11 ms·
MS Windows Defender and DeCSS
- anthk 5y ago15 years ago, often you found infected binaries on keygens and cracking tools. On DeCSS, that made me nostalgic ahout DVDCSS and cracking a DVD movie in "just" 20 minutes with MPlayer. The key was cached, luckily.
- chovybizzass 5y agoMy coworker and i worked at PayPal back then and we both got portable hard drives and ripped DVDs we got at the local libraries during lunch time and from Netflix on PayPal computers. Good times to be had. My wife threw out our 12 dvd binders just a year or two ago once we went full IPTV.
- RachelF 5y agoI wonder when Anti-Virus will start deleting files that express opinions they don't like. Reminds me of the famous Earworm https://www.youtube.com/watch?v=-JlxuQ7tPgQ https://www.youtube.com/watch?v=-JlxuQ7tPgQ
- X-Cubed 5y agoI get annoyed with AV when it quarantines "Potentially unwanted software" like ProduKey. While it may be able to be used maliciously, that's not why I have it installed, and I do want it on my machine.
- mewse-hn 5y agoMy win10 install recently started deleting my install of qBittorrent, which I very much want installed and use daily, as "potentially unwanted software". Exceptions kept getting ignored so just today I disabled the entire category of potentially unwanted software in win defender. It feels like they're just getting capricious in their scope for flagging things now.
- Akronymus 5y agoI personally never really vibed with qbittorrent. Stuck with deluge for years. May I ask why you use qbit?
- selfhoster11 5y agoThat's entirely off-topic.
- jasonjayr 5y agoFirefox 90.0b12 on Linux also reports that file as a virus/threat, and warns on download
- userbinator 5y agoIt's packed, which for some reason that tends to trigger a lot of AVs... although the fact that it's a packer from roughly 2 decades ago and one that any respectable AV should be able to easily unpack by now certainly doesn't inspire confidence. Then again, AVs detecting things as innocent as freshly-compiled "Hello World" programs is not new, and certainly makes one wonder just what exactly they are trying to detect.
- dreamlayers 5y agoI'm guessing that some virus signatures detect packers instead of unpacking the code and detecting malware code there.
- ooboe 5y agoHis comment in /r/sysadmin: "Setting a Windows Defender exception to the folder does not prevent the quarantine from occurring. I re-ran this test three times trying exceptions and even the entire NAS drive as on the excluded list." Windows Defender is overriding the user whitelist?
- RachelF 5y agofrom that forum it also seems like Windows Defender is deleting a .txt file containing the source code.
- ooboe 5y agoYes, if true, this would invalidate the "heuristics error on exe" argument.
- sneak 5y agoIn addition, Windows also quarantines and deletes innocuous Windows activation crack tools that contain no malware whatsoever, but can be used to activate Windows independently of Microsoft. It's really amazing the attitude Microsoft takes regarding hardware that isn't theirs, including the nonconsensual forced autoupdate.
- aardvarkr 5y agoOh no, they’re making the world safer by encouraging the adoption of the latest security patches and bug fixes? And giving away best-in-class security software that you can disable at any time? How evil. You must really have loved the days of Norton Antivirus.
- dexterhaslem 5y agoyou may have misread the parent comment? it is deleting things completely unrelated to malware
- gogopuppygogo 5y ago
- Santosh83 5y agoDo tech aware people like nearly everyone in this forum, need Defender (or another AV) to run at all? How many people here completely or partially stop it from running?
- DrJokepu 5y agoSadly it’s often a contractual / insurance requirement.
- TedDoesntTalk 5y agoAt home?
- bathtub365 5y agoIf anything I think it makes more sense to have higher security requirements for a computer that will be primarily used outside of a controlled corporate network.
- PostOnce 5y agothe "reputable source" you downloaded from can always be compromised
- throwaway17_17 5y agoI had to get signed permission from our IT contractors to disable it. But then again, I was trying to get a PDF of a Categorical Logic paper from an Italian university’s website and the filters kept blocking for pornography and sending emergency messages to the contractor to audit my computer.
- Beldin 5y agoSounds weird... Do you know to what extent those are correlated? That is: is the contractor told every time the filter thinks it has found adult entertainment? Or was your case exceptional?
- john_moscow 5y agoTo be fair, this does look like a false positive. In general, the desktop antivirus space in 2021 is a mess. Because of the sheer number of malware, and some obfuscation techniques used by some of it, antivirus software has to use very broad regular expressions for describing the malware, counterbalanced by huge whitelists of known mainstream software. If you don't qualify as a "mainstream software vendor", simply building a random piece of code into an exe file will get you about 10% chance of getting flagged by one of the "heuristic engines" if you upload it to VirusTotal. You can contact the A/V vendor and they will usually add it to the whitelist, but it only lasts until the next rebuild. Or you can rebuild it a couple of times with different optimization levels, and the detection sometimes goes away.
