activitywatch icon indicating copy to clipboard operation
activitywatch copied to clipboard

Virustotal flags installation files of v0.12 for windows as malicious

Open MaximilianRettinger opened this issue 3 years ago • 1 comments

Hi,

I wanted to install activity watch on my new work machine running windows. Had good experience with AW so far on my linux machine. Can you please clarify why this is happening? I would really like to use this great tool, but I simply can't install with red warning flags like this.

Zip: image Exe: image

MaximilianRettinger avatar Sep 19 '22 08:09 MaximilianRettinger

Hi there! As you're new to this repo, please make sure you've used an appropriate issue template and searched for duplicates (it helps us focus on actual development!). We'd also like to suggest that you read our contribution guidelines and our code of conduct. Thanks a bunch for opening your first issue! 🙏

github-actions[bot] avatar Sep 19 '22 08:09 github-actions[bot]

This is definitely a false positive, and you should have no reasons to worry.

VLEU avatar Oct 07 '22 06:10 VLEU

@VLEU Thanks for your reply. Doesn't really matter if I worry or not - it matters that the admin in the company that I am working for worries. So I'd have to provide some sort of proof to him, that this a false positive. Could you supply a valid reasoning to me why this is a false positive?

ghost avatar Oct 07 '22 10:10 ghost

VirusTotal simply aggregates the output of different antivirus vendors and URL scanners, it does not produce any verdicts of its own. 4/61 or 1/66 is definitely an indicator of a false positive.

When 4 obscure "virus scanners" that nobody uses and nobody has ever heard of say it contains a virus, and the other 100 true virus scanners, including all the big and reputable names say it is clean, that should tell them something. A simple explanation for the false positive is that the 4 vendors might have some overly aggressive detection filters (either that or they simply suck - in layman's terms).

Additionally, this entire project is open-source. If there was a problem, someone would most likely have noticed it and voiced some concern.

VLEU avatar Oct 07 '22 16:10 VLEU

Handed in the 0.12.1 version to the Microsoft Security Intelligence portal and Windows Defender is now desensitized and will allow running the exe.

florianklumb avatar Oct 08 '22 16:10 florianklumb

Thanks you both, that's more than sufficient for me!

ghost avatar Oct 10 '22 07:10 ghost