stuerp / foo_midi

A foobar2000 component to play MIDI files.
MIT License
63 stars 1 forks source link

Possible Virus #33

Closed Michelist closed 10 months ago

Michelist commented 10 months ago

I'm sorry to have to tell you this, but: According to this result: https://www.virustotal.com/gui/file/93e28bab767288c13ede2c9ff43448a4ff0513ff40fe144527d603f22ac9c302 it is not impossible that your building environment is infested. In the meantime, Windows Defender is now bagging the file foo_midi.fb2k-component in version v2.9.2.0 too.

In view of the reputation of the scanners reporting the find, I consider the infection to be very likely to exist, as my initial scan, immediately after I noticed the launch two days ago, was still completely without hits. If you had used a problematic build environment, like most free builders for EXE installers, these hits would have occurred two days ago.

Regards Michelist

stuerp commented 10 months ago

Thanks for the report but it's a false positive.

Michelist commented 10 months ago

I'll wait and see. Almost no one is safe from being compromised these days. I do not believe, nor am I saying, that this is deliberate.

Regards Michelist

stuerp commented 10 months ago

Or you can just remove the vshost.exe files and loose VSTi support. It's not my fault that legit functionality is flagged as suspect.

ramonsmits commented 10 months ago

Or you can just remove the vshost.exe files and loose VSTi support.

That is what I did:

  1. Save file to folder that is excluded from scanning
  2. Open the archive with for example 7zip
  3. Delete the *.exe files in the root
  4. Scan the archive and no threats are detected