- howaboutnope 5y agoDeleting both the exe and the source code makes a false positive seem rather unlikely to me.
- jcrawfordor 5y agoThe source code in question appears to have been obfuscated (possibly just for brevity). I'd guess the Defender signature in question was written around the packer/obfuscator.
- eurasiantiger 5y agoWanna bet the signature is the hex key?
- jcrawfordor 5y agoyeah, that'd be my guess. It's going to be in different representations in the source and the executable but if I was writing a signature for it straight up I'd probably add the C escape representation as well for good measure.
- deleted 5y ago[deleted]
- deleted 5y ago[deleted]
- adzm 5y agoDo AVs still respond to the EICAR test file?
- unixhero 5y agoYes
- tyingq 5y agoTried it. Windows Defender thinks it's "Trojan:Win32/Orsam!rfn" on my PC, which is different from "Glupteba!ml". It does let me override and keep it.
- rootw0rm 5y agoand this is why you use the group policy editor
- MonaroVXR 5y agoWait until Windows 11 comes along and has more security features enabled.
- parentheses 5y agoHe said DirectConnect!
- sergiomattei 5y agoOk, honest question. How do they come up with those names for the malware? Glupteba!ml looks like a randomly generated thing, but I’m sure it’s not.
- account42 5y agoThe "!ml" stands for machine learning so what else could the name be except randomly generated?
- Fiahil 5y agoI'm so happy to see a thread on Windows Defender, because my org recently switched antivirus software and I can't wait to tell you how bad it is ! There's a hidden feature in Defender, that will delight any user : it can turn your 15" MacBook Pro into a full breakfast machine. Want pancakes ? Start a zoom call. While you wait for your favorite video conference app to start, don't hope to finish your docker pull/save/build in less than 30 times its usual time. Your laptop I/O will be so cripled that you might get better bandwith with a floppy disk drive (I'm exagerating a bit, but that's how it feels to go from 120MB/s to 4MB/s on a SSD). Our Mac IT is completely powerless. I never thought I would ever regret getting rid of Symantec. I was wrong.
- foepys 5y agoWe are using Defender at work, too. There is a group policy that lets Defender do a full system scan once a week. To not interfere with the user there allegedly is a group policy setting to limit the CPU usage and it is set to 15%. The thing is, it simply does not work. Every week my fans spin up to max, Defender hogs all my CPU cores, 25% of my GPU according to the Task Manager. Even typing becomes laggy. The only way to stop it is to open Task Scheduler and end the scheduled task from there.
- qwerty456127 5y agoMS Windows Defender is generally good (I actually prefer it and preferred its SecurityEssentials predecessor to all the other antiviruses) but seems really notorious in removing non-virus "threats". It also removes NirSoft (and some Sysinternals IIRC) utilities regularly. Yesterday, trying to download the recent version of LibreOffice, I have even found found out I have no qBitTorrent installed any more - it killed it also. I really wish I could just put a regex filter to bulk-allow some classes of "threats" ("HackTool:" and "PUA:") permanently.
- unnouinceput 5y agoUse Deluge. The best IMO.
- cm2187 5y agoI disagree that it is good. It was good. But now it is indistinguishable from a malware. It regularly takes 100% CPU, it prevents many of my own apps from running, and if you switch off real-time protection it switches itself back on like any respectable rootkit.
- 1_player 5y agoI don't know if my installation is broken, but I haven't had Defender remove what I thought was a legitimate binary since I first installed Windows 10. Literally not one single time on half a dozen installations. FWIW I installed and ran qBitTorrent recently and it didn't complain.
- qwerty456127 5y ago> I haven't had Defender remove what I thought was a legitimate binary Probably because you are closer to a "typical" kind of user who doesn't use "hack tools" (which some people like me use for absolutely legal and benevolent purposes "hacking" their own PC, e.g. to backup the passwords and e-mail records saved on it). By the way it also is very important to distinguish between a legitimate hack tool and an infected hack tool and I am not sure they do. > I installed and ran qBitTorrent recently and it didn't complain. They just added a slightly old version to their threats database and didn't add the most recent version there yet. https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?name=PUA%3AWin32%2FQBitTorrent&threatid=292801 https://www.microsoft.com/en-us/wdsi/threats/malware-encyclo... https://www.reddit.com/r/qBittorrent/comments/lwqjm9/qbitborrent_flagged_as_malware_by_microsoft/ https://www.reddit.com/r/qBittorrent/comments/lwqjm9/qbitbor...
