Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

uiforetw32.exe - detected as malicious by various antivirus engines #71

Closed
glenritchie opened this issue Feb 9, 2016 · 7 comments
Closed

Comments

@glenritchie
Copy link

Release v1.28 - https://github.com/google/UIforETW/releases/download/v1.28/etwpackage.zip

uiforetw32.exe is detected by (at the time of this post) 9 anti-virus engines as malicious.

See: https://www.virustotal.com/en/file/ef59759757396d329b9a2fd25fef83c58ffe49a6004baa4b49bcc8ab0dffbd71/analysis/

@randomascii
Copy link
Contributor

Well that's unfortunate. Any idea why? My guess is that it's just a false positive, but if the binary is corrupted that would be pretty bad.

At least it's only the 32-bit version, which virtually nobody should be using anyway.

@ariccio
Copy link
Contributor

ariccio commented Feb 9, 2016

It's up to twelve now... huh? The 64 bit executable has two detections.

@randomascii just for safety, maybe you should run a full system antimalware scan? I'll do so later tonight. I don't expect to find anything, but at least it's a good excuse for a full system scan.

@glenritchie
Copy link
Author

I've submitted it to Bitdefender for review, my version quarantined it when I downloaded it, I'll let you know what they reply with if I get a response.

@glenritchie
Copy link
Author

No longer detected by Bitdefender but still showing malicious by 5 anti-virus engines ( McAfee being the most well known).

Perhaps add a notice to the releases page letting people know it could be a false positive?

@randomascii
Copy link
Contributor

I added a note to the latest release, linking to this issue.

@snowkoan
Copy link

You might try signing your release binaries. These days, no signature is a warning sign for anti-malware engines.

@randomascii
Copy link
Contributor

Binaries are signed now. Virustotal now gives UIforETW.exe a clean bill of health - 0/60. UIforETW32.exe gets a score of 0/60 also. Closing as fixed?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants