Goz3rr / SatisfactorySaveEditor

294 stars 75 forks source link

Malwarebytes reports v0.5.0 as "MachineLearning/Anomalous.95%" #83

Closed EpicLPer closed 5 years ago

EpicLPer commented 5 years ago

I'm kinda amused right now that when you delete the v0.5.0 ZIP file and leave it there for Malwarebytes to scan it'll report it back as the above mentioned threat... Now I'm quite certain it's just a false positive but in case other people in the future will talk about this you're at least informed :) I've uploaded the ZIP itself to Virustotal and it came back totally clean. https://www.virustotal.com/#/file-analysis/YjdjZjA0NDQxMDI0MWFjODJmMTZjMGM3ZjAyMGFkNzM6MTU1NjcwNjk3MQ==

image

Just a headsup!

EDIT: Apparently Malwarebytes will also do it if you just scan it normally, tho for some strange reason Virustotal just won't show it...

mircearoata commented 5 years ago

It also happened to somebody using my build (with delete clones). The anomalous is because it is something unusual for its ML. Maybe send it as a false positive to malwarebytes to add it to its algorithm.

EpicLPer commented 5 years ago

It also happened to somebody using my build (with delete clones). The anomalous is because it is something unusual for its ML. Maybe send it as a false positive to malwarebytes to add it to its algorithm.

I've already made a thread on their forum about it: https://forums.malwarebytes.com/topic/246791-satisfactorysaveeditorexe-machinelearning-false-positive/

Goz3rr commented 5 years ago

Thanks for taking the effort of reporting it to malwarebytes, I see they replied that it should be fixed now. I suspect they just whitelisted us or something, so I'll wait with closing this issue until a new version is released and that doesn't trigger it again.

Goz3rr commented 5 years ago

From a quick test it seems that 0.5.1 is not detected for me