- 0x_rs 5y agoDefender, as per Windows 10 philosophy, is extremely annoying to use with its UI and behavior that makes you feel every setting and button you press is entirely useless and nothing will change. A shame the old Security Essentials UI was removed entirely, it was the only bearable hack-y way to use it. I just disable it permanently on every machine. The anti-malware service likes to eat disk activity when you're working, and most importantly, exceptions handling is useless: I've seen it delete or quarantine (and then delete) files put into exceptions multiple times, repeatedly, as if the exception list was getting reset, or expired. This kind of software behavior is unacceptable in any way or form.
- encryptluks2 5y agoFirst, you are relying on Kaspersky which I don't think is that reliable of a source anymore give what we know. Second, I can definitely say there are something up with a lot of keygens and cracks. I thought a lot of big name scene groups were reputable and there is no way that they'd sneak in a trojan, but low and behold after ignoring a few Windows Defender warnings... I could literally hear my computer randomly spinning up at random times, it would never sleep, games were choppy, etc. Did a complete reinstall without installing any scene software and the problem was solved. Just because people haven't taken the time to properly investigate the security of cracks and keygens doesn't mean that they don't contain actual trojans.
- dannyw 5y agoNo shit, cracks and keygen are at extremely elevated risk of malware lol.
- Ashanmaril 5y agoI just download them for the cool music
- anthk 5y agoJust get chiptunes.
- skeletron 5y agoWhat I really don't like about Defender and other antivirus products is they'll silently send your files to the mothership to be analyzed, without even letting you know that's happened, or any straightforward way to find out. I understand that's a large source of new malware samples for them, but it's an awful antiprivacy behavior.
- npteljes 5y agoAnother dark pattern here is that there's an option to turn this off, and I turned it off, only to be nagged weekly to turn it back on! Fuckers don't take no for an answer, until I'm nagged into clicking yes. And the UI acts like this is some security warning, with a yellow exclamation mark and everything.
- trishmapow2 5y agoIn Windows Security click settings on the bottom left and then you can manage notifications.
- bob1029 5y agoMaybe this is a good time to ask a dumb question.... how do yall disable windows defender? I spent a weekend on it last year and couldn't figure it out. Best I could surmise is that I need to wipe my hard drive and install a sketchy copy of "mad max edition" windows 10 enterprise, which I would have to download on TPB or some other Warez site.
- colejohnson66 5y agoNot sure why you’d want to disable virus protection, but Microsoft has a guide should you want to: https://support.microsoft.com/en-us/windows/turn-off-defender-antivirus-protection-in-windows-security-99e6004f-c54c-8509-773c-a4d776b77960 https://support.microsoft.com/en-us/windows/turn-off-defende...
- bob1029 5y ago> Follow these steps to temporarily turn off real-time Microsoft Defender antivirus protection in Windows Security. How long is "temporary"? > Not sure why you’d want to disable virus protection Because Microsoft's implementation drags ass when fighting with one of Microsoft's other terrible messes - visual studio. Also. It's my fucking computer.
- topkai22 5y agoYou can (depending on group policy if domain joined) disable real time scanning on individual processes, files, and folders in a more permanent manner IRC.
- mattbee 5y agoThere's a registry (or group policy?) tweak to turn it off for good. It was absolutely necessary on my 2015-era laptop, especially in the era of WSL1 where every Linux-side file operation caused a Defender operation - made a huge difference running test suites, git operations and so on. I've tried to leave it on my new laptop (esp on WSL2 where Defender doesn't get a look-in) but I can _smell_ when it's slowing me down.
- 5y ago
- unixhero 5y agoI work in Cyber Security and I would never want to run any Next Gen antivirus software (such as Defender ATP) on my private computers. For a corporation or organization that wants tight control, these are perfect products. You can go full Orwell 1984 on your org with these tools and they do provide good endpoint protection including graph and AI based (post-signature) antivirus and full Event Detection and Respond* (essentially a spy-black-box), which is great if you're a company or org. However this is a future you do not want to be part of in your private life. * See for instance documentation on Microsoft Defender ATP EDR in Block Mode
- tempfs 5y agoYour concerns extend to the OS itself by the way. Windows is a full blown surveillance platform now. Defender ATP telemetry also sends much more home than the customer can ever see. They claim to anonymize it but anyone who works in security for a living knows just how much story you can tell with relatively little data.
- account42 5y agoThe ML antivirus detections are out of control.
