Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

BRL-CAD_7.36.0_win64.exe Blocked by Antivirus #98

Open
millercr4 opened this issue Aug 30, 2023 · 6 comments
Open

BRL-CAD_7.36.0_win64.exe Blocked by Antivirus #98

millercr4 opened this issue Aug 30, 2023 · 6 comments

Comments

@millercr4
Copy link

When attempting to download BRL-CAD_7.36.0_win64.exe, the download was blocked due to detected Trojan:Win32/Wacatac.H!ml. This did not occur when downloading the .msi. The BRL-CAD 7.36.0 release page shows the that .exe was updated Aug 14th, 2023 but the other release assets show Jul 26th and 27th.

@starseeker
Copy link
Member

We had gotten a previous report on the .exe installer, and I regenerated it with the latest NSIS from sourceforge. Is there any way to confirm whether there could be a false positive?

@bckelley
Copy link

bckelley commented Oct 3, 2023

I just had the same issue with the msi

@timbolin
Copy link

i also just had this with the exe. id really appreciate if someone could confirm whether or not this was a false positive. vitustotal has a LOT of detections for it when analyzed so im a bit concerned.

@starseeker
Copy link
Member

I'm not sure what is triggering the reports... I've taken down the .exe for now, since the .msi seems to be causing fewer issues. I'll try regenerating the .exe again later.

@starseeker
Copy link
Member

I thought it might be NSIS tripping up the scanners, but submitting a zip file of freshly compiled BRL-CAD build outputs to VirusTotal still results in some vendors flagging some of the executable files. I'm thinking false positive based on it being a fresh compile without going through NSIS. Six of them don't seem to like coil.exe, of all things...

@starseeker
Copy link
Member

OK, yeah... Building with the Windows development VM from https://developer.microsoft.com/en-us/windows/downloads/virtual-machines and not using any installers (just making a zip file of the build) VirusTotal still returns a bunch of flags.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants