moudey / Shell

Powerful context menu manager for Windows File Explorer
https://nilesoft.org
MIT License
3.34k stars 113 forks source link

Virus Total Report! #441

Open Ares-Hantrio opened 6 months ago

Ares-Hantrio commented 6 months ago

www virustotal com_gui_file_46e5afb96a092307725eb4503480ed4c894168884474df01b5a679bdae7e3e5e_relations

Can you tell why Virus Total showing this? I just uploaded your shell.exe file here and Vrus total shows it has some relations with bad IPs..

Ares-Hantrio commented 6 months ago

Is shell is really Safe?

moudey commented 6 months ago

Please explain more about the bad IP relations. The results are false positives on VirusTotal, and we are working to correct this.

Ares-Hantrio commented 6 months ago

Please explain more about the bad IP relations. The results are false positives on VirusTotal, and we are working to correct this.

How could the virus total show 7 false positive results? And wait let me explain to you what I mean by bad IP relations..

Dev123456689 commented 4 months ago

www virustotal com_gui_file_46e5afb96a092307725eb4503480ed4c894168884474df01b5a679bdae7e3e5e_relations

@Ares-03 According to the image you have posted and as per my testing it only got 2 positives out of 73. It is not uncommon to have 2 false positives out of 73. Additionally one of the detection was made by AI which is highly susceptible to false positives.

Ares-Hantrio commented 4 months ago

What about this..?

hgfjhnfg

Dev123456689 commented 4 months ago

hgfjhnfg

This looks suspicious 😨. Developer it's your turn to answer.

moudey commented 4 months ago

Shell uses a system API that some antivirus programs consider malware because it is not signed with an EV code signing certificate It is expensive and I cannot afford it.

The source code is now open. You can review and compile it, and then scan it by Virustotal.

Ares-Hantrio commented 4 months ago

Shell uses a system API that some antivirus programs consider malware because it is not signed with an EV code signing certificate It is expensive and I cannot afford it.

The source code is now open. You can review and compile it, and then scan it by Virustotal.

I can understand your point. And I will also check your source code one day. And I can say that I also believe that this is not an unsafe software, but the point is if you can do something in this situation then please do, i.e. if you can fix this antivirus detection thing then please do. my job was to tell and it is your wish. And thanks for the reply..

moudey commented 4 months ago

I can understand your point. And I will also check your source code one day. And I can say that I also believe that this is not an unsafe software, but the point is if you can do something in this situation then please do, i.e. if you can fix this antivirus detection thing then please do. my job was to tell and it is your wish. And thanks for the reply..

About a year ago, I tried to exclude some APIs, but later their use became necessary, so some false positive results appeared despite sending review requests to antivirus companies. Of course, informing you about this is very important and appreciated. I will work to resolve this issue as much as possible

whindsaks commented 4 months ago

VirusTotal runs these tests with Windows Update and all other Windows bloat features turned on so I would not necessarily cry wolf about anything contacting certain IP addresses.

pa-0 commented 2 months ago

Many whitelisted, known-to-be safe applications are typically flagged by a handful of vendors. The heuristics these AV's use to detect 'bad' applications are far from an exact science (but also sometimes correct!)