Ch4r0ne / ARK-Ascended-Server-Manager

ARK Survival Ascended Server Manager
MIT License
41 stars 5 forks source link

Executable of Server Manager gets detected as Trojan:Win32/Bearfoos.B!ml by Windows Defender. #3

Closed thantik closed 11 months ago

thantik commented 11 months ago

Had the .exe file deleted twice as I tried to figure out what was going on...

Ch4r0ne commented 11 months ago

I have never used the .exe, I am checking the facts. I have only run the .msi and .ps1 so far

Ch4r0ne commented 11 months ago

Did you also have this problem with earlier versions? I think it could be due to the backup button.

https://github.com/Ch4r0ne/ARK-Ascended-Server-Manager/releases/tag/1.0.1

Ch4r0ne commented 11 months ago

thank you very much for reporting this, i have put them all on pre release and will look for the problem for the false positif. if necessary, a function has to be deleted first. you will have no problems with version 1.0.1

thantik commented 11 months ago

Thanks. I wasn't concerned with it actually being anything malicious, as the PS1 file is easily readable and I can basically verify its contents myself. Just reporting it so that you didn't somehow get any flak from anyone who was inexperienced and develop any kind of trust issue within the community. :) Apparently this particular trojan has a lot of false positives among different programs out there, and the "ml" at the end denotes that it was picked up by a machine learning algo.

Ch4r0ne commented 11 months ago

I have now deleted the function again. Do you have any idea why this is classed as a Trojan? This is actually the best way to create a reliable backup. Sure, but Defender could also classify it as malicious. I can also include the code directly in the main script, then it will be visible, right?

https://github.com/Ch4r0ne/ARK-Ascended-Server-Manager/releases

thantik commented 11 months ago

I have no idea why it's being incorrectly flagged as a trojan. Just that it was on my machine. Windows Defender was flagging it as malicious, and automatically deleting it from my desktop. I'll see if it happens again in future releases.

thantik commented 11 months ago

Just checked the latest version and it's not getting flagged. So at least for now the problem seems to be resolved. I have seen some comments on various places online that you can submit the signature to Microsoft and have them somehow remove the false positive, but I have never gone through the procedure, so I am no help there.

darkstealth16 commented 6 months ago

Updating this thread: Current version appears to still trigger false positive on virus/trojan. I have gone through steps in windows to ignore the .exe so it does not delete it when turning on my server PC.