Downloading the installer with Google Chrome reports 'Virus Detected'

Started by FrankB, June 02, 2024, 05:16:46 AM

Previous topic - Next topic

FrankB

It has been reported that Downloading GUI with Google Chrome fails with 'Virus Detected'. Downloading with FireFox works fine.

Does anyone know how to succesfully report 'false positives' to Google? Your input is welcome.

See also:
https://github.com/FrankBijnen/ExifToolGui/issues/433

Edit: Same happens when downloading via Edge. It looks like Microsoft Defender reports V632 as a virus, V631 is reported safe.

FrankB

The installer 'ExifToolui_install_6.3.2.0.exe' was reported to MS as 'false positive'. I'm still awaiting a definitive answer, but meanwhile downloading via Chrome no longer reports 'Virus Detected'.

FrankB


obetz

Defender reports "Trojan:Win32/Wacatac.H!ml" Published Mar 09, 2022. Signature based detection is error prone... It might be sufficient to create a new installer with minor changes.

Edit: No, this might be not sufficient since many of the contained files get positive reports at virustotal, e.g. ExifToolGui_X64.PTB and more. So it's not necessarily an InnoSetup issue.

FrankB

@obetz

I think you're right. I considered changing the compression from lzma to zip. That would help for a while. But I fear it would be a cat and mouse game.

Another thing I noticed. The language Dll for win32 Chinese is now also considered a virus.

To be continued

FrankB

Trying to solve the virus reports I have just released V6.3.3. The installer is now zip compressed in stead of lzma2
Also 2 small bugfixes included.

Let's see how long it lasts...

FrankB

It lasted for 2 weeks. Now MS Defender reports: Trojan:Win32/Wacatac.B!ml

Postponing development on the project until this is settled. Will continue to answer your questions.

Frank