Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

snoretoast-x86.exe detected as a trojan by McAfee Endpoint Security #848

Closed
chernobog opened this issue Sep 30, 2022 · 5 comments · Fixed by #941
Closed

snoretoast-x86.exe detected as a trojan by McAfee Endpoint Security #848

chernobog opened this issue Sep 30, 2022 · 5 comments · Fixed by #941

Comments

@chernobog
Copy link

Whether or not snoretoast-x86.exe is malware, this creates a poor user experience, and compromises trust with this repo.

McAfee ENS detects the following file as a trojan (RDN/Generic.dx):
%userprofile%\AppData\Local\Temp\nsoBF47.tmp\7z-out\resources\app.asar.unpacked\node_modules\note-notifier\vendor\snore\snoretoast-x86.exe

@ve3
Copy link

ve3 commented Oct 8, 2022

YouTube-Music-1.18.0.exe Also detected in Virus total website scanned by Trend micro ( https://www.virustotal.com/gui/file/f64aa95b6778a61cf9e50f6f4b8d28fc64fe08980c4ded44b48f8a0420e6622f?nocache=1 )
TROJ_GEN.R002H06IR22

@th-ch
Copy link
Owner

th-ch commented Oct 9, 2022

Hey folks, that seems weird indeed 🤔 Snoretoast is compiled from source in the repo (also applying a missing patch along the way) and nothing was changed recently in that area, not sure why some antiviruses suddenly detect it (false positive?) - if you prefer, you can compile it yourself by setting up the repo (cloning and install dependencies with yarn) then building snoretoast (see the linked CI file for instructions - it consists in cloning the repo, applying the patch then compiling it), then building the app (yarn build:win) - hope that helps!

@Araxeus
Copy link
Collaborator

Araxeus commented Dec 14, 2022

@th-ch seems like some changes were made and a new snoretoast version was released

KDE/snoretoast@8502ef0
https://invent.kde.org/libraries/snoretoast/-/commit/8502ef06167b3741c072cf65ba74d4f501600408

(this is pretty much what the local patch does)

https://binary-factory.kde.org/job/SnoreToast_Release_win64/
https://binary-factory.kde.org/job/SnoreToast_Nightly_win64/

might work with the signed file now, need some testing (I cannot test it sadly)

I've also posted in node-notifier (mikaelbr/node-notifier#375 (comment))
Might be better to wait for them to update

@chernobog
Copy link
Author

Reinstalled today, and McAfee did not protest.

@Araxeus
Copy link
Collaborator

Araxeus commented Jan 6, 2023

New snoretoast version was officialy released

https://download.kde.org/stable/snoretoast/0.9.0/

release notes

edit: the new version didn't actually fix the bug

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants