gibaBR / Switch-Backup-Manager

Complete Switch Backups management tool
372 stars 54 forks source link

WIndows 10 Error 0x800700E1: Defender detects "unwanted software/virus" #33

Closed GuyInDogSuit closed 5 years ago

GuyInDogSuit commented 5 years ago

I tried to unzip this and get the message, "Error 0x800700E1: Operation did not complete successfully because the file contains a virus or potentially unwanted software." Latest build.

digiwombat commented 5 years ago

Same issue on my machine.

The virus it's detecting has been out since 2016 which would make it pretty easy to detect generally.

Windows Defender and AhnLab are the only two who have a problem with the file.

AhnLab calls it "Win32.GameTool.R232654" which I'm maybe is some popup ad malware that shipped with CheatEngine? No idea. It dates to 2015.

Almost a guaranteed positive, though definitely worth trying to figure out why it's getting flagged as two unrelated viruses.

Virus Total: https://www.virustotal.com/#/file/26bb4b2c9678d659444d591938faf19981fedf0dfaccd3097247134c661ab4cf/detection

garoxas commented 5 years ago

even with me building from source code, Kaspersky also detects it as HEUR:Trojan.Win32.Generic, so pretty sure it's false positive maybe because there's a logic to run hactool as hidden process possible workaround is to either show hactool window while it's running (ugly) or to port hactool code directly in the app

gibaBR commented 5 years ago

I think it's because I use NuGet called "costura". It embeeds some dlls used by the application into the .EXE file.

wantonpick commented 5 years ago

This is still an issue, it may be a false positive, but the number of AV that are detecting it is only growing - last I was able to check was somewhere around 8-12 vendors. I can't even unzip the file to upload to virustotal.com anymore, even when I disable all user facing AV controls. I'm not going to try and bypass it further via safe mode. If you could investigate ways to mitigate this, or clear it altogether that would be appreciated.

The virus detected is also different, now gen:Variant.Razy.394367