DreymaR / BigBagKbdTrixPKL

"DreymaR's Big Bag of Keyboard Tricks" for Windows with EPKL
Other
326 stars 32 forks source link

McAfee detects trojan Artemis!E16CE83C5E8B #61

Closed Knochi closed 1 year ago

Knochi commented 1 year ago

Wanted to use on corporate machine and EKPL.exe was deleted.

DreymaR commented 1 year ago

As explained in the README, virus software has a nasty habit of being skittish towards compiled AHK code. I believe the reason is that AHK has been used to write trojans in the past. If you are truly worried, then consider the fact that all the EPKL code is freely viewable in this repo – it isn't as if I could've hidden anything malignant in there, hehe!

I sometimes have to temporarily disable my protection to allow compliation. As I understand it, your McAfee reacted to the already compiled program so that's unfortunate.

Maybe you can have your virus program make an exception for EPKL.exe, but on a corporate machine that'd likely require the cooperation of your IT department. I'd give them a link to the EPKL repo and tell them all my code is open source and freely inspectable, as is the AHK code itself. If they're an IT department worth their salt, they should know about AHK.

I have worked with Microsoft Defender in the past, submitting my code and getting it cleared of all suspicion. But then, a year later it was back to overreacting and I haven't been able to calm it down completely since that. So it appears there isn't a lot I can do about this problem? But if you wish, submit a ticket to McAfee about its erroneous detection.

Knochi commented 1 year ago

Ah ok, guess IT department will not help with this. So I guess i have to get a custom keyboard ;-)

DreymaR commented 1 year ago

I know, they're not always helpful. At my work computer, I use Hasu's QUICKIE device to get Colemak-CAWS with Extend. Zero chance of running anything unsanctioned on that machine.