Arx Libertatis Bug Tracker
star_faded.png
Please log in to bookmark issues
bug_report_small.png
CLOSED  Bug report #1555  -  1.2 installer sets off antivirus warnings
Posted Jun 30, 2021 - updated Jan 05, 2023   Shortlink: http://arx.vg/1555
action_vote_minus_faded.png
0
Votes
action_vote_plus_faded.png
icon_info.png This issue has been closed with status "Upstream" and resolution "Not determined".
Issue details
  • Type of issue
    Bug report
  • Status
     
    Upstream
  • Assigned to
    Not assigned to anyone
  • Type of bug
    Not triaged
  • Likelihood
    Not triaged
  • Effect
    Not triaged
  • Posted by
     Guest user
  • Owned by
    Not owned by anyone
  • Estimated time
    Not estimated
  • Category
    Not determined
  • Resolution
    Not determined
  • Priority
    Not determined
  • Reproducability
    Always
  • Severity
    Not determined
  • Targetted for
    icon_milestones.png Not determined
  • OS
    icon_customdatatype.png Not determined
  • Architecture
    icon_customdatatype.png Not determined
  • Fixed in
    icon_customdatatype.png Not determined
Issue description
defendericon_open_new.png

As you can see in the image, it gives a specific error, which seems to be common among "unsigned" .exe installers (.ini solves it, I think)
Steps to reproduce this issue
Download the installer on Windows. Both chrome and edge throw up false positive warnings. Then Windows Defender autoremoves it.

#1
icon_reply.pngReply
Comment posted by
 Daniel Scharrer
Jul 01, 06:41
If you have malware installed on your system that randomly deletes files I suggest you contact your antivirus vendor - oh wait...

Seriously though, there isn't really anything we can do about this. With the current state of Windows antivirus I suggest ignoring all machine learning detections like those that contain "!ml", "!ai", "!cl", "Generic", ".Gen", "Artemis", "ML." in their name. It is disappointing to have to give this advice since there is legit malware out there, but the current state is ridiculous.

As for signing the executables: That is expensive and complicates the build process while not even making any guarantees or allowing reputation to carry across different releases from the same publisher or of the same software, unless you get an EV certificate which are only available to corporations. I'd be happy to use signing if there was a sensible solution (like there is Let's Encrypt for SSL), but there is none.

If you want, you can try submitting the file as safe here, but it is unlikely to do much as the next release will be flagged again by our artificial "intelligence" overlords: https://www.microsoft.com/en-us/wdsi/filesubmission

The issue was updated with the following change(s):
  • The status has been updated, from New to Upstream.
  • This issue has been closed
#2
icon_reply.pngReply
Comment posted by
 Daniel Scharrer
Jan 05, 19:53
Other duplicates: Bug report 1477 - Trojan.GenericKDZ.67863, Bug report 1572 - Bitdefender detected Trojan.GenericKD.37282355, Bug report 1546 - Arx Libertatis 1.2-dev-2021-04-11 has a trojan Phonzy.A!ml