AveYo / fox

Firefox stuff
725 stars 69 forks source link

Defender flags ChrEdgeFkOff as trojan: Wacatac.h!ml #16

Closed dgriffith0 closed 2 years ago

dgriffith0 commented 2 years ago

Window 11 defender is flagging the ChrEdgeFkOff as trojan Wacatac.h!ml after running and then removes it breaking the search.

AveYo commented 2 years ago

Yeah this just started. An automated false-positive detection.
I already did the best I could few months ago to tame Defender and worked so far ;(
What's left for me to do is probably to have a cmd window briefly shown, which is an annoyance.
What you can do is to report a False Positive to microsoft: https://www.microsoft.com/en-us/wdsi/filesubmission

AveYo commented 2 years ago

Pushed an update with a pure batch version. So the command window will briefly flash when doing searches 👎
Let's see if it's just Defender being dumber than a rock, or it's also malicious intent, specifically targeting the redirector.

AveYo commented 2 years ago

Command window flashing no more 🥇

akuropka commented 2 years ago

@AveYo, trying to download the github ZIP leads to detection of the supposed trojan: 20221004_125731 20221004_125715_ApplicationFrameHost

AveYo commented 2 years ago

It's obviously a false-positive.
Download the script you need directly i.e. view OpenWebSearch.cmd - Raw - Save As. Can also just copy the text directly into a powershell window.

akuropka commented 2 years ago

Yeah, that works of course. I was just getting the impression the issue may have been resolved that's why I noted this.

AveYo commented 2 years ago

Defender is a simpleton.