onlyfang / VBoxVmService

Windows Service to run VirtualBox VMs automatically
328 stars 48 forks source link

? Virus ? #70

Closed 3boysdad closed 1 year ago

3boysdad commented 2 years ago

Anyone else getting blocked by Microsoft "Anti-Virus" from installing this?

AJMansfield commented 1 year ago

I had a similar issue attempting to install the new 7.0 version. Windows Defender detects it as 'potentially malicious', and Trend Micro Apex One classified it as "potentially ransomware". For now, I've just stuck with the older 6.1 version since I only have VirtualBox 6.1 installed anyway.

AJMansfield commented 1 year ago

VirusTotal reports that four different vendors mark the most recent version as malicious: https://www.virustotal.com/gui/file/79b34abe08068a6292cc427a05613334a0202fe1a9d829979612ccc8c739b0c9

All of the "Mitre ATT&CK Tactics And Techniques" reported in the behavior analysis are things I'd expect this program to need to do to have the functionality it has, though, so idk.

onlyfang commented 1 year ago

We see similar issue before. Most likely this is because InnoSetup is used to create the setup. Some other malware might have also used InnoSetup, That caused the anti-virus software detected this as a malware.

I totally trust InnoSetup is clean, and will just close this. If you are not sure, since this is open source software, please just build the package by your own.