Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Kasperky Internet Security reports 3.8 release contains Trojan.Multi.GenAutorunReg.A #141

Open
pskerr opened this issue Dec 10, 2016 · 15 comments

Comments

@pskerr
Copy link

pskerr commented Dec 10, 2016

n/t

@jansokoly
Copy link
Collaborator

Please attach a screenshot.
Did you do a new installation from *.msi or updated from previous version using built-in updater?

@pskerr
Copy link
Author

pskerr commented Dec 10, 2016

It was picked up when automatically downloading the update, and I also downloaded the zip file from here and scanned it to double check. Also picked up there.

@pskerr
Copy link
Author

pskerr commented Dec 10, 2016

screen1
screen2

@shellscape
Copy link
Owner

ran the installer through https://scan.kaspersky.com and it reported the same.

@shellscape
Copy link
Owner

edited the release, added a note about the possible infection, and marked it as a pre-release. @jansokoly high recommend scanning your local machine :)

@jansokoly
Copy link
Collaborator

From the name of the "trojan" being HEUR:Trojan.Win32.Generic, I assume it's just Kaspersky false positive based on some overprotective heuristic, probably identifying update mechanism as a trojan.

I recommend checking the file with more then just one antivirus before mocking. https://www.virustotal.com/en/file/a7726321acf1e45ad8f724529bd036e4b19ffd88ba496eba7648160d6effdc41/analysis/

@pskerr
Copy link
Author

pskerr commented Dec 10, 2016

That's why I put both screenshots in there, once loaded in memory, it was more specific. I definitely leave it up to you guys as to how you want to handle it, though.

@shellscape
Copy link
Owner

@jansokoly I didn't read the messages as anyone mocking you. hopefully you don't think that. I only edited that release to pre-release as a precaution. if you feel that this is a false positive, please do change it to full release. total faith in you bud!

@pneuschwander
Copy link

Greetings.
I got the update via built-in "AutoUpdater" (a feature that can't be disabled? - found no option in settings)
The "behavioral analysis" of G Data InternetSecurity jumped in and reported suspicious actions:

The program connects to a network.
The program has created or manipulated an executable file.
The program has tried to delete its own program file.
The program tried to change the name of its own program file.
The program has tried to move its own program file.

I was asked whether I want to allow or deny those actions.
The .exe itself is reported to be clean. Just the behavioral thing when the update was applied automatically.

Seems to be a false positive.

@jansokoly Thank you for maintaining the application!

@shellscape
Copy link
Owner

thanks for investigating @regmebaby

@pskerr
Copy link
Author

pskerr commented Dec 11, 2016

I'll go ahead and close the issue.

@pskerr pskerr closed this as completed Dec 11, 2016
@pskerr
Copy link
Author

pskerr commented Dec 11, 2016

@shellscape @jansokoly Well, I'll keep it closed, because there's no need to scare the world, but I can't even get Kaspersky to whitelist your file. I won't be able to run this without changes. Want me to create an "incompatibility" issue?

@jansokoly
Copy link
Collaborator

@pskerr I'm not familiar with Kaspersky, but they seem to have a form to report false positives here: https://newvirus.kaspersky.com
Not sure if we can do anything else than submit url to installer (https://github.com/shellscape/Gmail-Notifier-Plus/releases/download/v3.8/Gmail-Notifier-Plus-3.8.msi) via that form.

@shellscape
Copy link
Owner

Received an email from a user with HitmanPro, claiming there was a trojan in the update:

Hi, I've been using Gmail Notifier Plus for some time now and like it. HitmanPro is saying, however, that there is a Trojan in the files after the most recent update. Do you have any information on this?

I'm no longer on Windows and don't have access to it, so I cannot verify.

@shellscape shellscape reopened this Dec 16, 2016
@shellscape
Copy link
Owner

shellscape commented Dec 16, 2016

I've performed a multiclient online scan, and a scan on Sophos for mac with only hits on Kaspersky clients and clients which depend on Kaspersky data:

scan
scan

These results point to false positives. Will leave the issue open for additional input. It also looks like this is not an isolated incident. https://forum.kaspersky.com/index.php?showtopic=360642

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants