valinet / ExplorerPatcher

This project aims to enhance the working environment on Windows
GNU General Public License v2.0
22k stars 969 forks source link

Several files marked as malicious from my antivirus #3229

Open PIndividual opened 2 weeks ago

PIndividual commented 2 weeks ago

After finishing installing EP, my antivirus claims that these files are behaving very similar to a trojan and recommends I to quarantine them ASAP. These files are: C:\WINDOws\dxgi.dll C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\dxgi.dll C:\WindowslSystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\wincorlib.DLL C:\WindowslSystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\dxgi.dll Should I do that? Are these files essential for EP to work?

Amrsatrio commented 2 weeks ago

Yes. Those files are essential. Microsoft doesn't seem to like EP anymore, so they have marked this as a virus. Compiling EP yourself seems to be the only option now to be safe in the long run.

jlearman commented 1 week ago

Not long after a recent Windows (and ExplorerPatcher) update, ep_setup.exe was quarantined by Windows Security.

Detected: HackTool:Win64/ExplorerPatcher!MTB
Status: Quarantined
Date: 5/3/2024
Details: This program has potentiall unwanted behavior.

Affected items:
  file: C:\Program Files\ExplorerPatcher\ep_setup.exe
  regkey: HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{D17F1E1A-5919-4427-8F89-A1A8503CA3EB}_ExplorerPatcher
  uninstall: HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{D17F1E1A-5919-4427-8F89-A1A8503CA3EB}_ExplorerPatcher

ExplorerPatcher is still working. Please LMK if there's any information I can provide or anything I can do to help.

I'd post the About text from ExplorerPatcher, but sadly, it's not selectable so I can't copy it.

pyrates999 commented 1 week ago

You can also set windows defender to exclude the following:

  1. C:\Program Files\ExplorerPatcher
  2. %APPDATA%\ExplorerPatcher

Future updates to EP won't be flagged then.

You can also set windows defender to exclude the directory that you manually download EP to so you can install it without windows defender blocking it.

merlinuwe commented 6 days ago

Soon, I got this message from Windows:

image

Do I have to worry?

Amrsatrio commented 6 days ago

No. Just allow it and continue as you were.