Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Getting "Virus detected" when downloading ExifToolGUI installer from Chrome, prevents download #433

Closed
alelom opened this issue Jun 1, 2024 · 15 comments

Comments

@alelom
Copy link

alelom commented Jun 1, 2024

See:

image

This prevents download of the installer.

Chrome Version 125.0.6422.113 (Official Build) (64-bit)
Windows 10

Firefox is instead able to download without issues.

@alelom alelom changed the title Getting "Virus detected" when downloading ExifToolGUI installer from Chrome Getting "Virus detected" when downloading ExifToolGUI installer from Chrome, prevents download Jun 1, 2024
@FrankBijnen
Copy link
Owner

Thanx for the info.
Alas I'm able to change Chrome. Maybe you can report it to Chrome?

V632 has been downloaded 1500+ times by now, highly unlikely that it contains a virus.

@alelom
Copy link
Author

alelom commented Jun 2, 2024

Hey, no probs.

I think the right place to report is the owner's repo because:

  • generally what's needed is some minor modification to the code or repo content to avoid the incorrect flag. In theory, you probably will need to check what's changed in recent chrome versions and comply with their new safety standards. That is, if you want to be compliant, which I wouldn't say is a priority unless the issue appears with most other browsers and/or anti-virus services too.
  • so users of this repo are aware that this has been raised already and that is a false flag.

@FrankBijnen
Copy link
Owner

FrankBijnen commented Jun 2, 2024

I agree that posting here is a good idea.

I dont agree that the installer of GUI should be changed. The installer is created with InnoSetup using this sourcecode;
https://github.com/FrankBijnen/ExifToolGui/blob/main/Redist/ExifToolGUI_install.iss
Lots of installers are created by InnoSetup, and many AV's report false positives. To put it in other words: I wouldn't know what to change.
I think it works best if many people report false positives to Google Chrome.

Edit: It is Windows Defender that reports that there's a virus.

@FrankBijnen
Copy link
Owner

Meanwhile reported to MS.
afbeelding

@FrankBijnen
Copy link
Owner

@alelom

Could you please try again?

I updated my definitions, and did not get a virus warning when I tried again. Maybe reporting to MS did help?

@ColmanPerkins-Stephen
Copy link

@FrankBijnen
Copy link
Owner

@ColmanPerkins-Stephen

Thanks.
What can I say? I dont consider it alarming, but that's my opinion.

@ColmanPerkins-Stephen
Copy link

@ColmanPerkins-Stephen

Thanks. What can I say? I dont consider it alarming, but that's my opinion.

Agreed, just adding my 2 cents. I added a community note to the VT hash page also.

@PaulCoddington
Copy link

Currently being blocked and quarantined by Windows Defender with MS Edge (Trojan:Win32/Wacatac.H!ml).

Looks spurious, will give it a bit of time for signature updates to come through.

@FrankBijnen
Copy link
Owner

@PaulCoddington

Same here.

Downloading with Edge results in: Trojan:Win32/Wacatac.H!ml
Downloading with Chrome results in: Trojan:Win32/QQPass

Previously it was: Trojan:Win32/Vigorf.A

MS cant seem to make up their mind!

@PaulCoddington
Copy link

v6.3.3 installer had no problems until today, but this evening Defender has started flagging my backup copy of the installer (PUA:Win32/Puwaders.C!ml).

@FrankBijnen
Copy link
Owner

@PaulCoddington

Tried to reproduce it, by first updating virus definitions, downloading via Chrome, and executing installer with all options.
No problems so far here. But that doesn't mean they will not appear sometime.

I fear it will be a 'cat and mouse game'. Eventually I might give in and postpone this project.

@Philshappy
Copy link

Since the portable version doesn't appear to have this issue would it be possible to continue with the portable version. This tool is so valuable it would be sad not to continue it.

@FrankBijnen
Copy link
Owner

Thanks for your high opinion.

I'm just postponing not abandoning.

It may help if lots of people report this as a false positive to MS.

@FrankBijnen
Copy link
Owner

The installer V633 is no longer reported as a virus.
Just released V634. Just hope that will be fine.
If not then I will report it as a false positive to MS.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants