schneidermanuel / TwitchLeecher-Dx

Twitch Leecher DX - The Broadcast Downloader
MIT License
112 stars 5 forks source link

AV detection for file TL_CockyGrabber.dll? #4

Closed squarecrusher closed 1 year ago

squarecrusher commented 1 year ago

Hi!

I was upgrading from twitch leecher 2.07 to latest release in this fork (3.2.1).

My AV (Eset) gets a detection with the following log:

Log C:\Users\zzz\Downloads\TwitchLeecher_3.2.1.exe » WIXSFX » 0002.cab » CAB » a0 » MSI » Setup.cab » CAB » TL_CockyGrabber.dll - a variant of MSIL/PSW.Agent.SSC trojan - cleaned by deleting [1]

Virustotal report for this release file: https://www.virustotal.com/gui/file/02ad0a6be55f15b8b729f572e1ecbf836c84f0662b59e98fd8d9e8e466131c81

OS Name Microsoft Windows 11 Home Version 10.0.22621 Build 22621

Edit: After some reading i gathered that its probably this projects file being used and from the desc, i can see how it would be flagged. Its also been raised as an issue in their project.

https://github.com/MoistCoder/CockyGrabber https://github.com/MoistCoder/CockyGrabber/issues/37

schneidermanuel commented 1 year ago

Yes, I am aware of this situation. The issue is indeed the use of CockyGrabber.dll. this is ONLY used for sub-only mode since this freature is not part of the official twitch api and any 3rd party app (such as TwitchLeecher DX) cannot access this scope. So TwitchLeecher Grabs the Coockie of your Twitch Session to access this scope.

I will likly compile and release 2 seoperate versions of TwitchLeecher-DX, one with and one without subonly-Mode support, the one without does not ship the dll and won't be detected as Virus. If sub-Only Downloads are a feature you need, the only way now is whitelisting this Program in your antivirus.

Anyways - Thanks for reporting!

schneidermanuel commented 1 year ago

Closed with release v3.3.0