cDima / Aerial

Aerial Apple TV screen saver for Windows
1.97k stars 180 forks source link

Malware Detected!!! #25

Closed evonbart closed 8 years ago

evonbart commented 8 years ago

Every time I click the link to download the .ZIP, I get a Malware detected message through windows and it deletes the file. Shame because on my MAC they look amazing. image

PatrickRoethlisberger commented 8 years ago

Same here. Detected: Artemis!E631ADC94B18

evonbart commented 8 years ago

Mwahhh mwahhhhh mwahhhhhhhhhh (sad trombone)

PatrickRoethlisberger commented 8 years ago

Duplicate #9

alistairmcmillan commented 8 years ago

@evonbart Try the 0.2 release. According to this BitDefender doesn't flag it as malware.

https://www.virustotal.com/en/file/72802e9b6b58109a1065ea35daab46f93f5ab655c9835b5a5f86f8618a8516ec/analysis/

dpkg commented 8 years ago

not sure about BitDefender, but Windows10 still identifies it (release 0.2) as malware.

cDima commented 8 years ago

Can you retry the 0.2 release? It was updated yesterday and file size was changed. Perhaps Windows defector definition files were falsy on the old file size?

viktorx11 commented 8 years ago

0.2 release, windows 10, avira says there is an TR/Agent.584192.30 inside :-\

alistairmcmillan commented 8 years ago

@cDima You can submit your screensaver to VirusTotal to see how it'll be detected.

The current 0.2 is identified as by 13 out of 54 as something malicious. https://www.virustotal.com/en/file/bc91eea135921f396eca0be2f8c19f090ceb228e248fb822655be66fd8d6d50b/analysis/

:(

cDima commented 8 years ago

Perhaps signing it with a certificate would help, this is getting ridiculous.

Dmitry Sadakov http://sadakov.com

On Nov 16, 2015, at 4:19 AM, Alistair McMillan notifications@github.com wrote:

@cDima You can submit your screensaver to VirusTotal to see how it'll be detected.

The current 0.2 is identified as by 13 out of 54 as something malicious. https://www.virustotal.com/en/file/bc91eea135921f396eca0be2f8c19f090ceb228e248fb822655be66fd8d6d50b/analysis/

:(

— Reply to this email directly or view it on GitHub.

alistairmcmillan commented 8 years ago

@cDima Yup. I've been playing about with one of my own. Trying to figure out what triggers the malware heuristics. I've created the simplest screensaver ever, it just makes the screen black and does nothing else. Nothing!!! And 1 out of 54 vendors still think it's a piece of malware.

Signing was something I was going to try next.

cDima commented 8 years ago

Seems like there's nothing perpetually free for open source projects, epic fail. Perhaps we should make a "Top 20 Worst Antiviruses" hit-list?

Dmitry Sadakov +164648531955 | http://sadakov.com

On Nov 16, 2015, at 8:43 AM, Alistair McMillan notifications@github.com wrote:

@cDima Yup. I've been playing about with one of my own. Trying to figure out what triggers the malware heuristics. I've created the simplest screensaver ever, it just makes the screen black and does nothing else. Nothing!!! And 1 out of 54 vendors still think it's a piece of malware.

Signing was something I was going to try next.

— Reply to this email directly or view it on GitHub.

kamargo commented 8 years ago

Try downloading the ZIP instead of the SCR, It worked for me. Running Windows 10 and Bitdefender

krohn commented 8 years ago

Same issue here. Avira reports TR/Agent.584192.30 (Avira Virusdefinitionfile v7.12.30.16/20.11.2015)

Opened a ticket at http://analysis.avira.com/samples/index.php and asked to check for a false positive. I'll report as soon as I have a response.

cDima commented 8 years ago

Thank you Karsten! The only other option is to sign the screensaver with a <$100 certificate, but it can't be opensource nor maintained by others.

On Fri, Nov 20, 2015 at 9:16 AM, Karsten Krohn notifications@github.com wrote:

Same issue here. Avira reports TR/Agent.584192.30 (Avira Virusdefinitionfile v7.12.30.16/20.11.2015)

Opened a ticket at http://analysis.avira.com/samples/index.php and asked to check for a false positive. I'll report as soon as I have a response.

— Reply to this email directly or view it on GitHub https://github.com/cDima/Aerial/issues/25#issuecomment-158412608.

Dmitry Sadakov Consultant – Web Technology | Gemini Systems | A&M | 600 Madison Ave| New York, NY | Mobile +16468531955 sadakov.com | linkedin http://linkedin.com/in/sadakov | stackoverflow http://stackoverflow.com/users/82054/cdima | github https://github.com/cDima | g+ http://www.google.com/profiles/sadakov | facebook https://www.facebook.com/sadakov | vk http://vk.com/sadakov | skype:dmitry.sadakov

krohn commented 8 years ago

Feedback from Avira: False positive for aerial.scr.zip (MD5 = 09c023e796bf57ef8ba541b33d30b570):

https://analysis.avira.com/en/status?uniqueid=QSPO2qybQhwkYtJJtMW6UU5bFTwH8tPW&incidentid=1951688