ReVanced / GmsCore

Free implementation of Play Services
https://microg.org
Apache License 2.0
1.75k stars 79 forks source link

VirusTotal Sandbox - MALWARE TROJAN EVADER #58

Closed michalpl7 closed 2 months ago

michalpl7 commented 2 months ago

Hello, do You know why VirusTotal triggers such alert with Your new GMS Core - "MALWARE TROJAN EVADER".

Here is link: [https://www.virustotal.com/gui/file/68ea7a4fc95fcb81cb1c1278c11c8da8caba5608ecefb6142461c668282a0545/behavior]

Old version microG was clean of that alert: [https://www.virustotal.com/gui/file/e5ce4f9759d3e70ac479bf2d0707efe5a42fca8513cf387de583b8659dbfbbbf/behavior]

I guess it's false positive but it's a little confusing.

LisoUseInAIKyrios commented 2 months ago

Where did you download that GmsCore apk from?

Because using that virus scan site with the current release from here on GitHub shows no issues:

https://www.virustotal.com/gui/file/68ea7a4fc95fcb81cb1c1278c11c8da8caba5608ecefb6142461c668282a0545/detection

michalpl7 commented 2 months ago

Where did you download that GmsCore apk from?

Because using that virus scan site with the current release from here on GitHub shows no issues:

https://www.virustotal.com/gui/file/68ea7a4fc95fcb81cb1c1278c11c8da8caba5608ecefb6142461c668282a0545/detection

From this github website :) click on "Behaviour" - Sandbox.

LisoUseInAIKyrios commented 2 months ago

Oh I see. Yes it must be a false positive.

Scanning the upstream MicroG release shows the same warnings:

https://www.virustotal.com/gui/file/1a6f6205d82c5075f1789cfc92924e5ea9b648b7397e9f667959ac4d956cb3f5/behavior

michalpl7 commented 2 months ago

Oh I see. Yes it must be a false positive.

Scanning the upstream MicroG release shows the same warnings:

https://www.virustotal.com/gui/file/1a6f6205d82c5075f1789cfc92924e5ea9b648b7397e9f667959ac4d956cb3f5/behavior

I don't know what is upstream MicroG but version which I used for very long time was free of that alert and was working perfectly I posted it as second VT link.

oSumAtrIX commented 2 months ago

Both the release pipeline and the source code are transparent on GitHub. This is an issue with Virus total and co.