Windows Defender Malware detection (false positive)

Can’t download–WIndows 11 reports that 3.0.51 is a virus.

It’s a false positive. Please let us know if you have an AV software which report this so that we can report it.

Just using the standard Windows 11 virus protection.

Oh, ok. I hoped it was over by now, as the latest version is signed by Microsoft. But thanks for reporting.

A post was merged into an existing topic: Introducing MIDI GUITAR 3 HEX

Unfortunately, a code-signing certificate is nothing more than a document used to validate a programme in order to prove that it has not been modified by a third party, regardless of what it contains.

I just tried to d/l the Windows version but got a “virus detected” error message. I assume that this is a false positive. Any change you can zip the .exe installer? Thanks in advance.

It’s safe of course, and we are very careful to not get any infection on development machines, but apparently its impossible to avoid spurious false detections after a new update.

I’ll try to zip the next update, but I dont think that makes a difference.

I can confirm that this happens for me in Chrome:

image

Windows Security / Defender (win11) reports it to be Trojan:Win32/Wacatac.H!ml

image

Happens even if use windows build of curl to download the file, so it is not coming from Chrome.

I could restore the file in Windows Security → Protection History → Actions > Restore
image
File is restored and goes to exceptions. If you copy it somewhere - it gets deleted however, with detected threat.

VirusTotal shows two red results out of dozens of tests. Not really convicing.

image

Both Trojan:Win32/Wacatac.H!ml and Win64:Evo-gen [Trj] are heuristic indications, which are quite generous source of the false positives. Basically it means that it is not some known virus, but instead has some vague indirect similarity. Considering all that above, I am quite sure that it is a false positive, but it would be much convient for an end user not to clash with his own antivirus software.

Maybe you need to use some other installer or compression method or anything else to fix that before actual release. Final release might be much less perfect with this issue still persisting.

For beta… it’s just fine with me, a minor incovenience. Probably there are more pressing matters to do fix right now.

:smiley:

Yes, good points. Of course one we have a “final” version its easy to get it whitelisted, similar to all the previous versions, MG2, etc…

Its just in a period with many updates (and relatively few downloads of each) its difficult. Every time its a different virus with a different scanner, and it takes a month and some effort before its whitelisted, at which point there is another update which is flagged as as a new virus by a new scanner… if anybody knows how to get out of this, please help me :slight_smile:

http://blog.nirsoft.net/2009/05/17/antivirus-companies-cause-a-big-headache-to-small-developers/

https://coolsoft.altervista.org/en/blog/2018/05/antivirus-false-positives-are-plague-small-developers

I downloaded it twice. The first time it didn’t get flagged, but the second time it did. Why is that?

If you want to be sure that this file is harmless, run after installation a full Windows antivirus scan.
No threat will be detected.