- marcodiego 5y agoI fear anti-virus and firewall software may in the near future be used to guarantee DRM features. I fear the day when I try to play media I legally own from another region and can't play it because of region blocking and can't circumvent it because my "defense" software prevents me. Another thing that scares me: services requiring said kinds of software. The mobile world is somewhat like this already and it is basically what bars users from using their mobile phones as full blown computers even though said phone are powerful enough for that.
- grishka 5y agoAs long as the hardware allows booting arbitrary code, this kind of DRM remains technically impossible. There's nothing to stop you from booting into another OS and deleting the files implementing the harmful functionality. If there are checks for the presence of these files in other parts of the OS, you can remove them. IMO it's a very dangerous attitude when people consider software immutable. You can achieve a lot by modifying software made by other people.
- ddalex 5y ago> There's nothing to stop you from booting into another OS and deleting the files implementing the harmful functionality. If there are checks for the presence of these files in other parts of the OS, you can remove them Encrypted disks with TPM-stored keys will certainly prevent unauthorised modification to a filesystem > hardware allows booting arbitrary code And this particular cat is already out of the bag with Win 11 REQUIRING TPM support with verified boot. The war against general-purpose computing is in the final stages, and the garden-keepers have already won for almost everything that matters. Yes, you can still source open hardware and they will not fight against technical elites - a minority - but for the vast majority of users, it's over because they LIKE the closed apps holding data hostage.
- grishka 5y agoSo this might be a dumb question, but what's there to prevent someone emulating a TPM? What's there to prevent someone nop'ing out the code that implements the TPM functionality in Windows? Where does the root of trust (or, rather, distrust) come from?
- DrBazza 5y agoIt's things like this that are making me less and less likely to continue using Windows at home. I've been running Linux KDE dual booting for a year or so, and I've have touched Windows in (uptime...) - 22 days or so. With Windows 11 coming bundled with Teams, and other "stuff" from Windows 10 including it becoming an 'internet first OS (x)' I'm getting stuff I don't want or need. (x) although it's documented on the interwebs how to circumvent the dark pattern UI dialogs to turn stuff off.
- blooalien 5y ago> I've been running Linux KDE dual booting for a year or so, and I've have touched Windows in (uptime...) - 22 days or so. Sounds like how I ended up on Linux full time. I dual booted for a while before I one day realized I hadn't booted into Windows for months. At that point I saw no valid reason to keep my Windows partition at all and just put in the effort to get my last few "Windowsy" activities switched over to Linux applications (mostly gaming and graphics related stuff).
- SCHiM 5y agoA properly configured Defender ATP instance in a network is a beast to circumvent for attackers. It's a really nice piece of software as far as I'm concerned. Defender on personal systems owned & maintained by a knowledgeable power user, maybe less useful. Still, Defender ATP in the corporate environment is so much, much more than just an anti-virus scanner. There its primary functionality is EDR first, anti-virus distant second. And it works phenomenally.
- Ashanmaril 5y agoEarlier this year I spent a month or 2 working on a little Go project for a very niche little usecase (it would read a MIDI file and write it to a text file in a format that could be inserted into Super Mario World romhacks [or try to anyway]) After spending all that time working on it, I was hoping that I could just compile to the various OS/architectures and distribute that, but once someone tried using it I quickly found out that as soon as you downloaded my program, Windows Defender would flag it as malware and quarantine it. Even the builds in my project workspace that I compiled myself would get flagged/quarantined once it caught them. I tried doing some research and it seems to just be a regular thing with Go apps because I think the runtime code would be common across malware written in Go, so basically all Go programs are automatically assumed to be malware by Windows unless you buy a cert and/or get enough people using it. Or maybe this is more common than just Go programs. I've never really done anything like this before. But I ended up just abandoning attempting to release it properly and left the source code up on Github so if someone wants to compile it themselves they can. But the whole experience was a bit discouraging. It seems like there's really no cheap/easy way to distribute software. Webapps require hosting, and native code is assumed to be malware by default.
- Shadonototro 5y agowindows defender aggressively scan every .jar, but totally ignores .net executables no wonder they do something similar with go executables, it's easy to recognize them after all
- alyandon 5y agoIIRC, there is a group policy setting called "Turn off routine remediation" to stop defender from auto-removing stuff. There is also a setting to permanently disable automatic sample reporting. I enabled that on all my Windows machines after the first time I caught Defender exfiltrating sensitive files like places.sqlite database out of my FF profile directory.
- arch13 5y agohttps://www.arch13.com/ms-windows-defender-decss-part-ii/ https://www.arch13.com/ms-windows-defender-decss-part-ii/ OP Here. That lasted 3 days and then the file got blacklisted again as a generic definition. Whitelists and exceptions in MS Defender still do not work. It ignores them and yeets the file anyway.