C
C#ā€¢12mo ago
Sheik

Windows Defender trojan alert after publish

Whenever I publish my project to a folder I get a Windows Defender warning about "Meterpreter!pz" I have built this solution multiple times before and only now is it throwing this this at me.
24 Replies
Jimmacle
Jimmacleā€¢12mo ago
your program happens to match heuristics for malware that doesn't mean it is, just that defender thinks it is
Sheik
SheikOPā€¢12mo ago
What could I do to circumvent this?
Jimmacle
Jimmacleā€¢12mo ago
i think there's a guy here on the defender team that might appreciate a sample of the false positive
Sheik
SheikOPā€¢12mo ago
That would be great
mtreit
mtreitā€¢12mo ago
@rtreit and @etreit both work on the Defender team, although I think they are on holiday break. But yes you should submit it as a false positive here: https://www.microsoft.com/en-us/wdsi/filesubmission
Submit a file for malware analysis - Microsoft Security Intelligence
Submit suspected malware or incorrectly detected files for analysis. Submitted files will be added to or removed from antimalware definitions based on the analysis results.
mtreit
mtreitā€¢12mo ago
If you report back the submission ID they might be able to give the submission a little nudge.
Sheik
SheikOPā€¢12mo ago
Looking into it What do you mean by this?
mtreit
mtreitā€¢12mo ago
When you submit the false positive it should give you back some kind of ID
etreit
etreitā€¢12mo ago
You should get a submission number back, if you toss it here we can take a look more easily
mtreit
mtreitā€¢12mo ago
Meterpreter!pz For once it's not wacatac Thonk
etreit
etreitā€¢12mo ago
Iā€™m afk but should be back home soon and can take a look, might be worth seeing if you can do an update, I think I remember something about a meterpreter detection that was having some false positives that was removed, but might still be on your machine. I can verify if that might be the case in a bit.
Sheik
SheikOPā€¢12mo ago
lol File upload failed - please try again. dd1d08fd-1132-4928-980b-9b7b6081003c Very much appreciated!
etreit
etreitā€¢12mo ago
Thank so much for giving us the submission number, I took a look at what was detecting it and it seems a bit wonky so putting some stuff into motion for someone to re-examine that. Sorry about this!
Sheik
SheikOPā€¢12mo ago
I'll add that this only happens in the release publish builds with Single File option. It does not get flagged if i build a release build and run it locally.
mtreit
mtreitā€¢12mo ago
What about debug?
Sheik
SheikOPā€¢12mo ago
You mean running it in IDE with debug, or compiling a debug and executing it?
mtreit
mtreitā€¢12mo ago
I meant publishing a debug build with single file Was just curious
Sheik
SheikOPā€¢12mo ago
Will try in about 15 minutes It also gets deleted, only non-published ones work
etreit
etreitā€¢12mo ago
We are disabling that detection and the change should be rolling out soon. Thanks a ton for sharing with us!
Sheik
SheikOPā€¢12mo ago
Glad to hear! Was actually worried that my files were just compleetely damaged
Petris
Petrisā€¢12mo ago
That's some quick response time, unlike Norton who still hasn't responded to a friend of mine after 2 years šŸ˜„ For future reference, usually if you have issues with AVs, the best way to avoid them is to get a code signing certificate
Jimmacle
Jimmacleā€¢12mo ago
i managed to get a false positive on my company's (not defender) AV by changing the color of an element in avalonia PepeLaugh
jcotton42
jcotton42ā€¢12mo ago
I think Norton exists just to collect money and spread misery
mtreit
mtreitā€¢12mo ago
Norton is terrible
Want results from more Discord servers?
Add your server