seanox / virtual-environment

Portable platform and software environment for Microsoft Windows based on a virtual drive
Apache License 2.0
83 stars 25 forks source link

Detected as trojan? #1

Closed iron2000 closed 2 years ago

iron2000 commented 2 years ago

MS Defender just detected ShiftDown as a trojan. trojan

The original version was ok. Just updated to the latest version yesterday. So maybe the latest version has some similar behavior as the trojan?

seanox commented 2 years ago

Thanks for the feedback.

What can be: I now use net.exe instead of sc.exe. Possibly Trojans/viruses do that too.

I could not reproduce the virus warning unfortunately.

Antimalware client version: 4.18.2111.5 Module version: 1.1.18800.4 Antiviren-Version: 1.355.1272.0 Antispyware-Version: 1.355.1272.0

Online test (few provide false positive): https://metadefender.opswat.com/results/file/bzIyMDEwMnBkT1M4TVV2cVU4S3J0Z0RyQi0/regular/multiscan https://www.virustotal.com/gui/file/8565808510020c60670017d3917cc08f05a2ba87fb725967a882001f1d7aa29d?nocache=1 https://opentip.kaspersky.com/8565808510020C60670017D3917CC08F05A2BA87FB725967A882001F1D7AA29D/

@seanox Submit file to Microsoft as a false positive (if reproducible): https://www.microsoft.com/en-us/wdsi/filesubmission

At this point a big sorry, since Shiftdown has no own release directory, have been pushed in the last few days unintentionally update from development. I'm still correcting that. The current version corresponds to the release candidate 1.2.x and will also be published in the version if no further errors are found.

seanox commented 2 years ago

Submitted as false positive https://www.microsoft.com/en-us/wdsi/submission/2c8f1929-a88b-4711-b460-c03dd00f3cd2

seanox commented 2 years ago

At this time, the submitted files do not meet our criteria for malware or potentially unwanted applications. The detection has been removed. Please follow the steps below to clear cached detections and obtain the latest malware definitions.

  1. Open command prompt as administrator and change directory to c:\Program Files\Windows Defender
  2. Run “MpCmdRun.exe -removedefinitions -dynamicsignatures”
  3. Run "MpCmdRun.exe -SignatureUpdate"

Alternatively, the latest definition is available for download here: https://docs.microsoft.com/microsoft-365/security/defender-endpoint/manage-updates-baselines-microsoft-defender-antivirus

Thank you for contacting Microsoft.