jefoce / xmi

XMI Watch - Official Repository
https://jefoce.github.io/xmi
21 stars 2 forks source link

Windows defender warns of Trojan #1

Open JtxGit opened 3 years ago

JtxGit commented 3 years ago

What exactly causes Windows Defender to warn about a Trojan? (MSIL/FareitLoader!MTB)

jefoce commented 3 years ago

What exactly causes Windows Defender to warn about a Trojan? (MSIL/FareitLoader!MTB)

I don't know, my program haven't any trojans or viruses. And my defender found today..

JtxGit commented 3 years ago

Hope you can find the reason and fix it...

NamyX commented 3 years ago

Hope you can find the reason and fix it...

Is there any update on this bug? I got same issue

CingYan commented 3 years ago

Me too, i got sam issue here is report, hope can help you

Trojan:MSIL/FareitLoader!MTB

Affected items: file: C:\Users(username)\Downloads\xmi.zip webfile: C:\Users(username)\Downloads\xmi.zip|https://github-releases.githubusercontent.com/312902742/931ae100-3fa8-11eb-97a7-a5ff68f6e5bb?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAIWNJYAX4CSVEH53A%2F20210227%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20210227T164040Z&X-Amz-Expires=300&X-Amz-Signature=654d0432d6bee2b4b39be2b716088d9bf9f5049c5c5cdc9cbc555edd1cbb7064&X-Amz-SignedHeaders=host&actor_id=30778297&key_id=0&repo_id=312902742&response-content-disposition=attachment%3B%20filename%3Dxmi.zip&response-content-type=application%2Foctet-stream|pid:16272,ProcessStart:132589176489015664

wasifshaffaq commented 3 years ago

windows says it's backdoor (trojan) to control your pc remotely.

wasifshaffaq commented 3 years ago

I also tested it on a virutal machine, it doesn't work even if you override the windows defender warning.

pacjo commented 3 years ago

This issue is still present. Windows defender won't even let me open the zip. File is deleted automaticly

file: C:\Users(user)\Downloads\xmi.zip

webfile: C:\Users(user)\Downloads\xmi.zip|https://github-releases.githubusercontent.com/312902742/46fa3c80-bb04-11eb-90d4-b94fb84c2b83?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAIWNJYAX4CSVEH53A%2F20210613%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20210613T081218Z&X-Amz-Expires=300&X-Amz-Signature=56e36467c12eabf0c32c32146c337b60c4451f5e44345c2b6e32f4713713f4b1&X-Amz-SignedHeaders=host&actor_id=56438628&key_id=0&repo_id=312902742&response-content-disposition=attachment%3B%20filename%3Dxmi.zip&response-content-type=application%2Foctet-stream|pid:14204,ProcessStart:132680455480128825

Gatlincura commented 2 years ago

This is still persistent. Tried to download today and I get: image