Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

NeSync installer on windows detected as malware #144

Open
1 of 3 tasks
fxdeniz opened this issue Sep 6, 2023 · 3 comments
Open
1 of 3 tasks

NeSync installer on windows detected as malware #144

fxdeniz opened this issue Sep 6, 2023 · 3 comments
Assignees
Labels
help wanted Extra attention is needed Windows
Milestone

Comments

@fxdeniz
Copy link
Owner

fxdeniz commented Sep 6, 2023

NeSync uses NSIS as a installer on Windows. And, antiviruses Bkav Pro and SecureAge flag exe files based on NSIS as a virus.

Detection names:
Bkav Pro: W32.AIDetectMalware
SecureAge: Malicious
Gridinsoft: Ransom.Win32.Wacatac.oa!s1

VirusTotal result for version 1.8.1 installer

VirusTotal result for version 1.8.0 installer

VirusTotal result for version 1.7.0 installer

From detection names, we can conclude that, detections are machine learning based.
Both, Bkav Pro and SecureAge APEX are advertised for their AI capabilities. However, this is a false positive.

Update: Starting from september 6, Gridinsoft also marks installers for versions 1.8.x marks as malware.

To solve this issue, I'll communicate with two vendors.

  • Get in touch with Bkav Corporation
  • Get in touch with Secureage Technology Pte Ltd
  • Get in touch with Gridinsoft LLC
@fxdeniz fxdeniz added help wanted Extra attention is needed Windows labels Sep 6, 2023
@fxdeniz fxdeniz added this to the 2.0.0 milestone Sep 6, 2023
@fxdeniz fxdeniz self-assigned this Sep 6, 2023
@fxdeniz
Copy link
Owner Author

fxdeniz commented Sep 6, 2023

I reached to SecureAge (4th of September) via their false positive reporting page

And within same day, I received this reply which says they will remove false positive detections.

result-apex

@fxdeniz
Copy link
Owner Author

fxdeniz commented Sep 6, 2023

Also, I sent e-mail to fpreport@bkav.com and bkav@bkav.com in september 4

but still no response

@fxdeniz
Copy link
Owner Author

fxdeniz commented Sep 7, 2023

Today, I released the version 1.8.1

I reached to all of the vendors. Again, clearing false positives for new installer.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
help wanted Extra attention is needed Windows
Projects
None yet
Development

No branches or pull requests

1 participant