Giter VIP home page Giter VIP logo

Comments (42)

GavinFarrington avatar GavinFarrington commented on June 6, 2024 4

Windows Defender (Win 11) just flagged bt-3.5.2 as "threats found" for me.

Detected: Program:Win32/Wacapew.C!ml

from bt.

aloneguid avatar aloneguid commented on June 6, 2024 3

10 today.

from bt.

aloneguid avatar aloneguid commented on June 6, 2024 2

Analysis on above is still pending but some detections have already cleared out.

from bt.

eiqnepm avatar eiqnepm commented on June 6, 2024 2

It seems Microsoft doesn't like the latest version as it has been automatically removed from my PC by Windows Defender.

from bt.

aloneguid avatar aloneguid commented on June 6, 2024 2

Yeah, but it would be also super slow and at least x100 bigger in size of downloads and ram.

from bt.

aloneguid avatar aloneguid commented on June 6, 2024 1

It's about $1.5k for 3 years. Could be less if you shop around. But that won't solve false AV issues, you can still be banned and certificate revoked for no reason. I think realistically one needs a legal team to deal with AV false claims which I apparently don't have. I'd recommend having a read:

And by the way, the last BT version (3.5.0) has only a single AV's claim out of 90, unlike 29 out of 90 for version 3.4.0, so it's totally random trash. I've myself became very pessimistic about usefulness of AV software in general after dealing with this.

from bt.

jnv avatar jnv commented on June 6, 2024 1

Same thing here, BT 3.5.2 was flagged by Microsoft Defender as PUA. It's possible to send files to Microsoft for further analysis: https://www.microsoft.com/en-us/wdsi/filesubmission/ โ€“ I urge you to do it if you are affected.

from bt.

aloneguid avatar aloneguid commented on June 6, 2024 1

Same thing here, BT 3.5.2 was flagged by Microsoft Defender as PUA. It's possible to send files to Microsoft for further analysis: https://www.microsoft.com/en-us/wdsi/filesubmission/ โ€“ I urge you to do it if you are affected.

I have used this before, and just submitting for latest version as "incorrectly identified as malware". Will let you know on progress:
image

from bt.

aloneguid avatar aloneguid commented on June 6, 2024 1

@neoOpus thanks. Update checks are already fixed and will be out in v3.6. Defender does not block it anymore.

from bt.

jnv avatar jnv commented on June 6, 2024 1

By the way, I reported the false positive to Avast (which also includes AVG), so VT now reports only 11 false positives.

According to their reply, they reclassified BT from malware to PUA, since apparently it doesn't match their "clean software policy" (which, surprisingly, claims signing is preferred but not required):

Thank you for contacting Avast and reporting a false positive detection. We're happy to help.

Along with the Avast virus specialist, weโ€™ve checked the reported file and changed the threat detection to PUP (potentially unwanted program). The PUP detection is due to lack of compliance with Avastโ€™s clean software policy.

For more information, refer to this article: Avast Threat Labs - Clean guidelines

If you are the owner of the reported file and want to change the detection to clean, feel free to contact us again for a new analysis as soon as the file matches the Avast guidelines.

from bt.

aloneguid avatar aloneguid commented on June 6, 2024 1

@jnv I have raised Avast issue separately yesterday, and classification is cleared completely.

image

from bt.

aloneguid avatar aloneguid commented on June 6, 2024 1

Also submitted a dispute to McAfee now.

from bt.

aloneguid avatar aloneguid commented on June 6, 2024 1

And just for fun to Malwarebytes.

from bt.

aloneguid avatar aloneguid commented on June 6, 2024 1

from bt.

aloneguid avatar aloneguid commented on June 6, 2024 1

AVG and Avast were great help in whitelistimg 3.6.2, we are -2 now.

from bt.

aloneguid avatar aloneguid commented on June 6, 2024 1

14/61 today!

image

from bt.

neoOpus avatar neoOpus commented on June 6, 2024

I am unable to download it unless, of course, if I disable MS Defender

image

from bt.

aloneguid avatar aloneguid commented on June 6, 2024

I can't afford a signing certificate so it's not going to happen. You are free to validate it's not dangerous as source code and build pipelines are completely open and transparent.

from bt.

corvus2606 avatar corvus2606 commented on June 6, 2024

I can't afford a signing certificate so it's not going to happen. You are free to validate it's not dangerous as source code and build pipelines are completely open and transparent.

What is the cost of a signing certificate?

from bt.

paz avatar paz commented on June 6, 2024

Kaspersky and Sophos both left BT undetected for me, seems it might be a Microsoft specific issue.

from bt.

aloneguid avatar aloneguid commented on June 6, 2024

it's totally random and changes daily ;)

from bt.

neoOpus avatar neoOpus commented on June 6, 2024

It keeps getting deleted even when excluded from scans... I have to reinstall it every few days.

from bt.

