Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Updater.exe Blocked by Windows Defender #2133

Open
hl2guide opened this issue Nov 22, 2023 · 24 comments
Open

Updater.exe Blocked by Windows Defender #2133

hl2guide opened this issue Nov 22, 2023 · 24 comments

Comments

@hl2guide
Copy link

Describe the bug
Updater.exe Blocked by Windows Defender

ex

@bczegeny
Copy link

bczegeny commented Nov 22, 2023

Same but it thought it was another trojan
image

@ungkal96
Copy link

got this message too
Screenshot (7)

@CIsxxc
Copy link

CIsxxc commented Nov 22, 2023

I get the exact same as the above....

@jilherme
Copy link

same

@agarrandosenal
Copy link

same Wacatac.B!ml

Sad to have to find an alternative as I don't think this is a false positive. End of an era.

@ErisaFirehawk
Copy link

Trojan:Script/Wacatac.B!ml

well damn

@CIsxxc
Copy link

CIsxxc commented Nov 22, 2023

Wait, he does mention false positives here, but can @Rem0o comment on this?

image

@Rem0o
Copy link
Owner

Rem0o commented Nov 22, 2023

Whenever I recompile the updater, it triggers Microsoft Defender. I send a false positive submission, it gets scanned, then the false positive stops.

image

@ad0x00
Copy link

ad0x00 commented Nov 22, 2023

Same here, got the threat quarantined. @Rem0o should I restore the updater or delete and reinstall FC after some time?

@CIsxxc
Copy link

CIsxxc commented Nov 22, 2023

Whenever I recompile the updater, it triggers Microsoft Defender. I send a false positive submission, it gets scanned, then the false positive stops.

image

Thank you so much for your time and the effort you put into this project.

I'll be donating to you this payday after having used the app for a couple months very happily!

Have a lovely day/evening :)

@Spuner
Copy link

Spuner commented Nov 22, 2023

Windows Defender is a misunderstanding.

@a-zndr
Copy link

a-zndr commented Nov 22, 2023

Importantly if you're here because your FanControl isn't running now, and hangs on launch. the update process hasn't fully completed. redownload fancontrol and reinstall all the files as a replacement, preserving your config and plugins folder.

unfortunately because they are binaries you cannot confirm there isn't actually a trojan here. @Rem0o could be a compromised account encouraging us to download.

@marrok657
Copy link

Importantly if you're here because your FanControl isn't running now, and hangs on launch. the update process hasn't fully completed. redownload fancontrol and reinstall all the files as a replacement, preserving your config and plugins folder.

unfortunately because they are binaries you cannot confirm there isn't actually a trojan here. @Rem0o could be a compromised account encouraging us to download.

I have tried to download the newest and it still tells me "threat detected". unless maybe I download the version before?

@tullahstackz
Copy link

I had the same issue as everyone else. I finally got it working after I ran "Updater.exe". The first time it was run is shown in the attached screenshot. After deleting the .dll file that is mentioned, I ran Updater.exe again and the program runs as usual.
Screenshot (368)

@csandazoltan
Copy link

Until Windows Defender Sorts out its detection of the new updater, save your configurations, download 174 directly from the site.

@Trae132
Copy link

Trae132 commented Nov 22, 2023

Until Windows Defender Sorts out its detection of the new updater, save your configurations, download 174 directly from the site.

Thats what worked for me although I didnt try the poster above's recommendation of deleting the file, mainly because I didnt see the update.exe file referred to in their post. I copied the json and plugin folder from old install into new downloaded one from the website and all good.

@AussieGomez
Copy link

Yup same with me tried to update and just install straight from website and defender grabs it as well.

@Khanivore
Copy link

Khanivore commented Nov 22, 2023

I had the same problem and now fan control won't start at all.

@yvesfouquet4
Copy link

I had the same issue as everyone else. I finally got it working after I ran "Updater.exe". The first time it was run is shown in the attached screenshot. After deleting the .dll file that is mentioned, I ran Updater.exe again and the program runs as usual. Screenshot (368)

this solved it, thanks

@danielbr93
Copy link

It quarantined it for me, but after downloading the new update, unzipping it, deleting everything but the "Config" folder in the old folder and copy pasting the update into it, everything seems to work again.
If the Trojan is still doing stuff in the background, I can't tell.

@supabibz
Copy link

I had the same issue as everyone else. I finally got it working after I ran "Updater.exe". The first time it was run is shown in the attached screenshot. After deleting the .dll file that is mentioned, I ran Updater.exe again and the program runs as usual. Screenshot (368)

Worked for me too : had to delete Autofac.dll & Newtonxxxx.dll. After running the update, those dll didn't reappear...

@Chicora470
Copy link

There`s some news about this update is false positive or an hacked false update that bring virus?

@Chicora470
Copy link

Importantly if you're here because your FanControl isn't running now, and hangs on launch. the update process hasn't fully completed. redownload fancontrol and reinstall all the files as a replacement, preserving your config and plugins folder.

unfortunately because they are binaries you cannot confirm there isn't actually a trojan here. @Rem0o could be a compromised account encouraging us to download.

No response from @Rem0o about this?

@AtA3301
Copy link

AtA3301 commented Nov 28, 2023

Not had any issues with Windows Defender here. Remi already addressed why this can happen above: #2133 (comment)

Defender (and most AV products) will flag a program that tries to modify itself (ie, update) if the signature is not known. When FC is re-compiled, the signature is changed, and there will always be a delay between release and Defender being up to date.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests