FrankBijnen / ExifToolGui

A GUI for ExifTool
GNU General Public License v3.0
233 stars 12 forks source link

Getting "Virus detected" when downloading ExifToolGUI installer from Chrome, prevents download #433

Open alelom opened 1 month ago

alelom commented 1 month ago

See:

image

This prevents download of the installer.

Chrome Version 125.0.6422.113 (Official Build) (64-bit) Windows 10

Firefox is instead able to download without issues.

FrankBijnen commented 1 month ago

Thanx for the info. Alas I'm able to change Chrome. Maybe you can report it to Chrome?

V632 has been downloaded 1500+ times by now, highly unlikely that it contains a virus.

alelom commented 1 month ago

Hey, no probs.

I think the right place to report is the owner's repo because:

FrankBijnen commented 1 month ago

I agree that posting here is a good idea.

I dont agree that the installer of GUI should be changed. The installer is created with InnoSetup using this sourcecode; https://github.com/FrankBijnen/ExifToolGui/blob/main/Redist/ExifToolGUI_install.iss Lots of installers are created by InnoSetup, and many AV's report false positives. To put it in other words: I wouldn't know what to change. I think it works best if many people report false positives to Google Chrome.

Edit: It is Windows Defender that reports that there's a virus.

FrankBijnen commented 1 month ago

Meanwhile reported to MS. afbeelding

FrankBijnen commented 1 month ago

@alelom

Could you please try again?

I updated my definitions, and did not get a virus warning when I tried again. Maybe reporting to MS did help?

ColmanPerkins-Stephen commented 1 month ago

VirusTotal is reporting 2 vendors flagging the exe: https://www.virustotal.com/gui/file/197e4197778442e531183a5087a4d4a42eed87cd968eb9ab70f4009f86e11fa2?nocache=1

FrankBijnen commented 1 month ago

@ColmanPerkins-Stephen

Thanks. What can I say? I dont consider it alarming, but that's my opinion.

ColmanPerkins-Stephen commented 1 month ago

@ColmanPerkins-Stephen

Thanks. What can I say? I dont consider it alarming, but that's my opinion.

Agreed, just adding my 2 cents. I added a community note to the VT hash page also.

PaulCoddington commented 1 month ago

Currently being blocked and quarantined by Windows Defender with MS Edge (Trojan:Win32/Wacatac.H!ml).

Looks spurious, will give it a bit of time for signature updates to come through.

FrankBijnen commented 1 month ago

@PaulCoddington

Same here.

Downloading with Edge results in: Trojan:Win32/Wacatac.H!ml Downloading with Chrome results in: Trojan:Win32/QQPass

Previously it was: Trojan:Win32/Vigorf.A

MS cant seem to make up their mind!

PaulCoddington commented 2 weeks ago

v6.3.3 installer had no problems until today, but this evening Defender has started flagging my backup copy of the installer (PUA:Win32/Puwaders.C!ml).

FrankBijnen commented 2 weeks ago

@PaulCoddington

Tried to reproduce it, by first updating virus definitions, downloading via Chrome, and executing installer with all options. No problems so far here. But that doesn't mean they will not appear sometime.

I fear it will be a 'cat and mouse game'. Eventually I might give in and postpone this project.

Philshappy commented 2 weeks ago

Since the portable version doesn't appear to have this issue would it be possible to continue with the portable version. This tool is so valuable it would be sad not to continue it.

FrankBijnen commented 2 weeks ago

Thanks for your high opinion.

I'm just postponing not abandoning.

It may help if lots of people report this as a false positive to MS.