voltapp / volt

300 KB desktop client for Slack, Skype, Twitter, Telegram, and more
608 stars 8 forks source link

Installer marked as malicious by VirusTotal #87

Closed dwwmmn closed 5 years ago

dwwmmn commented 6 years ago

Six antivirus tools on VirusTotal marked the installer for Windows as malicious:

https://www.virustotal.com/#/file/ac794ec1927009fed5875fbaa50fe4d24ad29c4f8c3d07b1ab535cae462d0305/detection

I see previous issues (#18 ) addressed issues with false detections; is there a fix for this? If not, it may be good to add a section to the website about false positives to reassure users.

damianmcclure commented 6 years ago

Pretty sure they don't care about this project anymore. Both sites don't work anymore, etc. Would be nice if they released the source to public so someone else could continue.

Dilnu commented 5 years ago

The new mac version also appears to have a virus https://www.virustotal.com/en/file/bff80ae1f89b6495b1afbb4456276aebd257130f67016843c34bbdf73fbd80e5/analysis/1549521263/

voltapp2 commented 5 years ago

Fixed in 0.37.

All this time this was caused by the UPX compressor, which is indeed used by lots of viruses.

Smart antivirus software detects UPX compression and unpacks the executable. Bad antivirus software results in a false positive.

As of 0.37 UPX is no longer used.

voltapp2 commented 5 years ago

@mcclureski I did a terrible job with the development in 2018. Lots of bad decisions and lack of communication.

Sorry about that.

Soon I'll post a detailed blog about what caused the 9 month delay.

Dilnu commented 5 years ago

This still appears to be an issue with 0.41 https://www.virustotal.com/#/file/f4ffaafc07ceff49031b9777ba4bffd687cd06e57352f85b53e81a7d023dcc85/detection

benfletcher commented 5 years ago

https://www.virustotal.com/#/url/250e62eaac56ad9a3b01153082d2cc04e740b54d1b029e562c8609a6e6411d78/detection

As of today, comes up clean. Unless the download location link changes, this URL might work going forward.

Dilnu commented 5 years ago

If you click the link on that page to 'downloaded file' the same thing is detected. According to the developer this is because despite what was said earlier in this thread UPX is still used as of 0.43