CityguyUSA avatar CityguyUSA commented on June 6, 2024

There are 2 different .zip files. A pdb version which downloads fine and non-pdb version that doesn't. What's the difference between the 2?

from bt.

aloneguid avatar aloneguid commented on June 6, 2024

There are 2 different .zip files. A pdb version which downloads fine and non-pdb version that doesn't. What's the difference between the 2?

.pdb version is debug symbols to investigate crashes, you don't need that.

from bt.

aloneguid avatar aloneguid commented on June 6, 2024

It keeps getting deleted even when excluded from scans... I have to reinstall it every few days.

You can permanently allow the "threat" until MS investigates. There are instructions available here.

from bt.

aloneguid avatar aloneguid commented on June 6, 2024

Windows Defender should now be fine, just got analysis results from Microsoft:

image

from bt.

aloneguid avatar aloneguid commented on June 6, 2024

Also VirusTotal before and after (Microsoft AV is OK now). Hopefully others will follow the suit.

image

image

from bt.

neoOpus avatar neoOpus commented on June 6, 2024

It keeps getting deleted even when excluded from scans... I have to reinstall it every few days.

You can permanently allow the "threat" until MS investigates. There are instructions available here.

I have been doing that since the start, but it doesn't stick. That's why I notified you that currently it is allowed and working properly, but it crashes when trying to find updates... I am simply informing you of this, but it is alright if you are unable to resolve these.

from bt.

aloneguid avatar aloneguid commented on June 6, 2024

@jnv thanks for that, I also raised request with ESET which has reclassified as clean.

from bt.

neoOpus avatar neoOpus commented on June 6, 2024

So far, it worked and I didn't have any issue :)

from bt.

jnv avatar jnv commented on June 6, 2024

Unfortunately we're back to 24 false positives for the v3.6.2 installer. Today even Microsoft Defender took down my locally compiled version.

from bt.

cheTesta avatar cheTesta commented on June 6, 2024

Unfortunately we're back to 18/64

from bt.

cheTesta avatar cheTesta commented on June 6, 2024

image
18 on the .zip version

from bt.

aloneguid avatar aloneguid commented on June 6, 2024

Down to 11 today:

image

from bt.

aloneguid avatar aloneguid commented on June 6, 2024

image 18 on the .zip version

Down to 15 today. ZIP is catching up, as I'm submitting false positives for MSI only, which contains the same binary as zip.

from bt.

Ultrafeel avatar Ultrafeel commented on June 6, 2024

https://www.virustotal.com/gui/file/9a6a86a90c1c68423465a4b800f4f2941a92e1f82ed9ea0f4dfb58a641932cef/details

from bt.

aloneguid avatar aloneguid commented on June 6, 2024

Same here, looks like Microsoft needs a ticket for every new version to allowlist it again.

from bt.

aloneguid avatar aloneguid commented on June 6, 2024

Also this is odd, because VirusTotal only reports 4 hits from "bad" AVs

image

from bt.

Ultrafeel avatar Ultrafeel commented on June 6, 2024

I think if it was in Dotnet or other IL language it wouldn't have so many troubles. Because it is much easier to analyze than pure x86 instruction set.

from bt.

mahoromax avatar mahoromax commented on June 6, 2024

It seems Microsoft doesn't like the latest version as it has been automatically removed from my PC by Windows Defender.

Not only the latest, also 1 or 2 previous - it broke, I installed newer one (deactivated the antivir) but at some point it reactivated... It actually breaks opening links if BT is set as default handle for hyperlinks. Typical Microsoft -.-

Can we whitelist it manually? Or do we need to do that for every version as well?

Edit: Going into the defender history and reverting + adding a manual entry for C:\Program Files\Browser Tamer\bt.exe seems to work - for now. No resetting of default browser or anything needed.

from bt.

Ultrafeel avatar Ultrafeel commented on June 6, 2024

Yeah, but it would be also super slow and at least x100 bigger in size of downloads and ram.

Is https://github.com/mortenn/BrowserPicker , for example, slow and bloated for you?

from bt.

Ultrafeel avatar Ultrafeel commented on June 6, 2024

From what I understand from this talk about Windows - BlueHat IL 2023 - David Weston - Default Security
https://www.youtube.com/watch?v=8T6ClX-y2AE : maybe turning in UWP and converting msi to MSIX can make help against AV ๐Ÿค“. One of the issues was mentioned is "over privileged apps".

from bt.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.