Skip to content

NeSync installer on windows detected as malware #144

@fxdeniz

Description

@fxdeniz

NeSync uses NSIS as a installer on Windows. And, antiviruses Bkav Pro and SecureAge flag exe files based on NSIS as a virus.

Detection names:
Bkav Pro: W32.AIDetectMalware
SecureAge: Malicious
Gridinsoft: Ransom.Win32.Wacatac.oa!s1

VirusTotal result for version 1.8.1 installer

VirusTotal result for version 1.8.0 installer

VirusTotal result for version 1.7.0 installer

From detection names, we can conclude that, detections are machine learning based.
Both, Bkav Pro and SecureAge APEX are advertised for their AI capabilities. However, this is a false positive.

Update: Starting from september 6, Gridinsoft also marks installers for versions 1.8.x marks as malware.

To solve this issue, I'll communicate with two vendors.

  • Get in touch with Bkav Corporation
  • Get in touch with Secureage Technology Pte Ltd
  • Get in touch with Gridinsoft LLC

Metadata

Metadata

Assignees

Labels

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions