Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

EDMC 5.0.0. Flagged at Malware by AVG Anti Virus #1058

Closed
Bow-Lof-Petunias opened this issue May 13, 2021 · 24 comments
Closed

EDMC 5.0.0. Flagged at Malware by AVG Anti Virus #1058

Bow-Lof-Petunias opened this issue May 13, 2021 · 24 comments
Labels
anti-virus Anti-Virus issues

Comments

@Bow-Lof-Petunias
Copy link

Please complete the following information:

  • Version 5.0.0.
  • Game Version 'Live'
  • OS: Windows 10
  • OS Locale: English
  • Please attach BOTH log files, by dragging and dropping them into this input:
    1. %TEMP%\EDMarketConnector.log from immediately after the bug occurs (re-running the application overwrites this file).
    2. %TEMP%\EDMarketConnector\EDMarketConnector-debug.log`. See [Debug Log File]EDMarketConnector.log
      EDMarketConnector-debug.log

Describe the bug
When scanning EDMarketConnector_win_5.0.0.msi with AVG Internet Security 20.9.3152 (build 20.9.5758.625), product.cab EDMC.exe is flagged as containing Win32:Malware-gen

To Reproduce
Steps to reproduce the behavior:

  1. Download MSI from this project
  2. Run scanner on file

Expected behavior
MSI is reported free from malware

Screenshots
avg_edmc

Additional context
This report is not implying the installer is infected.
This feels like a false positive.
However this report is designed to raise awareness of a potential issue.
o7 Cmdrs

@Bow-Lof-Petunias Bow-Lof-Petunias added bug unconfirmed An unconfirmed bug labels May 13, 2021
@TrueMadMotion
Copy link

TrueMadMotion commented May 13, 2021

Similar here with Bitdefender Build 25.0.19.75; Engine Version 7.88511 'C:\Users*User*\AppData\Local\Temp\Update-53c11983-e30b-4b03-9826-c3dfba676e0e\EDMarketConnector_win_5.0.0.msi' infected with 'Gen:Variant.Bulz.466715'

@denisgre
Copy link

Same Bitdefender response here. Ended up uninstalling EDMC and trying a new install. Now neither Bitdefender nor Windows 10 will allow it to be installed or used. Message reads as above and also:
"We blocked this dangerous page for your protection:
https://github-releases.githubusercontent.com/36755989/ef094c00-b333-11eb-8ca8-39d9bb3142fa?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAIWNJYAX4CSVEH53A%2F20210512%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20210512T192429Z&X-Amz-Expires=300&X-Amz-Signature=603d8ca68316e1252b801840956576b2f4116592fa2fd114dfd7553b845bc5c2&X-Amz-SignedHeaders=host&actor_id=0&key_id=0&repo_id=36755989&response-content-disposition=attachment%3B%20filename%3DEDMarketConnector_win_5.0.0.msi&response-content-type=application%2Foctet-stream
Threat name: Gen:Variant.Bulz.466715
Dangerous pages attempt to install software that can harm the device, gather personal information or operate without your consent."

@Athanasius
Copy link
Contributor

This happens in the first instance because we use py2exe to package the application code into .exe's (and then bundle that and the other relevant files into an .msi installer using WiX).

See py2exe/py2exe#86 and py2exe/py2exe#73 for some discussion about why these are false positives.

I'll see about adding something about this to our Known Issues and Troubleshooting page.

When I get time I'll investigate if there's any utility in me uploading each .msi/.exe to alleged Anti-Virus websites in order to pre-empty this sort of thing. I'm not hopeful.

I'll also note that we now always build for release on GitHub, so any compromise would, in the first instance, have to be against their infrastructure and the third-party software they pull in (a Windows build, python versions, python modules, a download of WinSparkle). Of course then I have to download the resulting .msi file in order to then upload it when I make a GitHub release. I should see if there is any way in which to have that happen purely on the GitHub side of things.

Furthermore, anyone worried about this with the ability to effectively check our source could just run from source.

@Athanasius
Copy link
Contributor

I note that Windows Defender (Windows 10 20H2 with May 2021 updates) doesn't find anything wrong with either the installer or the then installed files.

@Athanasius
Copy link
Contributor

@denisgre
Copy link

Thanks for your prompt reply. Personally I have reinstalled v4.2.7 without any problem at all. Soon as I try to update to v5 Bitdefender just quarantines it and the whole thing stops working so I have to un/re-install. Currently I have opted for "Skip this version" for the moment.

@Athanasius
Copy link
Contributor

@denisgre

Thanks for your prompt reply. Personally I have reinstalled v4.2.7 without any problem at all. Soon as I try to update to v5 Bitdefender just quarantines it and the whole thing stops working so I have to un/re-install. Currently I have opted for "Skip this version" for the moment.

