Ylianst / MeshCentral

A complete web-based remote monitoring and management web site. Once setup you can install agents and perform remote desktop session to devices on the local network or over the Internet.
https://meshcentral.com
Apache License 2.0
4.76k stars 627 forks source link

Attention: ESET Endpoint Security and ESET Security report virus #6784

Closed CSW2000 closed 1 month ago

CSW2000 commented 1 month ago

Caution: ESET Endpoint Security and ESET Security report a "ML/Augur.C" threat when creating/downloading from a Windows 64-bit agent But only with the 64Bit Windows Agent version / with ARM and 32 Bit Agent is this clean. As a test, I installed a fresh Meshcentral2 on a new Linux Mint LMDE 6 in Lan mode. - There is the same problem. Personally, I assume that this is a false report. – Will clarify this again with ESET SUPPORT. But it wouldn't be unwise if you could get in touch with ESET.

Image

My System : Raspberry 4/ 8 GB / SSD am USB Debian 12 RASPIAN / Node Version 22.11.0 / NPM Version 10.9.0 7 / MariaDB Version 10.11.3 / PHP 8.2.7 System is up-to-date, I don't know what to do right now I hope someone has a solution

si458 commented 1 month ago

Yep false positive Nothing we can do sadly Bad actors have abused the meshagent and meshcentral! Only thing u can try is purchasing a code-signing certificate yourself and signing it as ur own software Also make sure to customise it so the is no mention of meshcentral or meshagent anywhere

WingedSpur commented 3 weeks ago

I just lost the majority of my client agents due to this. ESET has flagged them all as Augur trojan.

CSW2000 commented 3 weeks ago

Hello, you can set an exception in ESET so that your Meshcentral Server is no longer recognized as a Trojan. The White Paper Links from ESET - Only in German.

https://support.eset.com/de/kb141-wie-ubermittle-ich-einen-virus-eine-websseite-oder-ein-false-positive-sample-an-das-eset-virenlabor

https://support.eset.com/en/kb6993

https://help.eset.com/ees/12/de-DE/idh_config_epfw_scan_http_address_list.html

But I think the problem has been solved in the latest version 1.41 - there is a new agent from Nov2024 :-)