Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Malware warning from Windows defender when attempting to upgrade to 3.9.3.0 #421

Open
odog8 opened this issue Apr 2, 2022 · 11 comments
Open
Labels
bug Something isn't working

Comments

@odog8
Copy link

odog8 commented Apr 2, 2022

Describe the bug

Windows defender detects malware in latest build of hakchi
To Reproduce

upgrade to 3.9.3
Expected behavior

no malware warning
Screenshots

Additional context

@odog8 odog8 added the bug Something isn't working label Apr 2, 2022
@DanTheMan827
Copy link
Member

Safe screen or actual malware detection?

@odog8
Copy link
Author

odog8 commented Apr 2, 2022

actual malware detection

@odog8
Copy link
Author

odog8 commented Apr 2, 2022

Probably a false positive but idk

@DanTheMan827
Copy link
Member

Weird, I just uploaded the installer and portable version to virus total and defender detected nothing

some other scanners detected Linux “malware”, but it probably confused hakchi with it

@turbocomppro
Copy link

Yup. Can't update from hakchi or download unless I turn off all the virus scanners.

@eugeneniemand
Copy link

I get this warning on Win 11
image

@DanTheMan827
Copy link
Member

Unfortunately, these kind of things just happen...

It's a case of antivirus thinking there's a virus based on who knows what factors... might by download count, might be that it isn't codesigned, and maybe it's just because it's coming from github

I've seen one antivirus detect it because some of the linux binary files used for the mod itself are UPX packed to save space

@russellweed
Copy link

russellweed commented Jun 17, 2022

I received the same warning on Windows 10 (fully updated), from either downloading the portable release off GitHub or using the built-in auto-updater.

image

Maybe just to be on the safe side you guys should make sure you haven't been compromised, either via dependencies or on your build machines?

@DanTheMan827
Copy link
Member

Which file inside of the archive does it detect?

@impeeza
Copy link

impeeza commented Nov 16, 2022

Unwanted program IS NOT MALWARE (VIRUS, TROJAN, RAMSOMWARE, etc.) is the way in which Microsoft tell you "you are downloading a program what I THINK you shouldn't use" in other words: The developer has not pay me lots of money for me do not scare the users and give you bad reputation.

So, you have two options: use a real antivirus, or use a net explorer to scan the file.
do not trust the people here and do not use the software.

@DanTheMan827
Copy link
Member

DanTheMan827 commented Nov 17, 2022

@impeeza Here's the thing, I can download the same file and none of my systems detect it...
image
It's probably caused by the updater triggering some behavior the antivirus doesn't like.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

6 participants