Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

GDWeave flagged as false positive by antivirus software #25

Open
kdurmeter opened this issue Nov 11, 2024 · 12 comments
Open

GDWeave flagged as false positive by antivirus software #25

kdurmeter opened this issue Nov 11, 2024 · 12 comments

Comments

@kdurmeter
Copy link

Good morning.

Went to install GDWeave and it's being flagged as a virus by Windows Defender

It is flagging it as Trojan:Win32/Wacatac.B!ml

image

@NotNite
Copy link
Owner

NotNite commented Nov 11, 2024

This is a false positive by your antivirus, but I kind of expected this happening from the new GDWeave update that initializes itself in a different way. You can tell your antivirus to ignore this for now. I'll get this sorted soon.

@NotNite NotNite changed the title GDWeave Flagged as Virus by Windows Defender GDWeave flagged as false positive by antivirus software Nov 13, 2024
@NotNite NotNite pinned this issue Nov 13, 2024
@legokidlogan
Copy link

And yet, scanning built-in system copies of winmm.dll (of which there are many) results in no detection flags, for WD and virustotal.

Is there any difference in the contents of GDW's version of the dll from the standard C:\Windows\System32\winmm.dll or is it just a matter of not being properly signed? If it's the latter, then theoretically people could use a copy of the dll from their own system files instead and have it run fine without the worry of a flagged 3rd party dll.

@NotNite
Copy link
Owner

NotNite commented Nov 24, 2024

The winmm.dll included is a proxy DLL written in Rust. Replacing it with the system file would result in GDWeave not loading. The entire point is that it overrides the system file in the search path.

@RecoveryDeer
Copy link

yo has this been fixed or not?? @NotNite

@NotNite
Copy link
Owner

NotNite commented Dec 9, 2024

There isn't anything I can "fix". Microsoft's form to mark as a false positive is currently broken, and it's not a bug in my code. Also, please don't ping me in GitHub issues I'm already subscribed to - I will see your message eventually.

@RecoveryDeer
Copy link

RecoveryDeer commented Dec 9, 2024

I never got a reply for my other question, so I naturally assumed you didn't see it. This is the only time I've ever had this problem with anything; so I ask again:
Is it safe to mark as ignore? I've read that it's an actual potential virus in correspondence to other things, so if I mark it for ignore, how do I know it won't just ignore future instances where it isn't a 'false positive'?

You also stated in a previous comment that you'd get it sorted soon, ergo why I asked if it has been fixed or not.

@NotNite
Copy link
Owner

NotNite commented Dec 9, 2024

Is it safe to mark as ignore?

Yes.

I've read that it's an actual potential virus in correspondence to other things

It's not, and I proved this: #27 (comment)

if I mark it for ignore, how do I know it won't just ignore future instances where it isn't a 'false positive'?

Assuming you mark the detection as wanted instead of making an exclusion, it'll probably allow that specific version of the file instead of excluding every version.

There will never be a time I push malware to GDWeave, and I have systems in place to ensure that wrt CI. If it's really needed, I can set up attestation, but I don't think it's worth the effort.

You also stated in a previous comment that you'd get it sorted soon, ergo why I asked if it has been fixed or not.

I tried. Microsoft's form to mark as a false positive is currently broken.

@RecoveryDeer
Copy link

Thank you!!

@MareepSheepPeep
Copy link

My Windows Defender is flagging that .dll with PUA:Win32/Packunwan - is this also an expected false positive? It's also flagged as malicious by 12/68 vendors in VirusTotal, citing hacktool.rustregion. I am not trying to accuse you of anything or make any judgements about your character, I'm just trying to be as safe as possible.

@NotNite
Copy link
Owner

NotNite commented Dec 17, 2024

Yes.

@Foxydapirate12
Copy link

Foxydapirate12 commented Jan 3, 2025

You can submit the file to the Microsoft Malware Analysis File Submission Page and they usually include a patch for it in the next Windows Defender Security Intelligence Update, I'll submit the current version now ^w^

@NotNite
Copy link
Owner

NotNite commented Jan 3, 2025

You can submit the file to the Microsoft Malware Analysis File Submission Page and they usually include a patch for it in the next Windows Defender Security Intelligence Update, I'll submit the current version now ^w^

Last time I tried doing this, their submission form was broken, but if it works now you're welcome to. Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

6 participants