As you're actually a user of the software, could you do me a favour and find any documentation/help they have about reporting a file as not malicious ? The same goes for anyone using other A/V software.

@Bow-Lof-Petunias
Copy link
Author

I uninstalled 5.0.0 and reinstalled 4.2.7 and then tried the upgrade again and this time no issue was found. It's interesting that it's not a 100% reproduceable issue based on my experience. Thanks for the prompt response. Have reported as false positive to my A/V vendor. I guess we'll see.

@denisgre
Copy link

For Bitdefender I can only suggest contacting their Labs at https://labs.bitdefender.com/contact/ as this is where we report to, which I have done.
Currently I have reinstalled v5 and listed the .api and .exe files as exceptions for scanning. Both of these files ar immediately quarantined by BD. With this done it will not work from Win10 start menu but will work directly from the .exe file itself in the EDMC programs folder. I have right clicked this and made it shortcut to the desktop and that works from there. Bit of a mess but it works.

@Athanasius
Copy link
Contributor

For Bitdefender I can only suggest contacting their Labs at labs.bitdefender.com/contact as this is where we report to, which I have done.

Thanks.

Currently I have reinstalled v5 and listed the .api and .exe files as exceptions for scanning. Both of these files ar immediately quarantined by BD. With this done it will not work from Win10 start menu but will work directly from the .exe file itself in the EDMC programs folder. I have right clicked this and made it shortcut to the desktop and that works from there. Bit of a mess but it works.

What do you mean by ".api" ? There are not such files in a standard EDMarketConnector install.

@denisgre
Copy link

Sorry. I meant .msi, the download file. Many apologies.

@Bow-Lof-Petunias
Copy link
Author

I'm going to close this issue based on observed and noted behavior, as well as not being able to reproduce the issue consistently after uninstall, reinstall and subsequent upgrade.

@Tip131
Copy link

Tip131 commented May 14, 2021

MalwareBytes Professional quarantines this MSI. Uninstalling and reinstalling does not help, as the scan on installation quarantines it again. I'm reverting to the previous version until this is fixed.

@Athanasius
Copy link
Contributor

I've attempted to report this issue to MalwareBytes: https://forums.malwarebytes.com/topic/274269-py2exe-generated-executables-show-as-false-positives/

@Athanasius Athanasius reopened this May 14, 2021
@Athanasius
Copy link
Contributor

I've now submitted the .msi as part of applying to AVG's whitelisting program: https://www.avg.com/whitelist-program-registration

@Athanasius
Copy link
Contributor

Reported to BitDefender via https://www.bitdefender.com/consumer/support/answer/40673/

@Athanasius
Copy link
Contributor

I've attempted to report this issue to MalwareBytes: forums.malwarebytes.com/topic/274269-py2exe-generated-executables-show-as-false-positives

A staff member has replied saying the file is now whitelisted on MalwareBytes.

@Athanasius
Copy link
Contributor

From Discord:

Dommaarraa : FYI - Sophus has just reported EDMC.exe as a Generic PUA GK and "cleaned it up"

@Athanasius
Copy link
Contributor

NB: 'Sophos' not 'Sophus', and I'm submitting the .msi to https://support.sophos.com/support/s/filesubmission?language=en_US

@ITZAP
Copy link

ITZAP commented May 17, 2021

Open your Anti-Virus software and add the entire EDMC
folder to the List of Exceptions from scanning.

@Athanasius
Copy link
Contributor

Open your Anti-Virus software and add the entire EDMC
folder to the List of Exceptions from scanning.

Personally I'd just add EDMarketConnector.exe and EDMC.exe to the allowed list, unless it still complains after that. No-one should be installing third-party plugins in the installation 'plugins' folder (they should go under %LOCALAPPDATA\EDMarketConnector\plugins\, but that doesn't mean people don't do it.

@denisgre
Copy link

Adding the entire folder to exceptions assumes you could get it to load from the .msi file in the first place. Both Bitdefender and Win10, in my case at least, did not want to load the .msi file either. Currently I have added both .exe, full folder and .msi files to exceptions and working fine now from a desktop shortcut.

@Athanasius Athanasius added anti-virus Anti-Virus issues and removed bug unconfirmed An unconfirmed bug labels May 17, 2021
@Athanasius
Copy link
Contributor

Sophos users - you'll have to do the reporting to get the file(s) properly assessed. From email with them:

I checked with Sophos lab with your finding but just the file will not be enough to remove the false positive alert.

We need a detection name and a screenshot or SDU logs if any.

And I am not installing any A/V in order to do such.

@Athanasius
Copy link
Contributor

As we've had no further reports of this, including none for 5.0.1 or 5.0.2, I'm closing this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
anti-virus Anti-Virus issues
Projects
None yet
Development

No branches or pull requests

6 participants