or anything needed.

@Ultrafeel
Copy link

Yeah, but it would be also super slow and at least x100 bigger in size of downloads and ram.

Is https://github.com/mortenn/BrowserPicker , for example, slow and bloated for you?

@Ultrafeel
Copy link

From what I understand from this talk about Windows - BlueHat IL 2023 - David Weston - Default Security
https://www.youtube.com/watch?v=8T6ClX-y2AE : maybe turning in UWP and converting msi to MSIX can make help against AV 🤓. One of the issues was mentioned is "over privileged apps".

@dmocha
Copy link

dmocha commented Jul 26, 2024

I downloaded version 4.0.2 today
Viirus total shows a result of 21/73
https://www.virustotal.com/gui/file/68d876a6afb7d9bef7b1b1e1ebe32eea68ce7bd83f4c56c216cc25c0a90e3d4a
It's starting to make you think
:(

@aloneguid
Copy link
Owner

Please finish your thought ;)

@eiqnepm
Copy link

eiqnepm commented Jul 26, 2024

I downloaded version 4.0.2 today Viirus total shows a result of 21/73 https://www.virustotal.com/gui/file/68d876a6afb7d9bef7b1b1e1ebe32eea68ce7bd83f4c56c216cc25c0a90e3d4a It's starting to make you think :(

Browser Tamer by design needs to intercept links to work, this sometimes sets off the real time behavioral analysis of AV engines, when triggered most AVs will decided if it's malware based on reputation and manual review, obviously Browser Tamer is a small project with not a lot of users in the grand scheme of things, so the reputation is going to be low. Microsoft has already whitelisted versions of Browser Tamer after being submitted for manual review.

Browser Tamer releases are built using GitHub Actions, and of course you can build it yourself too.

@dmocha
Copy link

dmocha commented Jul 28, 2024

Please finish your thought ;)

I choose consciously and accept the possible risks, but others, seeing the scale, may give up at the very beginning

@aloneguid
Copy link
Owner

Latest build has 2 warnings instead of 21, so it's totally random

image

@aloneguid
Copy link
Owner

If anyone knows how to contact "Sangfor" (chinese company) to submit false positive report please let me know.

@dmocha
Copy link

dmocha commented Sep 5, 2024

Have you tried using the website: https://www.sangfor.com/about-us/contact-us
?
I'll add right away that I just looked it up on the Internet, I haven't used it myself

@aloneguid
Copy link
Owner

Thanks @dmocha, trying this one.

@aloneguid
Copy link
Owner

Unfortunately that didn't work - no response for a week or so. However, after a lot of comms with various AV providers I have managed to reduct VT to only 1 (Sangfor):

image

@neoOpus
Copy link
Contributor Author

neoOpus commented Sep 11, 2024

Unfortunately that didn't work - no response for a week or so. However, after a lot of comms with various AV providers I have managed to reduct VT to only 1 (Sangfor):

image

Maybe they will be more responsive if you contact them via their social media (https://x.com/SANGFOR)

@aloneguid
Copy link
Owner

@neoOpus seems like you have to be a premium user to contact them in the eX-twitter.

@neoOpus
Copy link
Contributor Author

neoOpus commented Sep 13, 2024

I tried but maybe it is just like you said... I will keep you updated if they reply

@aloneguid
Copy link
Owner

this is THE FIRST TIME we have ZERO virus detections! I'm not sure what you did @neoOpus but it seems to have worked!

image

@dmocha
Copy link

dmocha commented Oct 3, 2024

👍
Indeed, the bt-4.1.2.zip archive is "clean".
I just checked this archive

Now it would be useful to do the same with the bt.exe file

Because the file sent to VT indicates two threats:

2024-10-03 20 56 48 www virustotal com 943cbbbd2956
Link:
https://www.virustotal.com/gui/file/7908c83bdbf21dc49c9f8f8b644cec36f806d65b57792eb54faeb97c3d3c7cb4?nocache=1

@aloneguid
Copy link
Owner

@dmocha only Chinese AV companies seems to complain ;)

@aloneguid
Copy link
Owner

4.2.0

image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests