google / UIforETW

User interface for recording and managing ETW traces
https://randomascii.wordpress.com/2015/04/14/uiforetw-windows-performance-made-easier/
Apache License 2.0
1.55k stars 201 forks source link

uiforetw32.exe - detected as malicious by various antivirus engines #71

Closed glenritchie closed 7 years ago

glenritchie commented 8 years ago

Release v1.28 - https://github.com/google/UIforETW/releases/download/v1.28/etwpackage.zip

uiforetw32.exe is detected by (at the time of this post) 9 anti-virus engines as malicious.

See: https://www.virustotal.com/en/file/ef59759757396d329b9a2fd25fef83c58ffe49a6004baa4b49bcc8ab0dffbd71/analysis/

randomascii commented 8 years ago

Well that's unfortunate. Any idea why? My guess is that it's just a false positive, but if the binary is corrupted that would be pretty bad.

At least it's only the 32-bit version, which virtually nobody should be using anyway.

ariccio commented 8 years ago

It's up to twelve now... huh? The 64 bit executable has two detections.

@randomascii just for safety, maybe you should run a full system antimalware scan? I'll do so later tonight. I don't expect to find anything, but at least it's a good excuse for a full system scan.

glenritchie commented 8 years ago

I've submitted it to Bitdefender for review, my version quarantined it when I downloaded it, I'll let you know what they reply with if I get a response.

glenritchie commented 8 years ago

No longer detected by Bitdefender but still showing malicious by 5 anti-virus engines ( McAfee being the most well known).

Perhaps add a notice to the releases page letting people know it could be a false positive?

randomascii commented 8 years ago

I added a note to the latest release, linking to this issue.

snowkoan commented 8 years ago

You might try signing your release binaries. These days, no signature is a warning sign for anti-malware engines.

randomascii commented 7 years ago

Binaries are signed now. Virustotal now gives UIforETW.exe a clean bill of health - 0/60. UIforETW32.exe gets a score of 0/60 also. Closing as fixed?