aardappel / procrastitracker

a Windows time tracking application
http://strlen.com/procrastitracker/
500 stars 53 forks source link

Procrastitracker is recognised as malware: Variant.Razy #20

Open tjhowse opened 7 years ago

tjhowse commented 7 years ago

Binary installer from website: https://www.metadefender.com/#!/results/file/ZTE2MTEwM0hrbXZUd1dPbGdCazR2cHYtT2dn/regular/analysis https://www.virustotal.com/en/file/5d4d6bda9640ca24d5ac36669b924853c60942af5edca6b51f6ed34367774ba9/analysis/1478133705/

Compiled from source: https://www.metadefender.com/#!/results/file/ZTE2MTEwM3JKelpmWVdkZ2VCSm1aekZaT3hs/regular/analysis https://www.virustotal.com/en/file/756b7d6b2227789bf831c62a178c61931584f848fe90e57a808c67ec48e0a931/analysis/1478134193/

Not sure what's giving these positives.

aardappel commented 7 years ago

And what you compiled from source is showing up on even more virus checkers? That means either it is a false positive (likely), or you yourself are infected :)

Many virus checkers give false positives rather easily with binaries that they don't see frequently.

tjhowse commented 7 years ago

I should note that Windows Defender on Win10 deletes the binary installer as soon as the download completes, making it difficult for people with up-to-date systems to install your software. I realise you're under no obligation to support your software; it's free after all, but I thought you'd like to know.

aardappel commented 7 years ago

I do support my software where I can, but I cannot control what MS and these antivirus companies do. There is nothing obvious I can change about the software to not make it have this effect.

AlisterH commented 5 years ago

FYI it is currently a "verified" threat according to Trend Micro: image

aardappel commented 5 years ago

I wonder what they considered "verified"..

I guess one issue is that if these companies scan the PT executable, they will find functions that install global mouse and keyboard hooks (which I use for time tracking and statistics), but are also used in keyloggers and spyware.

But yeah, no idea how to avoid this, and I have no time to go argue with all these companies in person. And they apparently don't have time to check my software in person.