Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Windows 1.17.5 version detected as Trojan:Win32/Bearfoos.A!ml #832

Closed
CreativePR opened this issue May 6, 2024 · 6 comments
Closed

Windows 1.17.5 version detected as Trojan:Win32/Bearfoos.A!ml #832

CreativePR opened this issue May 6, 2024 · 6 comments
Labels

Comments

@CreativePR
Copy link

In Windows version 1.17.5 - Windows Defender now detecting iCloudPD as Trojan:Win32/Bearfoos.A!ml

Previous versions did not have this issue.

@CreativePR CreativePR added the bug label May 6, 2024
@boredazfcuk
Copy link
Contributor

boredazfcuk commented May 6, 2024

Someone else seeing same issue, with an app they wrote themself:

https://superuser.com/questions/1416678/my-own-backup-program-was-detected-as-win32-bearfoos-aml-virus#1417342

@AndreyNikiforov
Copy link
Collaborator

tested with https://www.virustotal.com/gui/file/1df602c6413610c4ae4b92b7d652054a193458eeaee7127a1339d61a106a6e33/detection - looks like two other products detect viruses, but Windows Defender seems to be okay (I assume 'Microsoft" in the report is Windows Defender)...

As a workaround, I can suggest updating Windows Defender.

@CreativePR
Copy link
Author

tested with https://www.virustotal.com/gui/file/1df602c6413610c4ae4b92b7d652054a193458eeaee7127a1339d61a106a6e33/detection - looks like two other products detect viruses, but Windows Defender seems to be okay (I assume 'Microsoft" in the report is Windows Defender)...

As a workaround, I can suggest updating Windows Defender.

I'll check it out- thanks

@AndreyNikiforov
Copy link
Collaborator

@CreativePR has you solved the issue?

@Lheligh
Copy link

Lheligh commented May 29, 2024

@AndreyNikiforov Same issue here - except Windows Defender marking the ZIP as "Trojan:Win32/Wacatac.H!ml" - for both v1.17.5 and the latest 1.18.x

Security Intelligence version is latest at 1.411.423.0

@AndreyNikiforov
Copy link
Collaborator

The tool that we use to package icloudpd suggests that false positive detection for trojans is because many trojans are using the same tool for packaging their apps. Reporting the issue as false positive to Win Defender authors or not using Win Defender at all were the two options suggested.

Closing as there is nothing icloudpd can do about that.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

4 participants