doug-101 / ConvertAll-py

a flexible unit converter
http://convertall.bellz.org
39 stars 15 forks source link

convertall-0.8.0-install-all.exe flagged by AV due to Trojan #21

Open christophermichaelshaw opened 2 years ago

christophermichaelshaw commented 2 years ago

Doug,

I sent you an email about this issue but wanted to flag it on GH as an issue as well:

Doug,

I have a client that utilizes ConvertAll in his daily workflow, and has encountered difficulties recently due to Webroot Secure Anywhere antivirus software quarantining the C:\Program Files\ConvertAll\CONVERTALL.exe due to a detected Trojan.

image

I've run both the all users and single user installers through https://www.virustotal.com/ and it appears the all users installer does indeed contain a trojan. The single user installer does not.

image

Just wanted to send over a heads up as your web host file repository may have been compromised.

doug-101 commented 2 years ago

These trojan warnings are almost always false positives. The python libraries and the tools that create the executables and installers tend to leave a specific signature, regardless of what the python code actually does. When an actual trojan is written using same tools, some antivirus software flags all applications that have a similar signature. I'm not sure about virustotal, but most antivirus companies allow you to submit software for a closer look, so they will remove the false positive.

Just to be safe, I checked several things:

Thanks, Doug