microsoft / hidtools

Human Interface Device (HID) Tools for Windows and Devices
MIT License
142 stars 20 forks source link

Waratah v1.6.0 flagged as Trojan.Marsilla #20

Open silvervest opened 1 month ago

silvervest commented 1 month ago

Hello there,

Firefox blocked this download, and when allowed and scanned by Windows Defender, it came up clear. However, running through VirusTotal gives a number of hits against Trojan.Marsilia... I've checked the shasum across multiple machines and networks to ensure it wasn't something modifying in-flight https://www.virustotal.com/gui/file/e7987ccb1859620039790f2b98399a1703d2c4be3ccd8b263426532c5d59822d/detection

Runs fine in a sandbox without anything weird, so seems like a false positive, but a pretty loud one that may need some clearing up.

Cheers, Nick

matwilli commented 1 month ago

Thanks mate for reaching-out about this. We had a similar problem with Windows Defender (see closed issues), and I was able to get it validated and allow-listed.

I've reached-out to Firefox, but I don't have high hopes of getting this resolved (as there doesn't seem to be a formal request mechanism for malware)