Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

the file contains a virus or potentially unwanted softwareAt #169

Open
61ax opened this issue Sep 13, 2024 · 2 comments
Open

the file contains a virus or potentially unwanted softwareAt #169

61ax opened this issue Sep 13, 2024 · 2 comments

Comments

@61ax
Copy link

61ax commented Sep 13, 2024

Program 'ysoserial.exe' failed to run: Operation did not complete successfully because the file contains a virus or
potentially unwanted softwareAt line:1 char:1

windows security ::
Detected:VirTool:MSIL/Vusrlize.A!MTB

Affected items:
file: C:\Users\folder\ysoserial.net\ysoserial\bin\Release\ysoserial.exe

@rkg-mm
Copy link

rkg-mm commented Nov 3, 2024

Can confirm our anti-virus also flagging this as Trojan

@irsdl
Copy link
Collaborator

irsdl commented Nov 4, 2024

Hey everyone,

This is not a trojan; rather, YSOSerial.Net is a legitimate security tool created for ethical testing by security professionals. It includes payloads for exploiting deserialization vulnerabilities in the .NET Framework/Mono. Antivirus programs often detect these embedded payload strings and flag them as potential threats because they resemble code patterns used in actual exploits.

If you're seeing this alert outside of a security testing context, it could indicate a compromise on your system. However, if you're a security professional using this tool intentionally, you likely understand the detection and can work around it by either excluding it in your antivirus settings or compiling a custom version to avoid generic string detection.

I’m providing this explanation in case you're not familiar with security testing tools. Unfortunately, we’re unable to discuss methods for bypassing antivirus detections in detail for security reasons. I hope this clears things up.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants