decalage2 / exefilter

ExeFilter is an open-source tool and framework to filter file formats in e-mails, web pages or files. It detects many common file formats and can remove active content (scripts, macros, etc) according to a configurable policy.
http://www.decalage.info/exefilter
Other
65 stars 28 forks source link

ExeFilter incorrectly flagged as malware #7

Open decalage2 opened 2 years ago

decalage2 commented 2 years ago

It looks like some antivirus are now flagging ExeFilter releases (and even the master zip from the github repo) as malware. It is obviously a false positive, and I guess it's due to some test files bundled with ExeFilter. Solution: remove test files, or zip them with a password.

Virustotal is currently OK with the master zip from github (but my corporate AV blocks it): https://www.virustotal.com/gui/url/1bd6773a63c33e984ea75642a60986b84c4005325f805662c725be34ea844909?nocache=1 But the latest release from 2011 on Adullact triggers some AV: https://www.virustotal.com/gui/url/86504856a9901133a900ecc706a37213d0de28e527ac7af1f1c1ae80c2a2dd9a image

decalage2 commented 2 years ago

Some references explaining why helloworld programs are flagged as malware: